Roles and Permission Groups
Role and Permission Group management helps you to configure security on the Conga Platform for CLM users. A role represents a profile (for example, system admin, contract facilitator, general user, and so on). You can create user roles that contain a set of permissions with specific access to objects, records, pages, and administrative functions in applications built on the Conga Platform. You can use the User Interface or REST APIs per your business needs. You can add permission group of the user in
The following are covered in role and permission group management.
- Role-Based Access Control (RBAC) for Users: Conga supports RBAC to grant or restrict access to various applications and data within the Conga Revenue Lifecycle Platform. Conga RBAC supports data access primarily through mechanisms such as object permissions, permission groups, roles, and so on. You can create roles to restrict access to data for certain users based on their functional roles and responsibilities. For instance, if a user is assigned the CongaCLMReadOnlyUser role and navigates to the Contact page, certain options such as Create Contact, Edit, Delete, or Create Contract on the Details page are not displayed for that user.
RBAC controls the menu visibility in modern UI.
- Roles: Roles determine a user's access to applications, objects, records, and permissions to perform actions on the Conga Advantage Platform. A role is assigned to users performing similar tasks and consists of a set of permissions. You can assign roles to the existing users or create a new user and edit the user details to assign roles. For example, Contracts Facilitator, Contract Manager, and so on.
- User Groups: User groups enable you to create groups of individual users with specific roles and permissions. You must add the permission group of the user in .
- Permission Groups: A permission group is a group of object permissions. Permission groups can be assigned to individual users or roles. You can also assign multiple permissions and permission groups to a user to grant access to all the assigned role permissions. For example, with the CongaCLMReadOnlyUser role, a user can view all records they have permission to see when navigating to the Search tab on the Contract Details page.
The following table maps the standard roles to their respective permission groups:
| Feature | Roles | Associated Permission Groups |
|---|---|---|
| Supplier | Business User |
|
| Supplier Manager |
| |
| Supplier Admin |
| |
| Conversations | Internal User | CongaConversationsReadOnlyPermissionGroup for viewing posts, attachments, and responses |
| Internal User | CongaConversationsUserPermissionGroup for creating, editing, and responding within Conversations |
For more information, see Roles and Permission Groups topic in Advantage Platform Administration administrators guide.
Record Type Permissions
Record Type permissions is managed through . By default, all record types within an object are accessible to all users who have access to the object.
- All users can create records using the NDA record type.
- Only users with specific roles (for example, legal team or contract managers) can create records using the MSA record type.
