Link Search Menu Expand Document

Permissions

Table of contents

  1. Introduction
  2. Permission Levels Overview
  3. Permission Levels
    1. Group Permissions
    2. Project Permissions
  4. Permission Inheritance
    1. STEM Branch Inheritance
      1. Inheritance Rules
    2. Personal Attributes Inheritance
      1. Group Level Inheritance
  5. Public Sharing
    1. Project Public Sharing
    2. Personal Attributes Public Sharing
  6. Permission Management
    1. Project Permissions
    2. Group Permissions

Introduction

BrainSTEM implements a hierarchical permission system that governs access control across the platform. This system enables flexible collaboration while maintaining data security through inheritance-based permissions.

permissions

Permission Levels Overview

Permission levelsGroupsProjectsPersonal Attributes
Permission scope3 levels, users only4 levels for groups & users4 levels for groups & users
MembersInherit project permissionsRead access to:
- subjects
- sessions
- modules
Read access to:
- attributes
- equipment
Contributors-Create/edit/delete modelsCreate/edit/delete equipment
ManagersAdd/remove membersAdd/remove members & groupsAdd/remove members & groups
OwnersManage group details
Add/remove managers
Edit project details
Add/remove managers
Edit attribute details
Add/remove managers

Permission Levels

Group Permissions

Groups are the foundation of BrainSTEM’s permission system, offering three distinct permission levels:

Permission LevelCapabilities
Owner- Manage group details and settings
- Add/remove managers
- Associate group with laboratory
- Rename group
- Manage public access settings
Manager- Add/remove regular members
- Create member invitations
- Remove users from group
Member- Access group resources
- Inherit project permissions assigned to group
- View group content
- Leave group voluntarily

Project Permissions

Projects implement four permission levels that can be assigned to both individual users and groups:

Permission LevelCapabilities
Owner- Manage project details
- Add/remove managers
- Has all Manager permissions
Manager- Add/remove project members
- Add/remove project groups
- Has all Contributor permissions
Contributor- Create/edit/delete project related models
- Has all Member permissions
Member- Read access to project, project-related subjects
- Read access to sessions and modules

When applied to groups, these permissions extend to all group members automatically.

Group Permission LevelEffect on Group Members
Owner Groups- All group members can manage project details
- All group members can add/remove managers
- Includes all Manager group permissions
Manager Groups- All group members can add/remove project members
- All group members can add/remove project groups
- Includes all Contributor group permissions
Contributor Groups- All group members can create/edit/delete project related models
- Includes all Member group permissions
Member Groups- All group members get read access to project, project-related subjects
- All group members get read access to sessions and modules

Permission Inheritance

STEM Branch Inheritance

The STEM branch follows this hierarchical pattern:

Project
├── Subject
│   ├── Subject Logs
│   └── Procedure
│       └── Procedure Logs
├── Session
│   ├── Behavior
│   ├── Manipulation
│   └── Data acquisition
├── Collection
└── Cohort

Inheritance Rules

Parent LevelInheritance PatternInheriting Components
ProjectAll project components inherit base permissionsSubjects, Sessions, Collections, Cohorts
SubjectDirect inheritance with cascading effectsSubject Logs, Procedures, Procedure Logs (via Procedures)
SessionModule-level inheritanceBehaviors, Data acquisitions, Manipulations

Personal Attributes Inheritance

Personal attributes follow their own inheritance structure from groups:

Personal Attributes
├── Setups
│   └── Equipment
├── Inventories
│   └── Consumable Stocks
├── Data Repositories
└── Behavioral Paradigms

Group Level Inheritance

Parent LevelInheritance PatternInheriting Components
GroupDirect inheritance from associated groupsPersonal Attributes (Behavioral Paradigms, Data Storage, Setups, Inventories)
Experimental SetupDirect inheritance with module-level accessEquipment
InventoryDirect inheritance with module-level accessConsumable Stocks
  • All personal attributes inherit permissions directly from their associated groups
  • Group membership automatically grants access to personal attributes

Public Sharing

Project Public Sharing

When a project is made public:

  • All associated components become publicly accessible
  • Only project owners can make a project public
  • Public access is read-only for anonymous users
  • Authorized users retain their edit capabilities

Personal Attributes Public Sharing

  • Each personal attribute requires individual public sharing settings
  • Only owners can modify public access settings
  • Public status required for behavioral paradigms, data storage, and setups used in public projects

Permission Management

Project Permissions

  • Access: Project page → Manage → Permissions
  • Actions: Add/remove users/groups, modify permission levels, set public access

Group Permissions

  • Access: Group page → Your group
  • Actions: Add/remove members, modify member roles