CapitalKnowledge

Administering Domains, Roles and Users

Roles

The Roles facility enables a selection of permissions and a change policy to be collected together under one name. Usually, a role equates to a job description. A role may be applied to a user account or a user group. If a user does not possess a permission for a certain function, an explanatory message is displayed whenever they attempt to carry out that function.

  • Permissions

  • Change Policy

Capital Access Manager provides a number of predefined roles based on common job descriptions. Each role has the typically required permissions enabled for that job description. For example, the predefined role of Designer includes permissions applicable to any user working with the design tools of the Capital software suite. Other predefined roles include, Librarian, Project Administrator, SBOM Engineer, System Administrator, and User Administrator.

Two example supplied roles, and some of the permissions they have enabled, are displayed below:

Figure 13: Example Set of Permissions Associated with the Predefined Designer Role

Figure 14: Example Set of Permissions Associated with the Predefined System Administrator Role

When a role is assigned to a user, Capital makes sure that the user has all the permissions that are defined in the role. Permissions configured for a role assigned to a user account can be overridden using the Permissions tab for that user (from the Edit User Account dialog box) if that user account is not in Derived Access Control (DAC) mode. If the user account is in DAC mode, you cannot edit the permission directly in the account, instead they are enforced by the user groups to which that account belongs (see Derived Access Control).

Be aware of the following behavior for an account not in DAC mode:

Scenario 1:

  • Assign a role to a user.

  • Remove permissions at the user level which have been granted by the role (instead of editing the role).

  • Remove the role from the user; the permissions for that user do not change at this point.

  • Re-assign the role to the user; the permissions for the user now include all granted permissions of the role.

Scenario 2:

  • Assign a role to a user.

  • Add permissions at the user level which were not previously granted by the role (instead of editing the role).

  • Remove the role from the user; the permissions for that user do not change at this point.

  • Re-assign the role to the user; the permissions for the user now include all granted permissions of the role and those manually added at the user level.

  • Creating and Editing a Role

Parent Topic:

Administering Domains, Roles and Users

Capital Access Manager User Guide, 2512.2606

Unpublished work. © 2026 Siemens

Source: https://docs.sw.siemens.com/en-US/doc/861057055/202511026.capital_am_user/id3e6c20ce-74cc-415f-b53f-de6a059c83c4 · retrieved 2026-07-18