Access Management at Noreja
Core Structure
Noreja Super Admins manage the overall platform and create customer environments (mandants) as well as their initial admins.
Mandants (customers) manage their own internal structure.
Within a mandant, there are:
- Users (regular users and admins)
- Departments (groups of users)
- Only admins can create users and departments and assign users to departments.
Access Control
Noreja combines two approaches to manage access:
1. Role-Based Access (Roles)
Roles define what a user is generally allowed to do.
Each role is based on:
- Feature (e.g. Analyzer, Builder)
- Action (e.g. view, edit, delete, import, export, share)
- Scope (e.g. entire mandant, a specific department, or an individual user)
Roles can be assigned to both individual users and entire departments.
2. Object-Based Access (Sharing)
In addition to roles, specific content can be shared directly, such as:
- Analyzer Tabs & Dashboards
- Dimensions & Entities
- Datasources
- Context (documents and text-based content)
Users can share these objects with other users or departments.
Important:
- When sharing, it can be defined whether the recipient is allowed to re-share the object or not
- Object sharing extends existing roles, but does not fully replace them
Central Administration
Admins have access to a central management page where they can:
- Create users and departments
- Assign users to departments
- Manage roles
- Control access to individual objects
Guiding Principle
The system follows a simple principle:
Roles define the baseline access — sharing enables flexible, case-specific extensions.
This ensures a balance between structure, scalability, and flexibility in collaboration.