- Home
- Blog
- EDGEBIC How-To
- How to Give One User Extra Access in EDGEBIC
Permissions in EDGEBIC by User Solutions come only from roles. There is no per-user override screen, so the way to give one person one extra capability is to build a narrow role and assign it alongside the role they already hold. A user can carry more than one role and rights add up, which makes this both the supported route and a more auditable one than a scattering of individual exceptions. Here is how to do it, and how to reverse it.
Every task in this library is mapped on the EDGEBIC how-to hub. For the foundation this sits on, start with how to create a role.
Before You Start
- The user already exists. Roles attach to a user record.
- You have administrator rights on security.
- You know exactly which permission code the blocked action needs, not just the module it lives in.
- You have decided whether you are adding a capability or taking one away, because those are two different procedures.
Step 1: Work Out Which Direction You Need
Roles only ever add. That single fact determines the shape of the fix.
| What you need | How to get it |
|---|---|
| One person needs one extra thing | A narrow add-on role, assigned alongside their current role |
| Several people need the same extra thing | The same add-on role, assigned to each of them |
| One person must not have something their role grants | A narrower replacement role, assigned instead of the broad one |
| The need is permanent and describes the job | Fold it into their main role |
Nothing you assign can subtract. If the outcome you want is less access than a role provides, no amount of assigning will produce it, and the replacement route is the only one that works.
Step 2: Build the Narrow Role
Open Settings, then Security, then Roles & Permissions, and create a new role.
Tick only the permission the exception is about. Resist the urge to add "while I am here" extras, because the entire value of a narrow role is that its name and its contents match.
Name it for the capability, not the person. Import Operator stays meaningful when Dave moves on; Dave Extra does not. Method in how to create a role.
Step 3: Assign It to the User
Open Settings, then Security, then Users. Select the user and open the edit dialog, then tick the new role alongside the one they already hold. Save.
Their effective access is now the union of both roles. The original role is unchanged, and every other person holding it is completely unaffected.
Step 4: For a Reduction, Swap Rather Than Add
If the goal is to remove one capability from one person, build a role that has everything they need except that capability, for example a Planner that omits delete. Then assign that role in place of the broad Planner rather than in addition to it.
Leaving both assigned achieves nothing, because the broad role keeps granting the right you are trying to withhold. This is the step people get wrong most often.
Step 5: Have Them Sign Out and Back In
The permission set is captured at sign-in. Until the user signs out and signs back in, they keep the access their current session started with, and it will look as though nothing happened. Closing a window is not the same as signing out.
Step 6: Reverse It by Unassigning
When the exception ends, open the user and untick the add-on role. Their access reverts to whatever their remaining roles provide, and the role itself stays available for the next time somebody needs it.
For a replacement role, swap the broad role back in the same way.
How to Check It Worked
- Ask the user to try the action after a fresh sign-in. The direct test, and the only one that proves it.
- Read the role selections back on their user record and confirm exactly what you intended is ticked.
- Check a colleague on the same original role is unaffected. They should see no change at all. If they do, you edited the shared role rather than the assignment.
- Confirm the reduction case actually reduced. After a role swap, have the user attempt the withheld action and confirm it is refused.
Common Mistakes
- Looking for a per-user override screen. There isn't one. Permissions come only from roles.
- Trying to subtract by assigning. Adding a narrower role next to a broad one changes nothing. Swap, do not stack.
- Widening the shared role instead. Ticking the code on the main Planner role gives it to every planner in the plant, which is usually the opposite of the intent.
- Creating one role per person. Name roles for capabilities and reuse them, or you will end up with an access model nobody can audit.
- Forgetting the sign-out. The most common reason a correct change appears not to have worked.
- Leaving temporary add-ons in place. Note the expected end date when you assign one for cover.
See how EDGEBIC controls access across planning, shop floor, and reporting on the EDGEBIC product page.
Expert Q&A: Deep Dive
Q: Two people on the same role need to run imports and the rest of the role should not. One narrow role or two?
A: One narrow role, assigned to both. Build a role containing just the import permissions, give it a name that says what it is for such as Import Operator, and add it to those two users alongside their existing role. Do not create a per-person role, because that is how a shop ends up with fifteen near-identical roles nobody can audit. The other question worth asking is whether this is temporary or structural. If it is coverage while somebody is on leave, note the date you expect to remove it, because an add-on role assigned for two weeks in March is exactly the kind of thing still sitting there in November.
Q: A user says they lost access to something and their role clearly grants it. Where do I look?
A: Since permissions come only from roles and roles only add, the access cannot have been subtracted from them individually, which rules out a whole category of theory immediately. Check first whether a role was removed from the user rather than changed, because the role you are looking at may no longer be assigned to them. Open the user and read the role selections rather than trusting the role screen. Next, confirm they actually signed out and back in, since the permission set is captured at sign-in. Finally, if this followed a software update, a newly shipped permission code goes to the Administrator role automatically but never to custom roles, so a screen that used to work can be gated by a code the custom role has not been given yet.
Frequently Asked Questions
Ready to Transform Your Production Scheduling?
User Solutions has been helping manufacturers optimize their production schedules for over 35 years. One-time license, 5-day implementation.

User Solutions Team
Manufacturing Software Experts
User Solutions has been developing production planning and scheduling software for manufacturers since 1991. Our team combines 35+ years of manufacturing software expertise with deep industry knowledge to help factories optimize their operations.
Share this article
Related Articles
How to Create a Watched-File Integration in EDGEBIC
Create a watched-file integration in EDGEBIC: point it at the file your ERP drops, pick the target entity and import mask, set the debounce, and let a new file trigger the run.
How to Rehearse an Integration With the EDGEBIC Simulator
Use the built-in Simulator to provision demo data, watch real integration runs happen, and prove the mechanism before you point anything at a live ERP. Includes the tear-down rule.
How to Run an Integration Now and Pause All Schedules in EDGEBIC
Force one integration to run with Run Now, cancel a run in progress, disable a single definition, or tick Pause all schedules to stop every automatic sync for the session.
