The two access systems: organisation role and project access
LCAbyg grants a user’s permissions through two routes, each with its own scope.
| Organisation role | Project access | |
|---|---|---|
| Values | Member, Owner | Owner, can edit, read-only |
| Set on | The organisation page | The project’s access dialog or an invitation |
| Applies to | The whole organisation | One single project |
The organisation role determines what a user can do in the organisation as a whole, for example create new users or edit the organisation’s library, see The library types. Project access determines what the user can do on one specific project, independently of the organisation role.
The order that decides access
Section titled “The order that decides access”Access to a project in LCAbyg, and whether it comes with edit or read permissions, is resolved as follows:
-
Organisation owner: full access, both view and edit, to all projects in their own organisation.
-
Individual project assignment: the user’s assigned level (owner, can edit or read-only) determines access.
-
No assignment: if the project is set to “Visible to all organisation members”, the user gets read access, never write access.
The trap
Section titled “The trap”The organisation owner has full edit access to every project regardless of any restricted sharing.