This article explains how to apply Org Unit Masking (a user-level setting in Assure that limits the Organisational Units a user can see to a specific subset of the full structure) to an individual Assure user account. Org Unit Masking is useful in organisations with large hierarchical structures, where most users only need visibility of their own area. Once masked, the user's view of the Organisational Structure is restricted to the selected Masked Parent Org Unit and any units beneath it. The setting is configured within the user profile and requires the Mask Org Unit Supervisor Privilege to be set to Allow.
Prerequisites
- Access to Settings > Organisational Configuration > Users in Assure.
- The Mask Org Unit Supervisor Privilege must be set to Allow on the administrator's Supervisor Privilege profile. If the privilege is not set to Allow, the Masked Parent field will not appear when editing a user account.
- The Manage Users Supervisor Privilege must also be set to Allow, as Mask Org Unit requires it.
When to Use Org Unit Masking
Note: Masking a user also restricts visibility of published module records and documents to those within the masked Org Unit and its children.
How to Apply Org Unit Masking to a User
1. Navigate to Settings > Organisational Configuration > Users.
2. Locate the user account to be masked. Use the search bar to find a specific user if needed.
3. Select the cog icon next to the user and choose Edit to open the user profile.
4. Scroll down within the user profile to the Masked Parent field.
5. Select the Select button/cog wheel icon next to the Masked Parent field.
6. The full Organisational Structure is displayed. Select the required Org Unit - this should be the user's home or top-level Org Unit within their area of the business.
7. Click Save and Close at the bottom of the user profile to apply the changes.
What the Masked User Sees
Note: The Masked Parent field controls what a user can see in the Organisational Structure. It is separate from Role Permissions, which control what data within those visible Org Units the user can access, create, edit, or approve. Ensure the user's Role Permissions are also configured correctly for the Org Units within their masked area.
Behaviour Reference
| Setting | Behaviour |
|---|---|
| Masked Parent set | User sees only the selected Org Unit and its child Org Units |
| Masked Parent not set | User sees the full Org Structure permitted by their Role Permissions |
| Mask Org Unit Supervisor Privilege set to Deny or Inherit | The Masked Parent field does not appear in the user profile edit screen |
Note: The Masked Parent field can only be matched by Org Unit ID when set via the Data Import Tool. It must be a child of the user's Default Unit and cannot be the top-level (root) Organisational Unit for the customer.
AI Metadata
- Product Area: Assure -- Organisational Configuration, User Management
- User Role: System Administrator (requires the Mask Org Unit Supervisor Privilege and Manage Users Supervisor Privilege)
- Tags: Org Unit Masking, Masked Parent, Organisational Structure, User Management, Organisational Configuration, Supervisor Privilege, Org Unit visibility
- Version/Region: All Assure versions; all regions
- Important Synonyms: Org Unit Masking = Masked Org Unit = Masked Parent; Organisational Unit = Org Unit; Organisational Structure = Org Structure = Org Tree; Masked Parent = home Org Unit (user context)
- Suggested Embedding Keywords: mask org unit Assure, Masked Parent user profile, limit org unit visibility Assure, restrict org structure user Assure, apply masking user Assure, Assure user org unit restriction, Masked Parent field Assure user, Supervisor Privilege Mask Org Unit
- Relevant Modules and Cross-Module Implications: This article is scoped to Organisational Configuration (User Management) in Assure. Cross-module implications include: AssureGO+ (a user's Masked Parent Org Unit controls which records and documents are visible within the AssureGO+ portal); Workflow Rules (masked users creating Workflow Rules will only see users who reside within the masked area when selecting assignees and approvers); Portal Configuration (the Masked Parent field in a portal questionnaire and the Portal Dashboard interact with each other -- the Portal Dashboard Org Unit overrides the questionnaire default Org Unit when a Masked Parent is set); Data Import (the Masked Parent field can be set via the Data Import Tool using the Org Unit ID, subject to validation rules).