Security roles setup and maintenance
Security roles in MPM define the permissions you can allocate to users within the system.
Users can be assigned multiple roles, which are allocated via Employee Maintenance (see the help guide for setting up employees).
To maintain Security Roles, you must have Administrator security.
Go to Settings > Administration.

The Administration area looks like this.
This section will only refer to Security Maintenance and Role Management.

Managing and creating new roles
To manage the roles available, click on the Role Management tab.
If you are using the standard setup , you will have nine standard roles. Add additional roles for specific purposes if required (for example, a separate role for Offshore or External employees).
In the standard setup, all staff must be either Administrator (full rights) or Staff (lowest level of rights). You can then assign additional roles to individual staff members depending on their requirements. You can also modify the standard setup to best suit your practice.

To create a new role, type the role name in the New Role box and click Add Role.
Warning: You cannot change the name of a role once it has been saved, so please check for spelling and typos before saving or assigning it.
You can delete roles you no longer need; however, you cannot delete a role if any users are currently allocated to it.
Setting up and maintaining permissions on each role
Navigate back to the Security Maintenance tab.
The screen shows Available Security Objects and Assigned Security Objects. You can move objects between these sections by selecting the relevant objects and using the arrows in the middle.
The filters at the top help you navigate between roles and filter the available objects.
Once an object is assigned or unassigned, the change is immediate and available to the user after refreshing their screen. You do not need to save or log out for the changes to take effect.

Understanding the filter objects

API access control and page security
For the primary roles (Administrator and Staff), ensure all objects under these sections are made available.
Module
This controls which modules you see on your home page. To access modules or links to third-party software, ensure the relevant modules are made available.

Main master default menu items
This section controls which items are available in the main menus.
This includes the CRM, Time, Reports, Processing and other menus at the top of the screen, as well as the items within those menus (for example, Billing, Time & Expenses, CRM or Contact Enquiry).
If you allocate items within a menu, make sure you also allocate access to the main menu itself so the user can see and access those items.
Command buttons and object security
This section controls more detailed actions a user can or cannot perform (for example, Approve Fees, Post Fees, and which billing types they can prepare).
These security objects work alongside the Approvals area in Employee Maintenance. For example, a user may have permission to post fees via their security role, but if they have no approvals assigned, they will see the relevant options/buttons and still not be able to post anything.
In this area, some security objects also have CRUD options (Create, Read, Update, Delete). These provide more granular control over what a user can do.
Mostly, these options apply to Client and Contact Maintenance. In the example below, this relates to the TFN (or IRD Number). By allocating the security object, the staff member can read the TFN on the client profile. You can then remove access to enter, change or delete a TFN by unticking the relevant boxes on that specific security object.

Report items
This section allocates individual reports. As you make these available the system will assign the relevant category to allow the report to be picked in the reports page.
You can assign any report to a role
Please be aware that some reports are assigned as they are relevant to quick links/short cuts available to reports in the system e.g. timesheet views or productivity views from the home page. If staff receive an error when trying to run one of these reports, it is because the report has not been assigned for their user security role
Please also note that some reports including some employee reports will show ALL employees details if the report is assigned regardless of the user’s other permissions. Ensure you have tested what users can see if you are not comfortable sharing this information.
Report category
It is recommended to leave this filter. The system will assign categories based on the report items selected.
If you do move a category to ‘available’ the system will assign ALL report items associated with that category.