Licenses, User Types & Access Management
Introduction of User Types
Valsight is licensed based on the number of named users. A named user is any natural person authorized by the customer to use the software under the terms stated in the overarching Valsight Agreements.
The maximum number of users is defined by the license. The licensed users are differentiated by user types, whereas each type allows users to use different parts of the application. The current usage and capacity can be viewed on the license page by system admins.
Supported user types:
- Analyst/Basic User: Can access simulation workspaces and build charts, but not change any data (no Scenario Manager access). Can view and create presentations.
- Simulation User: Same as the Analyst/Basic User + can access simulation workspaces, change data in the Scenario Manager, can upload/update/edit data sources and use Workflows.
- Model User: Same as Simulation User + can create and edit projects, models, dimensions, and data sources and use and edit Workflows.
- Unrestricted User: Same as Model User + can be a global admin which lifts all restrictions and enables full access, e.g. to settings and configuration.
Note: User types only impose restrictions on top of access rights, users still need to be given specific rights for each project/model/workspace/presentation/workflow that they want to access. Additionally, this also means that users with a restricted user type (e.g. being a basic user) will not be able to open a project although they have been given access to it.
Valsight Access Management
While there are 4 types of licenses, Valsight offers additional options on how to further define access rights for advanced customization among users.
Places to edit the Valsight Access Management | ||
Licenses | The initial access rights for each user are defined by the license type. Being able to choose between 4 different types of users, enables individually composed license packages. | |
Valsight settings | Access rights | The access rights settings can be reached via the Valsight settings. Here, permissions can be granted in an overview of projects, Models, Workspaces and presentations. Learn more. |
User management | The user management can be reached via the Valsight settings. Here, you can edit the permissions of each individual user. Learn more. | |
Group management | The group management can be reached via the Valsight settings. Here, access rights can be provided by assigning users to groups. Learn more. | |
Data permission classes | The data permission classes can be reached via the Valsight settings under 'Projects > Security'. Data permissions define which data a user can access. They can be configured for a project and will be enforced for Charts in Simulation Workspaces. Learn more. | |
Overview of User Type Access Limitations
Access at a glance
A more readable view of the access limitations. The tables show the maximum possible access for each license type — users still need the relevant access rights granted to reach it.
✓ = allowed
✗ = not allowed
Own items only = only items you created
Names only = the model graph shows only the models you have access to, not all models
With rights = requires that specific permission to be granted
— = not specified in the source
Info:
A Global Admin can grant themselves Project Admin rights on any project, so the Project Admin column represents the maximum access they can reach. Capabilities available only to Global Admins are listed in the Global Admin table below.
Project
Creating a project automatically makes you that project’s admin.
| Capability | Analyst / Basic | Simulation | Model · Can Use | Model · Project Admin |
|---|---|---|---|---|
| Create a project | ✗ | ✗ | ✓ | ✓ |
| Open & view project settings | ✓ | ✓ | ✓ | ✓ |
| Change / edit project settings ¹ | ✗ | ✗ | Own items only | ✓ |
| Delete a project | ✗ | ✗ | Own items only | ✓ |
| Duplicate a project | ✗ | ✗ | Own items only | ✓ |
| Upload a project image | ✗ | ✗ | Own items only | ✓ |
| Change access rights | ✗ | ✗ | ✗ | ✓ |
² Simulation user as project admin — can be set as project admin, but it only affects data sources (see the Data Source table).
³ Analyst as project admin — grants no extra rights.
⁴ Model user as project admin — can only hold "Can Edit" on a model and "Full Access" on a workspace.
Model
Creating a model automatically gives you “Can Edit” rights on it.
Model overview
| Capability | Analyst | Simulation | Model · Read-only | Model · Can Edit | Model · Can Edit + Project Admin |
|---|---|---|---|---|---|
| Create a model | ✗ | ✗ | ✗ | ✗ | ✓ |
| See model graph | Names only | Names only | Names only | Names only | ✓ |
| See / edit model settings | ✗ | ✗ | ✗ | ✓ | ✓ |
| Delete a model | ✗ | ✗ | Own items only | ✓ | ✓ |
| Duplicate a model | ✗ | ✗ | ✗ | ✗ | ✓ |
| Upload a model image | ✗ | ✗ | Own items only | ✓ | ✓ |
In the model
| Capability | Analyst | Simulation | Model · Read-only | Model · Can Edit | Model · Can Edit + Project Admin |
|---|---|---|---|---|---|
| Edit nodes (settings & formulas) | ✗ | ✗ | ✗ | ✓ | ✓ |
| Create / delete nodes | ✗ | ✗ | ✗ | ✓ | ✓ |
| Move nodes | ✗ | ✗ | ✗ | ✓ | ✓ |
| Create sections | ✗ | ✗ | ✗ | ✓ | ✓ |
| Upload data / create data source | ✗ | ✗ | ✗ | ✗ | ✓ |
| Copy nodes | — | — | ✓ | ✓ | ✓ |
| Paste nodes | — | — | ✗ | ✓ | ✓ |
Everyone can: view all formulas & settings, download model data sources, see the data preview, and change validation settings.
Model · Read-only — not possible for project admins; they always have at least "Can Edit".Model · Project Admin — can never have more than "Can Edit" on a model.
Simulation — can be granted "Can Edit" on a model, but it has no effect.
Workspace
Creating a workspace automatically gives you Full Access on it.
Workspace overview
| Capability | Analyst | Simulation · Limited | Simulation · Full | Model · Limited | Model · Full Access |
|---|---|---|---|---|---|
| Create a workspace | ✗ | ✓ | ✓ | ✓ | ✓ |
| Delete a workspace | ✗ | ✓ | ✓ | Own items only | ✓ |
| Duplicate a workspace | ✗ | ✓ | ✓ | Own items only | ✓ |
| Upload a workspace image | ✗ | ✓ | ✓ | Own items only | ✓ |
| See / edit workspace settings | ✗ | ✗ | ✓ | ✗ | ✓ |
| Change access rights | ✗ | ✗ | ✓ | ✗ | ✓ |
| Unshare shared scenarios | ✗ | ✗ | Own items only | Own items only | ✓ |
In the workspace
| Capability | Analyst | Simulation · Limited | Simulation · Full | Model · Limited | Model · Full Access |
|---|---|---|---|---|---|
| Trigger validation | ✗ | ✓ | ✓ | ✓ | ✓ |
| Edit / share in Scenario Manager | ✗ | ✗ | ✓ | ✗ | ✓ |
Everyone can: see shared scenarios, view the Scenario Manager, interact with worksheets, add/edit/delete workspace filters, and change validation settings.
Analyst — can only ever have Limited Access on a workspace (never Full).Creating a workspace — automatically gives Full Access on it, even if you'd otherwise have Limited.
Model · Full Access — also covers project-admin modelers (Full is the highest a modeler gets; Limited isn't possible for project admins).
Data Source
| Capability | Analyst | Simulation · Can Use | Simulation · Project Admin | Model · Can Use | Model · Project Admin |
|---|---|---|---|---|---|
| See data sources | ✗ | ✗ | ✓ | ✗ | ✓ |
| Edit data sources | ✗ | ✗ | ✓ | ✗ | ✓ |
| Upload / create data sources | ✗ | ✗ | ✗ | ✗ | ✓ |
| Delete data sources | ✗ | ✗ | ✗ | ✗ | ✓ |
Export Manager
| Capability | Analyst | Simulation | Model · Can Use | Model · Project Admin |
|---|---|---|---|---|
| View & manage all exports | ✗ | ✗ | ✗ | ✓ |
Everyone can: create exports, and view & update their own exports.
Data Permission Class
| Capability | Analyst | Simulation | Model · Can Use | Model · Project Admin |
|---|---|---|---|---|
| Edit data permission classes | ✗ | ✗ | ✗ | ✓ |
| Decide who gets read / write access | ✗ | ✗ | ✗ | ✓ |
Everyone can: view data permission classes.
Any user, regardless of type, can be granted read or write access to the data covered by a permission class:
- Read — view all line items and their results, without the ability to simulate line-item values.
- Write — view and simulate line-item values.
Dimension
| Capability | Analyst | Simulation | Model · Can Use | Model · Project Admin |
|---|---|---|---|---|
| See dimensions | ✗ | ✗ | ✗ | ✓ |
| Change / edit / delete dimensions | ✗ | ✗ | ✗ | ✓ |
Workflow
| Capability | Analyst | Simulation | Model · Can Use | Model · Project Admin |
|---|---|---|---|---|
| Create / edit workflows | ✗ | ✗ | ✗ | ✓ |
| Create / configure workflow steps | ✗ | ✗ | ✗ | ✓ |
| Update submission data; promote / demote steps | With rights | With rights | With rights | ✓ |
Presentations
| Capability | Analyst | Simulation | Model |
|---|---|---|---|
| Delete presentations | ✓ | ✓ | ✗ |
Everyone can: create and view presentations.
Global Admin
Beyond being able to grant themselves Project Admin on any project, a Global Admin can also, organization-wide:
| Global Admin can | What it means |
|---|---|
| Manage users & groups | Create and delete users and groups |
| Manage presentation access | Change access rights to presentations |
Advanced Configuration
User types are chosen when creating an account and can also be changed later. Disabled users do not count towards the limit. If you have reached the capacity for a certain type and create a new user, that user will be created as disabled. Enabling a user is allowed as long as you don’t exceed the capacity of that user’s type. When logging in via SSO and auto-creating users, the default type of a new account is unrestricted but can be changed by modifying the ‘autoCreatedUserType’ option from the config.yml (see Common SSO Options).