To access items within individual item groups, permissions can be set for each user or assignee group in the user record details on the Permissions tab (Users andGroups→ Users →Specific user →Permissions tab→Item (CI)). Permissions can be restricted to viewing, editing, and deleting records of groups and types, and it is possible to set access only to specific records of groups and item types via the gear icon in the row Records in the permissions list. Permissions can be set for each user, and it is recommended to set them for item types, not for groups.
Making item records available
User access to configuration item (CI) records is controlled by a combination of visibility and specific permissions settings. Visibility determines which CIs are displayed to the user, while permissions define what actions the user can perform on the displayed record (such as read, edit, or delete).
Access to your own records
Any user with access to the CMDB module and the Item record permission enabled automatically has access to the Config Item (CI) records belonging to the companies visible to them if:
- they are listed in the item’s Owner field, or
- the item has no designated Owner.
To access and view your own records at, you must have at least the “View” permission enabled for this permission. If a user only has the “Access – Read” permission enabled at , they will not be able to make any changes to the records—these are available to them for reading only. To allow changes, you must also enable the permission to edit items
, or to delete records
.
Access to third-party records
When the Access to other records permission is enabled in the CMDB configuration database module, the user will also have access to items where a different user is listed in the Owner field. The condition remains company visibility – the user has access only to records of items (CIs) belonging to the companies visible to them.
In this case, permissions for editing and deleting records are governed by the settings for the records themselves. If a user has only the access / read permission enabled for the Item record permission, they will not be able to make any changes to other users’ records. To allow changes, in addition to read access, you must also enable the permission to edit entries
, or the permission to delete records
.
Making subordinate users' records available
The Access to subordinate records permission is one of several specific mechanisms for managing record visibility that is also available for Configuration Management Database (CMDB) items.
When the Access to subordinate records permission is enabled in the CMDB configuration database module, the user will also have access to entries where the Owner field lists a subordinate user or a user subordinate to them (hierarchically lower). The condition remains company visibility – the user has access only to records of items (CI) belonging to companies visible to them.
Permissions for editing and deleting records are also governed by the settings for the records themselves in this case. If a user has only the access / read permission enabled for the Item record permission, they will not be able to make any changes to subordinate records. To allow changes, in addition to read access, you must also enable the permission to edit entries
, or the permission to delete records
.
Manual authorization of access to records (CI)
In practice, there may be situations where it is necessary to grant a user access only to items of specific types or groups of items. To manage access to items of selected types or groups, you can set special permissions for item types and groups—these are located under the gear icon as Permissions (Special) – Permissions for items in dspecific types/groups of items.
This method allows you to set permissions for records (view, edit, create, delete). It is not possible to grant access to records that a user cannot access under general permissions (for example, if a user does not have access to other users’ records, it is not possible to manually grant them access to another user’s record). Special permissions can be used to modify rights for records that are already accessible. For example, if editing item records (CI) is disabled, but editing is enabled for a specific group or item type, the user can only edit items (CI) of that group or type.
Priority when applying permissions: Special permissions at the record level take precedence over general settings. However, if a user does not have access to configuration item records, they will not be displayed even if the item’s visibility has been enabled by a special permission.