User Guide: Add/Remove Badge Access Level Catalog Items
Overview
The 'Badge Access Level' catalog item has been split into two separate processes — Add Access Level and Remove Access Level — with tightened security and a user-friendlier, Protected Asset–based selection experience. Underneath, a new user-centric data model allows access levels to be assigned directly to users, independent of any card CI — the foundation for non-integrated customers, new hires, and guest/visitor scenarios.
What's New
- Two catalog items instead of one — end users request access-level additions; removals are restricted to authorized roles (the 'Access admin' role) only.
- Security fix — the previous Remove Access Level item exposed a user's badge access assignments to anyone submitting a request. Removal requests now validate that the user actually holds the selected access level: if they don't, the request auto-closes with an audit log entry; if they do, it routes to approvers.
- Protected Asset–based filtering — both items start from a friendly "What building or area?" selector; the access level list then shows only the levels applicable to the selected Protected Asset (not the target user's assignments).
- User-direct access levels (data model) — a Bearing User record (name and department, with related lists for access level assignments, devices, and approvals) and a user↔access-level index allow assignments without a card CI. Existing Acre, Seeker/CQ, and RightCrowd flows are unchanged.
How to Use
Adding an access level (end users):
- Open Add Access Level in the catalog.
- Select the building or area (Protected Asset).
- Choose from the access levels available for that Protected Asset and submit; the request routes through the standard approval process.
- Open Remove Access Level (visible to the Access admin role).
- Select the user, the building/area, and the access level to remove.
- If the user holds that level, the request routes to approvers; if not, it closes automatically with an audit entry.
Removing an access level (Access admins):
- Open Remove Access Level (visible to the Access admin role).
- Select the user, the building/area, and the access level to remove.
- If the user holds that level, the request routes to approvers; if not, it closes automatically with an audit entry.