Licenses, User Types & Access Management

Introduction of User Types

Valsight is licensed based on the number of named users. A named user is any natural person authorized by the customer to use the software under the terms stated in the overarching Valsight Agreements.

The maximum number of users is defined by the license. The licensed users are differentiated by user types, whereas each type allows users to use different parts of the application. The current usage and capacity can be viewed on the license page by system admins.

Supported user types:

  1. Analyst/Basic User: Can access simulation workspaces and build charts, but not change any data (no Scenario Manager access). Can view and create presentations.
  2. Simulation User: Same as the Analyst/Basic User + can access simulation workspaces, change data in the Scenario Manager, can upload/update/edit data sources and use Workflows.
  3. Model User: Same as Simulation User + can create and edit projects, models, dimensions, and data sources and use and edit Workflows.
  4. Unrestricted User: Same as Model User + can be a global admin which lifts all restrictions and enables full access, e.g. to settings and configuration.

Note: User types only impose restrictions on top of access rights, users still need to be given specific rights for each project/model/workspace/presentation/workflow that they want to access. Additionally, this also means that users with a restricted user type (e.g. being a basic user) will not be able to open a project although they have been given access to it.

Valsight Access Management

While there are 4 types of licenses, Valsight offers additional options on how to further define access rights for advanced customization among users.

Places to edit the Valsight Access Management

Licenses

The initial access rights for each user are defined by the license type. Being able to choose between 4 different types of users, enables individually composed license packages.

Valsight settings

Access rights

The access rights settings can be reached via the Valsight settings. Here, permissions can be granted in an overview of projects, Models, Workspaces and presentations. Learn more.

User management

The user management can be reached via the Valsight settings. Here, you can edit the permissions of each individual user. Learn more.

Group management

The group management can be reached via the Valsight settings. Here, access rights can be provided by assigning users to groups. Learn more.

Data permission classes

The data permission classes can be reached via the Valsight settings under 'Projects > Security'. Data permissions define which data a user can access. They can be configured for a project and will be enforced for Charts in Simulation Workspaces. Learn more.

Overview of User Type Access Limitations

Access at a glance

A more readable view of the access limitations. The tables show the maximum possible access for each license type — users still need the relevant access rights granted to reach it.

= allowed
= not allowed
Own items only = only items you created
Names only = the model graph shows only the models you have access to, not all models
With rights = requires that specific permission to be granted
= not specified in the source

Info:

A Global Admin can grant themselves Project Admin rights on any project, so the Project Admin column represents the maximum access they can reach. Capabilities available only to Global Admins are listed in the Global Admin table below.

Project

Creating a project automatically makes you that project’s admin.

CapabilityAnalyst / BasicSimulationModel · Can UseModel · Project Admin
Create a project
Open & view project settings
Change / edit project settings ¹Own items only
Delete a projectOwn items only
Duplicate a projectOwn items only
Upload a project imageOwn items only
Change access rights
¹ Includes importing scenarios and configuring variables.
² Simulation user as project admin — can be set as project admin, but it only affects data sources (see the Data Source table).
³ Analyst as project admin — grants no extra rights.
⁴ Model user as project admin — can only hold "Can Edit" on a model and "Full Access" on a workspace.

Model

Creating a model automatically gives you “Can Edit” rights on it.

Model overview

CapabilityAnalystSimulationModel · Read-onlyModel · Can EditModel · Can Edit + Project Admin
Create a model
See model graphNames onlyNames onlyNames onlyNames only
See / edit model settings
Delete a modelOwn items only
Duplicate a model
Upload a model imageOwn items only

In the model

CapabilityAnalystSimulationModel · Read-onlyModel · Can EditModel · Can Edit + Project Admin
Edit nodes (settings & formulas)
Create / delete nodes
Move nodes
Create sections
Upload data / create data source
Copy nodes
Paste nodes

Everyone can: view all formulas & settings, download model data sources, see the data preview, and change validation settings.

Model · Read-only — not possible for project admins; they always have at least "Can Edit".
Model · Project Admin — can never have more than "Can Edit" on a model.
Simulation — can be granted "Can Edit" on a model, but it has no effect.

Workspace

Creating a workspace automatically gives you Full Access on it.

Workspace overview

CapabilityAnalystSimulation · LimitedSimulation · FullModel · LimitedModel · Full Access
Create a workspace
Delete a workspaceOwn items only
Duplicate a workspaceOwn items only
Upload a workspace imageOwn items only
See / edit workspace settings
Change access rights
Unshare shared scenariosOwn items onlyOwn items only

In the workspace

CapabilityAnalystSimulation · LimitedSimulation · FullModel · LimitedModel · Full Access
Trigger validation
Edit / share in Scenario Manager

Everyone can: see shared scenarios, view the Scenario Manager, interact with worksheets, add/edit/delete workspace filters, and change validation settings.

Analyst — can only ever have Limited Access on a workspace (never Full).
Creating a workspace — automatically gives Full Access on it, even if you'd otherwise have Limited.
Model · Full Access — also covers project-admin modelers (Full is the highest a modeler gets; Limited isn't possible for project admins).

Data Source

CapabilityAnalystSimulation · Can UseSimulation · Project AdminModel · Can UseModel · Project Admin
See data sources
Edit data sources
Upload / create data sources
Delete data sources
Data source access requires Project Admin — Analyst and plain "Can Use" users have no access to data sources at all.

Export Manager

CapabilityAnalystSimulationModel · Can UseModel · Project Admin
View & manage all exports

Everyone can: create exports, and view & update their own exports.

Data Permission Class

CapabilityAnalystSimulationModel · Can UseModel · Project Admin
Edit data permission classes
Decide who gets read / write access

Everyone can: view data permission classes.

Any user, regardless of type, can be granted read or write access to the data covered by a permission class:

  • Read — view all line items and their results, without the ability to simulate line-item values.
  • Write — view and simulate line-item values.

Dimension

CapabilityAnalystSimulationModel · Can UseModel · Project Admin
See dimensions
Change / edit / delete dimensions
Dimension access requires Project Admin — Analyst, Simulation and Model·Can Use have no access to dimensions.

Workflow

CapabilityAnalystSimulationModel · Can UseModel · Project Admin
Create / edit workflows
Create / configure workflow steps
Update submission data; promote / demote stepsWith rightsWith rightsWith rights

Presentations

CapabilityAnalystSimulationModel
Delete presentations

Everyone can: create and view presentations.

Global Admin

Beyond being able to grant themselves Project Admin on any project, a Global Admin can also, organization-wide:

Global Admin canWhat it means
Manage users & groupsCreate and delete users and groups
Manage presentation accessChange access rights to presentations

Advanced Configuration

User types are chosen when creating an account and can also be changed later. Disabled users do not count towards the limit. If you have reached the capacity for a certain type and create a new user, that user will be created as disabled. Enabling a user is allowed as long as you don’t exceed the capacity of that user’s type. When logging in via SSO and auto-creating users, the default type of a new account is unrestricted but can be changed by modifying the ‘autoCreatedUserType’ option from the config.yml (see Common SSO Options).

Was this page helpful?