Skip to content

4. Users, Roles, and Workflow

All UFZ employees are able to log in to GeoNetwork using their UFZ credentials and become a Registered User this way. The assignment of groups is conducted by the User Administrators of the respective groups at a later stage. The privileges of Registered Users include the access to unrestricted records as well as their own groups records. Guests from outside UFZ on the other hand are only able to see the former.

4.1 Concept of Users and Roles

In addition to common roles as Editor, Registered User or Guest, there is also the Reviewer in GeoNetwork: Besides the administrator, the Reviewer is the only one able to enable metadata records to be published on the intranet or internet.

The following table contains an overview of all roles existing in GeoNetwork as well as their respective privileges:

Profile Types (→) / Associated Privileges (↓) Admin. User Admin. Reviewer Editor Reg. User Guest Privilege Description
View Metadata All Group Group Group Group Free Ability to view the metadata
Download Data All Group Group Group Group -
Getting Data Download Notification All Group Group Group Group - Receiving notification if data attached to the metadata record is downloaded
Viewing Interactive Map All Group Group Group Group - Ability to get an interactive map (which has to be created using a Web Map Server)
Creating & Editing Records All Group Group Group - - Ability to create new and edit existing records
Setting Privileges All Group Group Own - - Ability to edit privileges for metadata records
Allow Publication All Group Group - - - Ability to give final clearance on the metadata publication (Intranet / Internet)
Creating & Editing Users All Group - - - - Ability to create new and edit existing users
Creating & Editing Groups All - - - - - Ability to create new and edit existing groups

Legend : All = „all records“; Group = „own groups records“; Own = „own records“4; Free = „free records“

Accordingly, the privileges connected with these roles can be summarized as follows:

  • Administrator: Ability to create, edit, or delete all user and group profiles, as well as all metadata records; system administration and configuration privileges
  • User Administrator: Ability to create, edit, or delete user profiles and metadata records in the respective group(s)
  • Reviewer: Ability to create, use, and in particular publish metadata records in the respective group(s) (as well as free metadata); a Reviewer of a certain group is by default also an Editor therein.
  • Editor: Ability to create and use metadata records in the respective group(s) (as well as free metadata)
  • Registered User: Ability to use metadata in the respective group(s) (as well as free metadata)
  • Guest: Ability to view free metadata

Within GeoNetwork there is the possibility to manage the access to a particular record very specifically (→5.4). The range of options extends from “only the author“ to “everyone“ and includes various intermediate steps.

4.2 Workflow in GeoNetwork

The relations and interactions between different roles, as well as possible actions concerning metadata records are summarized by the following figure (→F1):

figure 1 : work flow in GeoNetwork

figure 1 : work flow in GeoNetwork

Taking into account the concept of users and roles (→4.1) the key aspects can be condensed as follows:

  • Thanks to the LDAP linkage all employees of UFZ are able to login to GeoNetwork. They are then assigned the status Registered User automatically. Registered User can be assigned User Administrator, Reviewer or Editor.
  • The Administrator defines groups, as well as one or more User Administrators for each group.
  • The groups User Administrator defines at least one Reviewer for his/her group, as well as an arbitrary number of Editors.
  • Consequently a Registered User can become an Editor of one or more groups.
  • Editors are able to create new metadata records as well as to set their privileges. They submit these records to the Reviewer, who checks them for correctness and completeness.
  • It is the Reviewers task to allow a records publication, or return it to the Editor for revision until a satisfying result is attained.
  • Only members of the corresponding group are allowed to download the resources connected to metadata records (if they are not excluded by the records privilege settings)
  • External users (Guests) are only able to access unrestricted metadata records.