Skip to content

Roles, assignments, and modules

TEKControl combines roles, organizational assignments, and modules. A role can authorize a type of action, a client/site/post assignment scopes where it applies, and a module controls whether the associated product area is available.

Assign roles

Select one or more roles on Roles. The list is limited by the current administrator's authority. Protected roles such as high-level administration, AI access, or portal-bridge access can require elevated authority and may be hidden.

TEKControl applies a role hierarchy when saving and can remove redundant subordinate roles when a broader selected role already includes them. Always reopen the user and verify the saved effective role set instead of assuming every checked role remains listed.

Assign the narrowest role set that supports the person's work. A user's highest effective role also affects which other accounts they can manage.

Assign clients, sites, and posts

On Sites & Posts:

  1. Select one or more clients.
  2. Select at least one available site.
  3. Optionally select posts belonging to those sites.

Changing clients immediately prunes selected sites that no longer match. Changing sites prunes posts that no longer belong to the selection. Watch for the notification reporting removed selections and review all three cards before saving.

Client assignments are saved from both the explicitly selected clients and the clients that own the selected sites. Clearing a parent assignment can therefore change downstream access even when the user retains the same roles.

Assign modules

The Modules tab appears only for administrators allowed to manage module access and is hidden for limited administrators. It lists assignable product modules within the current administrator's own role, module, and site scope.

Selecting a module does not override its role or site requirements. TEKControl preserves module assignments the current administrator is not authorized to manage, and it can decline a checked module that the administrator does not possess or cannot access through an assigned site.

Verify effective access

After saving:

  1. Reopen the user and verify roles, clients, sites, posts, and modules.
  2. Confirm the intended sites are active.
  3. Test with a non-production or approved test account when the access design is complex.
  4. Review Change History for recorded assignment changes.

Do not grant broad roles or all-site access merely to resolve a missing menu. Identify whether the actual requirement is a role, site, post, module, or feature configuration.