OasisPro · PermissionWorks · IFS Cloud · Permission Sets · Navigation Recording
How PermissionWorks builds IFS Cloud permission sets
from real screen navigation.
PermissionWorks solves IFS Cloud permission management by doing something the traditional approach never does: it watches what users actually do in IFS Cloud and generates permission sets from that real behaviour. No theoretical role mapping. No IFS Solution Manager dependency. No manual identification of every permission point. A representative user navigates their daily IFS Cloud workflows. PermissionWorks records every screen, every action, and every data access. Then it builds the permission set automatically from that evidence.
The traditional IFS Cloud permission approach asks an administrator or consultant to predict what a user needs, then manually map those needs to IFS permission structures. That prediction is always incomplete, often wrong in places, and guaranteed to drift as the system changes.
PermissionWorks inverts that approach. Rather than predicting what a user needs, it observes what a representative user does and generates a permission set that precisely matches that real behaviour. The result is permission sets that are accurate, least-privilege by design, and reproducible consistently across every user in the same role.
PermissionWorks: from real navigation to accurate permission sets, automatically.
A finance manager navigates IFS Cloud for an hour, performing their actual daily tasks — approving purchase orders, running month-end reports, reviewing supplier invoices, adjusting cost allocations. PermissionWorks records every screen they visit and every action they take. It then generates a permission set that gives every finance manager in the business exactly that access, and nothing more.
The PermissionWorks process: from deploy to live permission sets
PermissionWorks follows a structured process that takes an IFS Cloud environment from manual permission management to automated, navigation-driven permission sets in approximately one week. Here is every step in detail.
What PermissionWorks records and how it maps to IFS Cloud permissions
IFS Cloud permissions are structured at multiple levels: menu access, screen access, action rights, field-level access, and data access controls. PermissionWorks captures navigation data at every level and generates permission sets that reflect all of them accurately.
Menu and navigation access
Every menu item and navigation path accessed during the recording session is captured. PermissionWorks maps these to the corresponding IFS Cloud navigator permission structures, ensuring users can reach every screen they need from the standard IFS Cloud navigation without dead links or access denied messages.
Screen and page permissions
Every screen, page, and form accessed is recorded. IFS Cloud's screen-level permission structure is captured accurately, including any sub-pages or tabs within a screen that the representative user visited during their recording session.
Action and command rights
Every action taken on a screen — creating records, modifying fields, posting transactions, approving workflows, printing documents, running processes — is captured. PermissionWorks maps each action to the corresponding IFS Cloud command permission, ensuring users can do what they need to do on every screen they access.
Search and query access
Every search, quick search, and data query performed during the recording session is captured and mapped to the appropriate IFS Cloud data access permissions. Users can query the data sets they need without encountering blank results from missing data access permissions.
Report and output permissions
Every report run, output generated, or document printed during the recording session is captured. This is particularly important for integrating with CrystalWorks — permission sets generated by PermissionWorks accurately cover the Crystal Reports or IFS Report Studio reports that each role uses.
What is not included: least-privilege enforcement
PermissionWorks only generates permissions for what was accessed during the recording session. Screens not visited, actions not taken, and data not queried are not included in the generated permission set. This natural least-privilege enforcement is one of the most significant security benefits of the navigation recording approach.
What PermissionWorks looks like for different IFS Cloud roles
PermissionWorks generates distinct permission sets for every distinct role in the business. Here are examples of how the recording approach works across typical IFS Cloud user profiles.
How PermissionWorks handles IFS Cloud upgrades automatically
Every IFS Cloud major release introduces new screens, new navigations, and new permission points. PermissionWorks handles these through supplementary recording sessions rather than manual review of every change in the release notes.
When IFS Cloud 26R1 was released, it introduced new MWO Service screens, emissions management navigations, and updated service contract screens. Businesses using PermissionWorks ran brief supplementary recording sessions covering the new areas relevant to each affected role. PermissionWorks generated updated permission sets covering the new navigations automatically. The post-upgrade permission gap that typically generates a support queue was resolved before go-live rather than after it.
PermissionWorks turns the twice-yearly IFS Cloud permission update from a manual project into a recording session.
Instead of reviewing release notes, identifying new permission points, and manually updating permission sets before every major release, IFS Cloud teams using PermissionWorks conduct targeted recording sessions covering new areas. The updated permission sets are generated automatically and ready before the upgrade goes live.
Want to see what PermissionWorks generates for your IFS Cloud roles? OasisPro will show you.
Talk to OasisPro. We will walk you through what a PermissionWorks recording session looks like for your environment, and what the generated permission sets cover for your key IFS Cloud roles.
Frequently asked questions about how PermissionWorks works
How accurate are the permission sets generated by PermissionWorks?
PermissionWorks generates permission sets that are as accurate as the recording sessions they are based on. A representative user who navigates their full daily IFS Cloud workflow during the recording session produces a permission set that covers that full workflow precisely. Edge cases, infrequent workflows, or month-end-only processes that are not captured in the initial recording can be covered through supplementary recording sessions or targeted additions reviewed during the validation phase.
Can PermissionWorks handle multi-role users in IFS Cloud?
Yes. PermissionWorks generates separate permission sets for each distinct role and these sets can be combined for users with multi-role responsibilities. Alternatively, a multi-role recording session can be conducted with a user who performs all the relevant workflows, generating a combined permission set for that specific hybrid role. OasisPro advises on the best approach based on how multi-role users are structured in your organisation.
What happens when a user needs access to something not covered in their permission set?
If a user needs access to a screen or action not covered in their existing PermissionWorks-generated permission set, the simplest resolution is a supplementary recording session covering the additional workflow. PermissionWorks generates a targeted addition to the existing permission set covering the new requirement. This is faster and more accurate than the traditional approach of manually identifying the specific permission points needed.
Does PermissionWorks record sensitive data entered during the session?
PermissionWorks records navigation paths, screen access, and action types — not data values. The recording session captures which screens a user visits and what actions they perform, not the specific data they enter or view. OasisPro can walk through the data captured by the recording engine in detail during a consultation for businesses with specific data privacy requirements.
PermissionWorks: IFS Cloud permission sets built from what users actually do, not what we think they need.
The navigation recording approach is the only way to generate IFS Cloud permission sets that are genuinely accurate, genuinely least-privilege, and genuinely maintainable across upgrades. Every other approach is a variation on manual prediction that degrades over time.
OasisPro deploys PermissionWorks in a week and maintains it alongside your IFS Cloud release cadence. Talk to us and we will show you what your permission management process looks like with PermissionWorks in place.
OasisPro are IFS Cloud specialists and the developers of PermissionWorks and CrystalWorks for IFS Cloud customers. · info@oasispro.co.uk · 01865 538071 · oasispro.co.uk