Insight's unified permissions model gives your firm the ability to manage user access at the Fund level, leverage group-based management, and built in user audit reporting.
Learn how to manage user access so that users have the exact capabilities they need based on your firm’s preferences.
Table of Contents
User Permissions overview
Standard Users
When adding or managing users, you can set:
|
User Provisioning Access
This is a stand-alone permission, fully separate from data access to your Funds.
This capability grants access to create, edit, and delete users, user groups, and notification settings. Those with this access can manage users and run audit reports, without seeing any Fund documents or data.
User Groups
User Groups help you to manage permissions at scale, ensure consistency across a group, simplify onboarding and offboarding, and reduce repetitive work when creating new funds; assign access once at the group level and the right users automatically get the right access to new funds.
| Type of Group | Details | When to use |
| System-Managed User Groups (SMGs) |
These are Ontra defined and maintained SMGs enabled in your account. Each SMG bundles a specific set of platform capabilities. Your firm controls who belongs to the group; Ontra manages what the group can do, keeping it current as product capabilities evolve.
|
You need a standard administrative role that Ontra keeps current. |
| Custom User Groups | These are groups your firm has created to organize users based on your needs, such as a group for all members of your Compliance team. | You need a different composition for your firm. |
Manage individual users
Add a user
If a user only needs to be assigned tasks - add them as a user following the steps below and start assigning tasks to them. There is no need to define their Access Level or Additional Permissions by Fund in this case. The user will be able to manage their assigned tasks accordingly (update status, add comments, and upload supporting documentation).
- Navigate to Admin and then select User Management
- On the Users tab, click the Actions drop-down menu
- Select Add User
- Input the user’s First Name, Last Name, and Email
- Select the applicable User Groups to enable more efficient and scalable management for permissions
- Click Add
Set a user’s Access Level and Additional Permissions
- Navigate to Admin and then select User Management
- Click the user’s name to open their User Details page
- Open the Access Management tab
- Manage Platform Controls:
- Click Edit in this tile
- Check the additional boxes to enable User Provisioning Access, Account Integrations Access, and/or the ability to Upload to Document Repository
- Click Save
- Manage Fund Access:
- Click Add Fund Access in this tile
- Select the Funds to include and Access Level (View or Edit)
- Check the Additional Permissions boxes to provide the ability to create and/or delete fund records
- Click Save
- Click the ⋮ icon and select Edit account controls
- Check the Fund Creation Access and/or Category Management Access boxes to provide the ability to create new funds and manage obligation categories
- Check the Fund Creation Access and/or Category Management Access boxes to provide the ability to create new funds and manage obligation categories
Users granted access to All Funds will be automatically added to newly created funds too.
Users can have varying access across funds to only see and perform the actions they need to. For example, a Standard User can have View access and the ability to create records on Fund I and Edit access only on Fund II.
Manage a user's permissions
- Navigate to Admin and then select User Management
- Click the user’s name to open their User Details page
- Open the Access Management tab
- In the Platform Controls tile:
- Click Edit
- Check/uncheck the applicable permissions
- Click Save
- In the Fund Access tile:
- To manage account controls:
- Click the ⋮ icon and select Edit account controls
- Check/uncheck the applicable permissions
- Click Save
- To manage fund access and content abilities:
- Click the ⋮ icon on the applicable fund's row and Edit Access or Remove Access
- If editing, make the necessary changes and then Save
- If removing, click Remove Access again to confirm the action
- To manage account controls:
Manage User Groups
Create a custom User Group
|
The Ontra System-Managed User Groups (SMGs) for Platform and Fund Administrators are automatically added to your account; your firm controls who belongs to the group; Ontra manages what the group can do, keeping it current as product capabilities evolve.
Add users to a group
Add a user to a User Group during their initial account creation or anytime after. This applies for custom create groups by your firm or Ontra System-Managed User Groups (SMGs).
|
Define and manage group access
- Once access is granted at the group level, all current and future members of that group receive the same permissions.
- If a user is added to multiple groups, the most permissive level of access will apply.
- You can only manage the access for custom groups your firm has created. System-Managed User Groups (SMGs) are maintained by Ontra.
- Navigate to Admin and then select User Management
- Open the Groups tab
- Locate the group to add users to and click the group name
- Open the Access Management tab
- In the Platform Controls tile:
- Click Edit
- Check/uncheck the applicable permissions and Save
- In the Fund Access tile:
- To manage account controls:
- Click the ⋮ icon and select Edit account controls
- Check/uncheck the applicable permissions and Save
- To manage fund access and content abilities:
- Click the ⋮ icon on the applicable fund's row and Edit Access or Remove Access
- If editing, make the necessary changes and Save
- If removing, click Remove Access again to confirm the action
- To manage account controls:
Perform User Access Audits
The self-serve audit feature is a great tool to help manage compliance reviews and reduce risk. Users with user provisioning access can export a real-time report of each user invited to the system, the funds they have access to, and what level of access they have.
- Navigate to Admin then select User Management
- On the Users tab, click the Actions drop-down menu
- Select Download All Users
- Open the downloaded .xlsx file to review all users, including their user group, role, access level, fund access, and user status