Skip to main content

Roles and permissions

A role is a named set of permissions. Everything a person can see and do in ITS comes from the roles on their account. What a role grants takes effect for everybody who holds it, immediately.

The Roles tab lists every role, shows what each one grants, and lets the operator build roles of their own when the built-in ones do not fit.

Who can open this screen

Only System admin, the operator who runs the deployment.

What you see depends on who you are
You are signed in asWhat you see
The operator (System admin)Users & roles has a Roles tab, with New role and every role.
The Secretariat adminNo Roles tab.
A State Party or REC administratorNo Roles tab. Typing its address shows grey placeholder rows and Loading roles… that never finish.

The Roles address opened by a State Party administrator: placeholder rows that never fill

To know what a role grants without this screen, read What each role can do.

Before you start

  • You need System admin.
  • Know which job you are describing. Most people need one of the built-in roles; a custom role is for a job none of them fits.

How to open it

  1. Select Users & roles in the header.
  2. Select the Roles tab.

The Roles tab: fourteen roles over two pages, each with its permission count, members and status

On the page

On the pageWhat it is for
New roleBuild a custom role.
Search roles…Narrows the list by name or description.
StatusActive only or Including inactive.
RoleA padlock for a system role, the name, a System or Custom badge, and the description.
PermissionsHow many permissions the role grants.
MembersHow many people hold it.
StatusActive or Inactive.
⋮ (Role actions)View and Duplicate for a system role; also Edit and Delete for a custom one.

The row menu on the Customs officer system role: View and Duplicate

System roles and custom roles

System rolesCustom roles
Where they come fromPart of the deploymentBuilt on this screen
BadgeSystem, with a padlockCustom
What you can doView, DuplicateView, Duplicate, Edit, Delete

"A system role ships with the deployment. It is read-only." To change what a system role grants, the ITS team changes the deployment.

The roles for people and the roles for systems are described in What each role can do. Only give people the roles for people.

Look inside a role

  1. In the role's ⋮ menu, select View. A panel opens on the right.

    The Organisation admin role opened with View: machine name, members, permission count, description, and the permissions by area

  2. Read the panel:

    Panel sectionWhat it shows
    RoleMachine name (the role's fixed internal name, for example organisation-admin), Members, Permissions (the count), the description, and Duplicate.
    PermissionsOne line per area, with the actions granted on it: for example customs-office activate create deactivate export import read update.

The areas are written with their internal names. The ones you will meet most:

AreaWhat it covers
etdDeclarations: read, and for systems issue (lodge), endorse (stamp), amend, attach, cancel, acknowledge.
its-analytics, its-register, its-integration, its-workforceThe Reports areas: Transit volumes and Time & delays; Register; Integration; Workforce.
customs-officeThe customs office register.
governanceGovernance.
user, user-stationUsers, and duty-station postings.
notificationNotifications and the bell.
onboarding, onboarding-selfThe integration workspace.

Build a custom role

The quickest way is to start from the closest system role.

  1. In that role's ⋮ menu, select Duplicate. The copy is named "Copy of" and the original name.
  2. Or select New role to start from nothing.
  3. Give the role a name people will recognise, and a description saying who it is for.
  4. Choose the permissions. Use Search permissions… to find an area, Select all and Clear all to start over.
  5. Select Create role (or Create copy), or close the window to keep nothing.

A role with no permissions can be created. Anyone holding it can sign in but do nothing.

Then give the role to people on Users. A State Party or REC administrator can only give the roles their organisation is allowed to give, so a custom role is, for now, something the Secretariat gives.

Known problems

Counts on this screen do not match the Users tab

Organisation admin shows 0 members, although every State Party and REC administrator holds it, and the member counts across all roles add up to more people than the Users tab lists. The counts do not tell you who holds a role.

Some permission counts include retired permissions

On the development system Organisation admin counts 34 permissions and Secretariat admin 43. Both include seven tin-scheme permissions for a register ITS no longer has (you can see them in the role's panel). They grant nothing.

Descriptions written for engineers

Several built-in descriptions name internal parts of ITS ("Production Core only…", "Outbound only…"). They are roles for systems; the descriptions are for the people who run the deployment.