How PermissionWorks Builds IFS Cloud Permission Sets from Real Screen Navigation | OasisPro

OasisPro · PermissionWorks · IFS Cloud · Permission Sets · Navigation Recording

How PermissionWorks builds IFS Cloud permission sets
from real screen navigation.

 · 9 min read ·  IFS Cloud PermissionWorks Feature Deep Dive

PermissionWorks IFS Cloud permission sets navigation recording automated OasisPro

PermissionWorks solves IFS Cloud permission management by doing something the traditional approach never does: it watches what users actually do in IFS Cloud and generates permission sets from that real behaviour. No theoretical role mapping. No IFS Solution Manager dependency. No manual identification of every permission point. A representative user navigates their daily IFS Cloud workflows. PermissionWorks records every screen, every action, and every data access. Then it builds the permission set automatically from that evidence.

The traditional IFS Cloud permission approach asks an administrator or consultant to predict what a user needs, then manually map those needs to IFS permission structures. That prediction is always incomplete, often wrong in places, and guaranteed to drift as the system changes.

PermissionWorks inverts that approach. Rather than predicting what a user needs, it observes what a representative user does and generates a permission set that precisely matches that real behaviour. The result is permission sets that are accurate, least-privilege by design, and reproducible consistently across every user in the same role.

PermissionWorks: from real navigation to accurate permission sets, automatically.

A finance manager navigates IFS Cloud for an hour, performing their actual daily tasks — approving purchase orders, running month-end reports, reviewing supplier invoices, adjusting cost allocations. PermissionWorks records every screen they visit and every action they take. It then generates a permission set that gives every finance manager in the business exactly that access, and nothing more.

Navigation recording engine Automatic set generation Least-privilege by design Multi-role support Upgrade-proof No Solution Manager One week to deploy All IFS modules
Real
Navigation data from actual user behaviour — not theoretical role predictions or manual mapping
Auto
Permission sets generated automatically from recording data, not assembled manually permission by permission
Least
Privilege access by design — users get exactly what their real navigation requires and nothing beyond it
1 week
From PermissionWorks deployment to validated permission sets live in your IFS Cloud environment

The PermissionWorks process: from deploy to live permission sets

PermissionWorks follows a structured process that takes an IFS Cloud environment from manual permission management to automated, navigation-driven permission sets in approximately one week. Here is every step in detail.

1
OasisPro deploys and configures PermissionWorks
PermissionWorks is installed in your IFS Cloud environment. OasisPro configures the recording engine, the permission set generation parameters, and the output structure to match your IFS Cloud setup. This initial deployment typically takes one to two days and requires no changes to IFS Cloud itself.
2
Identify representative users for each role
Working with your IFS Cloud team, OasisPro identifies a representative user for each distinct role in your organisation. The representative user for a role is the person whose IFS Cloud workflow most accurately reflects what that role actually needs to do. One representative per role is typically sufficient, though complex roles may use two or three to cover all workflows.
3
Recording sessions: representative users navigate IFS Cloud
Each representative user performs their normal IFS Cloud workflows with PermissionWorks recording active. They navigate to the screens they use, perform the actions they take daily, and access the data they need. The recording session captures every navigation point: every screen visited, every action taken, every search performed, every record accessed. A comprehensive recording session for a typical role takes one to two hours.
4
PermissionWorks generates permission sets from the recording data
PermissionWorks processes the navigation recording and maps every screen, action, and data access point to the corresponding IFS Cloud permission structures. It then generates a complete permission set that grants access to exactly what was recorded and nothing beyond it. The generated permission set is a standard IFS Cloud permission set structure that can be reviewed, adjusted if needed, and applied directly to user profiles.
5
Validation and refinement
OasisPro reviews the generated permission sets with your IFS Cloud team. Any scenarios not captured in the recording session — edge cases, infrequent workflows, or month-end-only processes — are either covered through supplementary recordings or handled through targeted manual additions to the generated sets. This validation phase ensures the permission sets are complete before deployment.
6
Permission sets applied and PermissionWorks maintained
The validated permission sets are applied to IFS Cloud user profiles. For new users added to an existing role, the pre-generated permission set is applied immediately — no further recording or mapping required. For future IFS Cloud upgrades, new recording sessions capture any new navigations introduced by the release and PermissionWorks updates the permission sets accordingly.

What PermissionWorks records and how it maps to IFS Cloud permissions

IFS Cloud permissions are structured at multiple levels: menu access, screen access, action rights, field-level access, and data access controls. PermissionWorks captures navigation data at every level and generates permission sets that reflect all of them accurately.

🗺️

Menu and navigation access

Every menu item and navigation path accessed during the recording session is captured. PermissionWorks maps these to the corresponding IFS Cloud navigator permission structures, ensuring users can reach every screen they need from the standard IFS Cloud navigation without dead links or access denied messages.

📱

Screen and page permissions

Every screen, page, and form accessed is recorded. IFS Cloud's screen-level permission structure is captured accurately, including any sub-pages or tabs within a screen that the representative user visited during their recording session.

Action and command rights

Every action taken on a screen — creating records, modifying fields, posting transactions, approving workflows, printing documents, running processes — is captured. PermissionWorks maps each action to the corresponding IFS Cloud command permission, ensuring users can do what they need to do on every screen they access.

🔍

Search and query access

Every search, quick search, and data query performed during the recording session is captured and mapped to the appropriate IFS Cloud data access permissions. Users can query the data sets they need without encountering blank results from missing data access permissions.

📊

Report and output permissions

Every report run, output generated, or document printed during the recording session is captured. This is particularly important for integrating with CrystalWorks — permission sets generated by PermissionWorks accurately cover the Crystal Reports or IFS Report Studio reports that each role uses.

🔒

What is not included: least-privilege enforcement

PermissionWorks only generates permissions for what was accessed during the recording session. Screens not visited, actions not taken, and data not queried are not included in the generated permission set. This natural least-privilege enforcement is one of the most significant security benefits of the navigation recording approach.

What PermissionWorks looks like for different IFS Cloud roles

PermissionWorks generates distinct permission sets for every distinct role in the business. Here are examples of how the recording approach works across typical IFS Cloud user profiles.

💰
Finance Manager
Recording covers AP/AR screens, supplier invoice approval, GL posting, cost centre reporting, month-end close processes, and financial report outputs. Result: precise finance permission set covering exactly those workflows.
📦
Procurement Officer
Recording covers purchase requisition creation, PO approval, goods receipt, supplier management, and contract review. Permissions generated for the procurement workflow precisely, with no access to finance posting screens not needed by the role.
🔧
Maintenance Engineer
Recording covers work order management, MWO Service, equipment history, spare parts, and safety authorisation screens. Generated permission set covers the full MRO workflow including 26R1 MWO enhancements automatically.
🏭
Production Planner
Recording covers manufacturing orders, routing, BOM access, shop floor scheduling, and material requirement screens. Permissions generated for the full production planning workflow without access to financial or HR areas.
🚛
Warehouse Supervisor
Recording covers inventory management, goods receipt, stock movement, location management, and despatch processing. Permission set covers the warehouse workflow, including barcode and mobile screens used by the team.
📊
Executive / Read-Only
Recording covers dashboard access, business intelligence screens, report running, and KPI views across the relevant business areas. Read-only permission set generated automatically, with no accidental write permissions included.

How PermissionWorks handles IFS Cloud upgrades automatically

Every IFS Cloud major release introduces new screens, new navigations, and new permission points. PermissionWorks handles these through supplementary recording sessions rather than manual review of every change in the release notes.

When IFS Cloud 26R1 was released, it introduced new MWO Service screens, emissions management navigations, and updated service contract screens. Businesses using PermissionWorks ran brief supplementary recording sessions covering the new areas relevant to each affected role. PermissionWorks generated updated permission sets covering the new navigations automatically. The post-upgrade permission gap that typically generates a support queue was resolved before go-live rather than after it.

PermissionWorks turns the twice-yearly IFS Cloud permission update from a manual project into a recording session.

Instead of reviewing release notes, identifying new permission points, and manually updating permission sets before every major release, IFS Cloud teams using PermissionWorks conduct targeted recording sessions covering new areas. The updated permission sets are generated automatically and ready before the upgrade goes live.

Also from OasisPro
PermissionWorks covers your reports in permission sets. CrystalWorks keeps them running after 26R1.

PermissionWorks includes report access in every generated permission set. But from IFS Cloud 26R2, Crystal Reports itself is removed. CrystalWorks is the only SAP-approved solution that keeps your RPT files running. Deploy both together and your reporting workflow survives every IFS Cloud upgrade.

Read: How CrystalWorks works →

Want to see what PermissionWorks generates for your IFS Cloud roles? OasisPro will show you.

Talk to OasisPro. We will walk you through what a PermissionWorks recording session looks like for your environment, and what the generated permission sets cover for your key IFS Cloud roles.

Frequently asked questions about how PermissionWorks works

How accurate are the permission sets generated by PermissionWorks?

PermissionWorks generates permission sets that are as accurate as the recording sessions they are based on. A representative user who navigates their full daily IFS Cloud workflow during the recording session produces a permission set that covers that full workflow precisely. Edge cases, infrequent workflows, or month-end-only processes that are not captured in the initial recording can be covered through supplementary recording sessions or targeted additions reviewed during the validation phase.

Can PermissionWorks handle multi-role users in IFS Cloud?

Yes. PermissionWorks generates separate permission sets for each distinct role and these sets can be combined for users with multi-role responsibilities. Alternatively, a multi-role recording session can be conducted with a user who performs all the relevant workflows, generating a combined permission set for that specific hybrid role. OasisPro advises on the best approach based on how multi-role users are structured in your organisation.

What happens when a user needs access to something not covered in their permission set?

If a user needs access to a screen or action not covered in their existing PermissionWorks-generated permission set, the simplest resolution is a supplementary recording session covering the additional workflow. PermissionWorks generates a targeted addition to the existing permission set covering the new requirement. This is faster and more accurate than the traditional approach of manually identifying the specific permission points needed.

Does PermissionWorks record sensitive data entered during the session?

PermissionWorks records navigation paths, screen access, and action types — not data values. The recording session captures which screens a user visits and what actions they perform, not the specific data they enter or view. OasisPro can walk through the data captured by the recording engine in detail during a consultation for businesses with specific data privacy requirements.

PermissionWorks: IFS Cloud permission sets built from what users actually do, not what we think they need.

The navigation recording approach is the only way to generate IFS Cloud permission sets that are genuinely accurate, genuinely least-privilege, and genuinely maintainable across upgrades. Every other approach is a variation on manual prediction that degrades over time.

OasisPro deploys PermissionWorks in a week and maintains it alongside your IFS Cloud release cadence. Talk to us and we will show you what your permission management process looks like with PermissionWorks in place.

OasisPro are IFS Cloud specialists and the developers of PermissionWorks and CrystalWorks for IFS Cloud customers.  ·  info@oasispro.co.uk  ·  01865 538071  ·  oasispro.co.uk