System Roles: Item Permissions
Learn about each type of permissions System Roles can grant to Items of a particular Template or Workflow.
Item Permissions are a collection of abilities granted for specific Templates and Workflows. These permissions allow users to view and work with Items, even if they are not on the Item’s Team.
Pro Tip: The Workflow and Template fields have an "or" relationship. For example, entering a Workflow and a Template applies the permissions to all Items that belong to either the Workflow or the Template.
Location Options
All Item Permissions except for "Participate" also specify where in the Network the Permission is valid. For example, a User might have Edit Permission for Improvements, but that doesn't necessarily mean they can Edit all Improvements in the system. The scope of their Permission depends on to which Locations their Permission is applied.
The Network Locations options are:
- Everywhere: The permission is applied to all Items within the specified Template or Workflow, regardless of what Network Location the Item has.
- Location and Below: The permission is applied to all Items within the specified Template or Workflow that are in the User's Network Location and the Network Locations nested beneath it.
- Only Location: The permission is applied to only Items within the specified Template or Workflow that are in the User's Network Location.
- Only User's: The permission is applied to only Items within the specified Template or Workflow in which the User is also on the Item Team.
- This option is only available on the Assign (Which Items), Toggle Private, and Delete permissions.
- Self: This option is only available on the Assign to (Who/Where) permission. It allows the user to assign the Item to themself.
Pro Tip: KaiNexus will reference an Item's Responsible Location when determining whether a User with a certain System Role has Permission to work with it. If the Item does not have a Responsible Location, it will reference the Originating Location instead.
Item Permissions
Participate
The Participate permission provide the ability to create and participate in Items as team members.
- Most organizations give this permission to everybody everywhere, but some organizations use this permission to limit participation in certain improvement work.
View
Provides the ability to view other Users’ public Items that are not in New status within the selected Location(s).
- This permission can be given Everywhere, Location and Below, or Only Location.
- Most organizations give this permission to everybody everywhere, but some organizations will use this permission to limit the visibility of improvement work across Locations. In order to promote transparency in KaiNexus, General Users will almost always be given this permission at some level.
View New
Provides the ability to view other users' public Items in every status, including New, within the selected Location(s).
- This permission can be given Everywhere, Location and Below, or Only Location.
- This permission should be given to people who should see New Items as soon as they're entered into the system, instead of only being able to see them after they've been assigned or activated.
- This permission is typically given to leaders and/or improvement specialists.
Edit
Provides the ability to edit Items the User has permission to view within the selected Location(s).
- This permission can be given Everywhere, Location and Below, or Only Location.
- This permission is typically given to leaders and/or improvement specialists who should have widespread edit abilities without the ability to view new Items or assign Items.
- Granting this permission results in the Role being upgraded to a Pro license.
Request
Provides the ability to request people to become the Responsible Team Role on an Item within the selected Location(s).
- This permission can be given Everywhere, Location and Below, or Only Location.
- This permission also implicitly grants Edit permissions for Standard Items within the selected Locations.
- This permission is often given to leaders, improvement specialists, and/or managers of a location that should be able to request that people outside their Location(s) work on an item. Often these people will have the Assign permission in their own Location but only the Request permission outside of their Location.
Assign (Which Items)
Provides the ability to assign public Items within the selected Locations. Determines which Items a user can assign, based on the Item’s Location.
- This permission can be given Everywhere, Location and Below, Only Location, or Only User's.
- This permission also implicitly grants the View New, View, and Edit permissions for Standard Items within the selected Locations.
Note: Giving this permission anywhere except for Only User's results in the System Role being a Pro license.
Assign to (Who/Where)
Determines which users you can assign an Item to. Users with this permission can assign Items to users within the selected Location(s).
- This permission can be given Everywhere, Location and Below, Only Location, or Self (meaning you can assign the Item to yourself).
- This permission is typically given to leaders and/or improvement specialists.
View Private
Provides the ability to view other users' Private Items — regardless of status — within the selected Location(s).
- This permission can be given Everywhere, Location and Below, or Only Location.
- This permission is typically given to leaders and/or improvement specialists.
Toggle Private
Provides the ability to make a public Item private or a private Item public in the selected Location(s). A person must also have the Edit permission (described above) or have Primary Edit ability on an Item based on their Team Role in order to toggle the Item's Private status.
- This permission can be given Everywhere, Location and Below, Only Location, or Only User's.
- This permission is typically given to leaders and/or improvement specialists.
Honor Roll
Provides the ability to add or remove Honor Roll from Items the user has permission to view within the selected Location(s).
- This permission can be given Everywhere, Location and Below, or Only Location.
- This permission is often given to leaders, improvement specialists, and/or managers of Locations that should be able to highlight particularly noteworthy Items.
Delete
Provides the ability to delete Items the user has permission to view within the selected Location(s). A person must also have the Edit permission (described above) or have Primary Edit ability on an Item based on their Team Role in order to delete the Item.
- This permission can be given Everywhere, Location and Below, Only Location, or Only User's.
- The permission is usually only given to "superusers." If necessary, though, it can be granted to leaders and improvement specialists in a Location, or to frontline people at the Only Users level.
Learn more about System Roles
- What are System Roles?
- System Roles: Platform and Admin Permissions
- Create a System Role
- System Role Notifications
- View where System Roles are being referenced in the System
