Skip to main content

Assign Access Levels to Query-Based Collections

Assign Access Levels to Query-Based Collections to grant specific permissions and resource access to all members of the collection. When you assign an Access Level to a Query-Based Collection, every person or resource in that collection automatically receives the corresponding access to the targeted resources.

Prerequisites

Before assigning Access Levels to Query-Based Collections, ensure you have:

  • Access to manage Query-Based Collections in EmpowerID

Procedure

  1. Navigate to Role Management > Query-Based Collections (SetGroups).
  2. Search for and locate the target Query-Based Collection.
  3. Click the Display Name link to open the collection's View page. Query-Based Collection Display Name
    The View page displays all configuration and access information for the Query-Based Collection. Query-Based Collection View Page
  4. Expand the Access Granted to Query-Based Collection accordion.
  5. Click Add. Add Access Assignment
    The Grant Actor Access page opens, allowing you to configure the Access Level assignment and its scope. Grant Actor Access Page
  6. In the Which Type of Access panel, configure the assignment parameters:
    • Assign Direct to Resource or Other Method: Select the assignment scoping method:
      • Direct — Assigns access to specific individual resources, such as a particular group
      • By Location — Assigns access to all resources within a location and its child locations
      • Relative — Assigns access to resources based on each member's location assignment
      • Belonging to which group — Assigns access to all users and people who are members of selected groups
      • Belonging to which Management Role — Assigns access to all people assigned to selected Management Roles
      • Belonging to which Query-Based Collection — Assigns access to all objects in a different Query-Based Collection
    • Resource Type: Select the type of resource for which you are assigning access, such as Group (Security) or Account
    • Access Level: Select the Access Level that defines the permissions being granted, such as Member or Owner
  7. In the Where: Select Resources or a Location panel, define the scope of the assignment:
    • For Direct assignments, search for and select specific resources
    • For By Location assignments, search for and select the location that defines the resource scope
    • For other assignment types, search for and select the appropriate groups, roles, or collections
  8. In the Why & for How Long? panel, configure justification and temporal settings:
    • Comment or Justification: Enter a comment explaining the purpose of the assignment (optional but recommended for audit purposes)
    • Access Starts: Select a start date and time from the calendar picker (leave blank for immediate activation)
    • Access Ends: Select an end date and time from the calendar picker (leave blank for permanent assignment)
    • Click Add to add the assignment to your pending changes
  9. Repeat steps 6 through 8 to add additional Access Level assignments as needed.
  10. When you have configured all desired assignments, click Submit to commit your changes.

Verify the Results

After submitting your Access Level assignments:

  1. The View page refreshes and displays the updated Query-Based Collection.
  2. In the Access Granted to Query-Based Collection accordion, confirm your assignments appear in the list.
  3. Verify each assignment displays the correct:
    • Resource Type — The type of resource the Access Level applies to
    • Access Level — The specific permissions granted
    • Scope — The assignment method (Direct, By Location, etc.) and target resources
    • Temporal settings — Start and end dates if configured
  4. (Optional) Verify a member of the Query-Based Collection received the expected access