Security and Permissions Follow
Security is a critical component of configuring Midnight and determines which areas of the application each user can access. User permissions are applied when a user logs into the system and are controlled through a combination of Employee Settings and Security Roles.
Security roles are assigned through the Employee Permissions screen, while role permissions are managed through Admin Settings > Security > Create Role Right.
Midnight includes several pre-configured security roles designed to support common job functions and business needs. While these default roles are ready to use, you can also create additional roles and customize permissions to meet your organization's specific requirements.
A recommended approach is to:
- Assign each employee to the pre-defined role that most closely matches their job responsibilities.
- Modify the role's permissions as needed to align with your company's security policies and operational requirements.
Important: Each user can be assigned to only one security role at a time.
By properly configuring security roles and permissions, you can ensure employees have access to the tools and information needed to perform their jobs while protecting sensitive data and restricting access to areas that are not relevant to their responsibilities.
Employees
The Employees screen contains a list of all employees configured in Midnight. From this screen, you can create new employee records, update existing employee information, assign security roles, and manage user permissions.
Once created, the employee will be able to log in using the credentials provided and will inherit the permissions associated with their assigned security role. User access can be updated at any time by reopening the employee record and modifying their assigned role or account settings.
To add a new employee:
- Open Admin Settings by clicking the gear icon.
- Select Employees from the menu.
- Click the New Employee button.
- Enter the required employee information. In this demonstration we are using the name "John Smith."
Roles
- Navigate to the Roles tab to assign the appropriate employee role.
Permissions
- Navigate to the Permissions tab to assign the appropriate security role.
Note: At the top of the Security Role screen are three optional security settings that can be used to restrict a salesperson's visibility within the system:
- Limit to Sales Rep on Customer: Restricts the user to viewing and accessing only the customer records for which they are assigned as the Sales Representative.
- Limit to Sales Rep on Estimate: Restricts the user to viewing and accessing only estimates where they are assigned as the Sales Representative.
- Limit to Sales Rep on Order: Restricts the user to viewing and accessing only orders where they are assigned as the Sales Representative.
You may enable any one of these options individually or combine them as needed. These settings are particularly useful for organizations that want to limit sales representatives to their own accounts and ensure users only have access to customers, estimates, and orders directly associated with them.
Note for Legacy Midnight Users: The User Logon and Permissions screen may appear slightly different in earlier versions of Midnight. In addition to assigning a security role, administrators can also manage user login credentials from this screen, including updating employee Usernames and resetting or changing Passwords as needed.
Regardless of the screen layout, this area is used to manage both user access and security settings for employee accounts. Changes made here take effect the next time the user logs into the system.
Dashboard
Next, we will configure the dashboard widgets available to John Smith based on his assigned security role.
For this example, we will skip the Quick Links Report and Job Tracking sections, as they have limited relevance to security configuration and user permissions.
To add a widget for a user:
- Select the checkbox next to the widget you want to add.
- Click Add to move the widget to the Selected Widgets list.
- Multiple widgets can be selected and added at the same time.
Any widgets displayed in the Selected Widgets section will appear on the user's Dashboard.
To remove a widget:
- Select the checkbox next to the widget in the Selected Widgets list.
- Click Remove to take the widget off the user's Dashboard.
The next time the user navigates to their Home screen, their Dashboard will automatically reflect the updated widget configuration.
Note: Dashboard widgets provide quick access to key information and real-time data throughout Midnight. Administrators can customize the Dashboard experience based on each employee's role and responsibilities, ensuring users have easy access to the information most relevant to their daily tasks.
Security
The Security menu contains two setup options used to manage user roles and system permissions.
- Create Roles: Allows administrators to create and manage security roles within Midnight. Security roles are used to group permissions and determine which areas of the system users can access.
- Create Role Rights: Allows administrators to configure the permissions associated with each security role. From this screen, you can define which modules, screens, and functions a role can access, as well as the level of access granted.
Together, Create Roles and Create Role Rights provide the foundation for Midnight's security structure, allowing organizations to control user access and ensure employees only have access to the tools and information required for their job responsibilities.
Best Practice: Start by assigning users to one of Midnight's pre-defined roles, then customize the role's permissions through Create Role Rights as needed. This approach simplifies security management while ensuring users have appropriate access throughout the system.
Create Role
The Create Role screen allows administrators to create new security roles within Midnight. Roles are used to group permissions and define what areas of the system users can access.
To create a new role:
- Navigate to Admin Settings > Security > Create Role.
- Locate the blank gray row at the bottom of the screen.
- Enter the name of the new role in the Role field.
- Click the Save button on the far-right side of the row.
Once the role has been created, it will be available for assignment to employees through the Employees screen.
Note: Creating a role only adds the role name to the system. The new role will not have any permissions until they are configured in Admin Settings > Security > Create Role Rights. After creating a role, you should immediately configure its security permissions before assigning it to users.
Create RoleRights
The Create Role Rights screen is used to configure the permissions associated with each security role. This screen allows administrators to determine which modules, pages, and fields users can access based on their assigned role.
To modify role permissions:
- Navigate to Admin Settings > Security > Create Role Rights.
- Select the role you want to edit.
- Choose the desired Security Level:
- Module: Controls access to entire modules or areas of Midnight.
- Page: Controls access to specific screens or pages within a module.
- Field/Control: Controls access to individual fields, buttons, and controls within a screen.
After selecting the security level, you can grant or restrict access by checking or unchecking the appropriate permissions.
For example, a Sales Representative may need access to the CRM, Estimates, and Orders modules, but may not require access to Admin, Accounting, or other system configuration areas. By configuring the role's permissions appropriately, administrators can ensure users have access only to the functions necessary for their job responsibilities.
The Page and Field/Control security levels provide additional granularity, allowing administrators to restrict specific screens, fields, buttons, or actions without removing access to an entire module.
Best Practice: Start by configuring permissions at the Module level, then use Page and Field/Control permissions only when more detailed access restrictions are required. This approach makes security management easier while maintaining appropriate access controls throughout the system.