Assessment permissions
This topic explains how to control who can view, edit, and retake assessments. It defines the roles used in assessments, describes the permission settings in templates and how they flow to assessments, includes a matrix of the actions each role can perform, and provides steps to change permissions on the assessment page.
About assessment permissions
You can protect sensitive assessments by giving specific permissions to individuals. This includes choosing whether an assessment is private or public, and assigning people to collaborate on the assessment. These permissions determine who can view, edit, or retake the assessment, and thus prevent unauthorized access.
Assessment permissions are role-based and differ from global permissions related to Assessments.
Role definitions
- Owner
-
User in the Owner field in the Properties sidebar of an assessment. Typically, the owner of an assessment is the user who created or retook the assessment.
-
Assignee
-
User in the Assignees field in the Properties sidebar of an assessment.
-
Assessments administrator
-
User who has the Assessments Admin global role.
Permission settings in a template
The template used in an assessment defines who can view, start, and retake the assessment, based on the following settings.
| Setting | Description |
|---|---|
| Who can start this |
Determines who can start an assessment on an asset. This setting is available only for templates associated with an asset type; templates not linked to an asset type don't have this restriction. It's a multi-select field: you can select one or more resource roles. By default, this setting is empty, and anyone with a global role that has the Assessments > Conduct Assessments global permission can start an assessment on any asset of the template's asset type. If you select one or more resource roles, only users who hold one of the selected roles on the asset, including roles inherited from a parent domain or community, can start an assessment on that asset. Users without one of the required roles don't see the option to start the assessment, whether from the Lifecycle tracker or the Assessments landing page. A user with the Manage all resources global permission can always start an assessment, regardless of this setting. This restriction is always enforced against the latest published version of the template, not necessarily the version an existing assessment was originally started with. If you retake an assessment for the same asset, this setting isn't checked again, but if you retake it for a different asset, it is. |
| Who can view this |
Determines who can view an assessment. You can select one of the following options:
The owner of an assessment or an Assessments administrator can always change the view permissions of the assessment at the assessment level. |
| Retake type |
Determines how a retake is handled when a user retakes an assessment based on this template. You can select one of the following options:
|
| Who can retake this |
Determines who can retake an assessment. This setting applies only when Retake type (specified in the preceding row) is set to Out-of-the-box retake. You can select one of the following options:
|
How permissions flow from templates
By default, assessments inherit view and retake permissions from their template. The owner of an assessment or an Assessments administrator can change the view permissions of the assessment at the assessment level.
The following table describes where you can manage specific permissions for assessments and templates.
| Permission type | Manage in template | Manage in assessment |
|---|---|---|
| View |
|
|
| Start |
|
|
| Edit |
|
|
| Retake |
|
|
Role-based permissions matrix
The following table summarizes the actions that are available to each role.
| Action | Owner | Assignee | Assessments administrator |
|---|---|---|---|
| View an assessment. |
|
|
|
| Edit answers of a draft assessment. |
|
|
|
| Edit answers of a completed, submitted, or obsolete assessment. |
|
|
|
| Edit the name of a draft assessment. |
|
|
|
| Edit the name of a completed, submitted, or obsolete assessment. |
|
|
|
| Change view permissions of any assessment. |
|
|
|
| Change assignees of any assessment. |
|
|
|
| Change the owner of any assessment. |
|
|
|
| Retake any assessment. |
|
Depends on the template setting |
|
| Complete or submit any assessment. |
|
|
|
| Download any assessment as PDF. |
|
|
|
| Mark any assessment as obsolete. |
|
|
|
| Delete any assessment. |
|
|
|
Change permissions
You can change who can see or edit an assessment, directly on the assessment page.
Prerequisites
- You have a global role with the Assessments > Conduct assessments global permission.
- You either have the Assessments Admin global role or are the owner of the assessment.
Steps
- Open the Assessments landing page..
- Click the assessment whose permissions you want to change.
- In the Properties sidebar, click the current value in each of the following sections, select the required option, and then click
.
Section Option Result Permission to View Everyone Public. Everyone can see the assessment. Permission to View Only Owner and Assignees Private. Only the owner and selected assignees (in the Assignees field) can see the assessment.
Permission to Edit Owner Owner can:
- Edit the name and answers if the assessment status is Draft.
- Change the view permission and assignee of the assessment.
- Complete or submit the assessment.
- Mark the assessment as obsolete.
- Delete the assessment.
The owner of an assessment is the user who created or retook the assessment. Only an Assessments administrator can change the owner, regardless of the assessment status.
Permission to Edit Assignees Assignees can:
- Edit answers if the assessment status is Draft.
- Complete or submit the assessment.
Your changes to permissions are saved.
What happens next
- When the view or edit permissions of a submitted assessment are updated, the change is automatically recorded as a comment on the History tab of the linked review asset, showing the new permissions.
- If notifications are enabled in the template, an email is automatically sent to someone whenever they are set as the owner or assignee of a draft assessment.