Permissions: Users must have the Administer or Manage Users privilege to manage users and user groups.
Users are added through User Management in Platform Administration. After a user is added, the user record can be managed using the icons on the right side of the user row.
Groups support streamlined privilege management by defining sets of privileges for specific roles or job functions. For example, when all Data Managers require the same elluminate privileges, a Data Manager group can be created and privileges assigned at the group level. This approach removes the need to assign privileges individually to each user.
Note: A set of default groups is available when a new URL is created for studies. Privilege management is expected to occur primarily through group membership.
Privileges can be system-wide or scoped to Studies, Global Data Stores, Compounds, Programs, or Therapeutic Areas, depending on the privilege. System privileges apply across all applicable entities and do not require a study to be selected.
Important: The View privilege must be assigned for a study to display unless the user has the Administer privilege.
Note: Disabled users do not count against the license limit. The system displays a warning and prevents adding users or studies when the license limit is exceeded.
Create a New User
- Click the 9-dot icon to open the Platform Menu.
- From the Platform Menu, select User Management under Platform Administration.
- Click the Users tab in the master header. By default, the Users tab displays the list of users. An icon to the left of each user name indicates the user type.
- Admin
- User
- Unlicensed User
- Admin
- Click the Add User icon in the master header.
-
The Add New User window opens, allowing entry of user details in the top section and selection of privileges in the bottom section.
Important: If a user is assigned to a group, privileges should be assigned at the group level rather than at the user level.
- Enter the required fields at the top of the window for the user being added. Required fields are identified with a red asterisk (*).
- Username: Enter a unique username used to log in to the system. As a best practice, use a standardized username format such as first initial and last name (i.e., JSMITH). The username must start with a letter, be at least 2 alphanumeric characters long, contain no spaces, and include no special characters.
- First Name: Enter the user's first name.
- Last Name: Enter the user's last name.
- Email: Enter the user's email address.
- Company: Select the company name from the drop-down. Company names are configured in Platform Administration under Configuration.
- Optionally, enter additional information:
- Phone: Enter the user's phone number.
- Fax: Enter the user's fax number.
- Comments: Enter any relevant comments.
- Disabled: Select to deactivate the user account. This option is useful for temporary leaves of absence or when creating accounts prior to a start date.
- Locked: Displays as selected automatically when a user is locked out of the system. Manual selection is not available.
- Select Password Never Expires ONLY when the password should not expire. When selected, the user is never prompted to change the password.
- Select eClinical User when adding an eClinical user to a client URL. This allows access without consuming a license.
- Select Unlicensed User for users who interact only with issues. Unlicensed users can log in and view or respond to assigned issues but have limited access to elluminate. Unlicensed users do not count toward licensed user limits.
-
If Unlicensed User is selected:
The user becomes available in the Assign to User list when creating issues.
By default, access is available for all studies.
The user can be added to groups for issue assignment but cannot be added to groups with Administer privileges.
Study access can be limited using Study Access.
Select Study Access. This option becomes available only after Unlicensed User is selected.
Click the Privileges tab.
Select View.
Click the arrow next to Studies to expand the list.
Select the studies for which the user should have issue access. For selected studies, the username appears in the Assign to User drop-down when assigning issues.
-
- Select Read Only User for users who require visibility into audit events across all users and actions within the URL. This option enables platform viewing without database modification capabilities. No additional configuration is required when selected.
- Assign additional privileges as needed OR, if assigning the user to a Group, proceed to the Select Users for a Group section.
-
The Privileges tab displays by default. Select the appropriate privileges. Privileges may be system-wide or scoped to Studies, Global Data Stores, Compounds, Programs, or Therapeutic Areas. For scoped privileges, click the arrow next to each category to expand and make selections.
Tip: Use the Search field to filter privileges. Enter part of the privilege name and click the magnifying glass icon. To restore the full list, click the X in the search bar.
Note: When selecting Studies, Global Data Stores, Compounds, Programs, or Therapeutic Areas, select All for users who require access to all items. Users with All access automatically receive access to newly added items.
-
- Click Save.
Add Credentials for a User
The Credentials tab is available in the new or edit user window. A Reporting Database username can be added during initial configuration. After the user is saved, an Api Key and Api Secret can be generated.
- Under the Users tab in the Add / Edit User window, click the Credentials tab.
- In the API section (available in the Edit User window after saving), click the Generate / Regenerate button. The Api Key and Api Secret generate and display.
- In the Reporting Database section, enter the Reporting DB Username. This username displays in the My Profile window and must match the connected external database. For more details regarding the Reporting Database, refer to the Configure and Manage the Reporting Database article.
Edit a User
To edit user information, select the appropriate icon to open the user record and make updates.
Use the table below to understand the available icons. Not all icons display for every user.
User Management Icons
| Icon | Description |
|---|---|
| Lock. Unlocks the account. This icon displays only when a user account is locked due to multiple failed sign-in attempts. | |
| Disable / Enable User. Disables or enables a user account. A faded icon indicates the user is disabled. | |
|
Reset Password. Resets the user password and sends a system-generated message. Password reset messages are valid for six hours. Note: Users can also initiate a password reset using the Forgot Password? link on the login page. |
|
| Edit User. Opens the Edit User window to update account information. | |
| Deny Data Stores. Manages the list of Data Stores the user can access. Refer to the Manage Access to Data Stores in Administration article for more information. | |
| Delete User. Deletes the user from the system. Disabling a user is recommended instead of deleting. |
- Click the Edit icon to open the user record.
- Update privileges or other user details as needed.
- Click Save.
Import and Export Users or Groups
When working across multiple environments, user or group lists can be exported from one URL and imported into another. The following export options are available:
- Excel or CSV: Exports a list of existing users or groups from the current environment.
- Template: Exports a blank template that can be completed with user or group details for a future import.
Export a Users or Groups List
- Click the 9-dot icon to open the Platform Menu.
- From the Platform Menu, select User Management under Platform Administration.
- Select the Users or Groups tab in the master header. By default, the Users tab displays. To export groups, select the Groups tab.
- Click the Export icon.
- Select Export to Excel or Export to CSV.
A file named Users_[URLname]_[DateTime] with the selected extension downloads. The exported file includes the following columns: Login, FirstName, LastName, Company, Email, Phone, Fax, Disabled (T/F), Locked (T/F), Unlicensed (T/F), Comments, eClinical User (T/F), and Groups.
Export a Users or Groups Template
- From User Management, select the Users or Groups tab in the master header. By default, the Users tab displays. To export a group template, select the Groups tab.
- Click the Export icon.
- Select Download Template (Excel) or Download Template (CSV).
A file named Users_Template_[URLname]_[DateTime] with the selected extension downloads.
Import Users or Groups
User or group lists can be imported from an Excel or CSV file instead of creating records individually. Files must follow the required format. Use the template available from the Export feature to ensure correct formatting. Group membership can be specified in the import file; privileges are assigned manually in elluminate.
- From User Management, select the Users or Groups tab in the master header. By default, the Users tab displays. To import groups, select the Groups tab.
- Click the Import icon. The Upload Users or Upload Groups window opens.
- Click Choose File, locate the file, and click Open, or Drag the file into the Drop files here area. A list of users or groups from the file displays.
- Clear the checkbox next to any users or groups that should not be imported.
- When importing users, optionally select or clear Send Emails to New Users to control notification emails. This option is not available when importing groups.
- Click Import Selected. A confirmation message displays indicating that users or groups were imported.
- Click OK.
Add a New Group
- Click the 9-dot icon to open the Platform Menu.
- From the Platform Menu, select User Management under Platform Administration.
- Click the Groups tab in the master header.
- Click the Add Group icon in the master header. The Add Group window opens, defaulted to the Privileges tab.
- In the Name field, enter the group name. This is the only required field. The name is limited to 100 alphanumeric characters. Underscores (_) and dashes (-) are allowed.
- In the Comments field, optionally enter relevant information for the group.
-
From the Privileges tab, select the appropriate privileges. Use the scrollbar to view all options. Available Studies, Global Data Stores, Compounds, Programs, or Therapeutic Areas display on the right.
Tip: Use the Search field to filter privileges. Enter part of the privilege name and click the magnifying glass icon. Click the X in the search field to restore the full list.
Important: Assign the View privilege and select the appropriate studies. Without View, studies do not display and other assigned privileges are not accessible.
Note: If Reporting DB is selected for a group privilege, refer to the Configure and Manage the Reporting Database article for details.
- Select the items on the right side of the window for which the group should have the selected privilege.
- Continue adding privileges and selections until the group configuration is complete.
- Click Save.
Select Users for a Group
After a group is created, users can be assigned to the group from the Add Group window. Users can also be assigned to groups during user creation.
- From the Add Group window, click the Users tab.
- Select users from the list. Use the scrollbar to view all users or use the Search field to filter results.
- Click Save.
Configure the Default Landing Page for a Group
Note: When a user belongs to multiple groups with different landing pages, redirection follows alphabetical order of group names.
- From the Add Group window, click the Home Page tab.
- Select the module from the drop-down to set as the group landing page when users sign in.
- Click Save.
Edit a Group
Groups can be managed using the icons at the right of the group row.
- Select a group row.
- Click the Edit icon. The Edit Group window opens.
- Make updates as needed.
- Click Save.
Groups Icons
| Icon | Description |
|---|---|
| Edit Group. Opens the Edit Group window. | |
| Deny Data Stores. Manages Data Store access for the group. | |
| Delete Group. Deletes the group. |
Add a User to a Group
Groups simplify privilege management by assigning predefined privileges to multiple users.
- From the Users tab, click the Edit icon for a user.
- Click the Groups tab.
- Select the checkbox next to the desired group. The user inherits all privileges assigned to the group.
- Click Save.
Search for a User or Group
- From User Management, select the Users or Groups tab.
- Enter all or part of the user name, first name, last name, email address, group name, or description in the Search field.
- Press Enter or click the search icon to filter the list.
Privilege Definitions
Access to elluminate modules and studies, as well as the ability to perform specific actions, will require the appropriate privileges.
| PRIVILEGE | TYPE | DEFINITION |
|---|---|---|
| Administer | System | This privilege provides the user access to all system, module, and study functionality, as well as user configuration. |
| Analytics | Study | This privilege allows the user to view any published sheets within Analytics, as well as create Bookmarks and Stories, but it prohibits the user from making any modifications to the visualizations, such as adding or modifying sheets. |
| Analytics Customize | System | This privilege provides the user with the ability to create a new data model for Analytics or to make modifications to a current data model, such as CDA. |
| Analytics Edit | System | This privilege provides the user with the ability to create, modify and publish sheets within the visualizations. A user must have the 'Analytics' privilege to access the visualizations. |
| Blinded Data Configure | Study |
This privilege allows the user to configure a study for Unblinding / Blinding. This privilege only permits configuring blinded data and does not grant the ability to view blinded data. |
| Blinded Data View | Study |
This privilege allows a user to view blinded data. By default, users cannot see or access blinded data. This privilege can only be assigned at the User level and cannot be added to a Group. |
| Data Central | Study |
This privilege allows the user to access Data Central. The actions a user can take within Data Central are configured within Data Central Configuration and based on the assigned reviewer role. |
| Data Central Designer | Study |
This privilege allows the Data Central user to save and manage public Workspaces, public Visualizations, and public Filter Sets within a defined folder structure and configure the security. It also allows the user to create and manage Patient Profiles, as well as configure and manage Advanced Filters and Data Cuts. |
| Data Quality | Study | This privilege provides the user with the ability to complete validations within the Data Quality module. |
| Delete Study | Study | This privilege provides the user with the ability to delete a study. |
| eDrive Global Read | System | This privilege provides the user with access to the root folder in eDrive. This allows access to any folder outside of the study. The user would still need the 'eDrive Read' privilege to access study folders. |
| eDrive Global Read Write | System | This privilege provides the user with Read / Write access to the root folder in eDrive. This allows access to any folder outside of the study. The user would still need the 'eDrive Read' privilege to access study folders. |
| eDrive Read | Study | This privilege provides the user with Read access to the study folder(s) and all subfolder(s) of the selected study. |
| eDrive Read Write | Study | This privilege provides the user with Read / Write access to the study folder(s) and all subfolder(s) of the selected study. |
| eForms | Study | This privilege provides the user with access to eForms, allowing them to view, enter, edit, and delete any data entered into an eForm. |
| eIQ Review | Study | This privilege provides access to eIQ Review in Data Central. |
| Exporter | Study |
This privilege provides the user with access to the Exporter module within a study, allowing them to export data from elluminate into the following formats: Excel, CSV, Delimited tilde, or Delimited vertical bar. The 'SAS Exporter' privilege is also required to Export in SAS formats. |
| Global Library Configure | System | This privilege allows the user to manage the Global Library used in Mapper. |
| Global PDAP Configure | System | This privilege allows the user to access the Protocol Deviation Assessment Plan (PDAP) under the Metadata Management section of the platform menu and the ability to configure the Global PDAP. |
| Importer | Study | This privilege provides the user with access to the Importer module within a study, allowing them to import data into elluminate. The user can also run an existing import definition or a manual import. |
| Issue Administration | System |
This privilege allows the user to edit Issue Text and the Due By date in the Edit Issue window within Issues and Data Central. This privilege also allows the user to upload an Excel file containing a list of open issues that have been addressed within the uploaded file. |
| Manage Users | System | This privilege provides the user with access to User Management for the purpose of administering user information and access to elluminate. |
| Mapper | System | This privilege provides the user with access to Mapper for building transformations. |
| Mapper Advanced | System | This privilege provides the ability to create Dynamic Mapping Templates. |
| Metadata Editor | System | This privilege provides the user with the ability to edit the available metadata for a study and to remove domains. |
| ODR Analytics | System | This privilege allows read-only access to the Operational Data Repository (the module) and access to the Operational Oversight app within Analytics. |
| ODR Configure | System | This privilege allows the user to configure picklists and fields within the form details and listings of the Operational Data Repository, but no access to the Analytics Operational Oversight app. |
| ODR Read | System | This privilege allows read-only access to the Operational Data Repository. |
| ODR Read Write | System | This privilege allows read and write access to the Operational Data Repository (the module), but no access to the Analytics Operational Oversight app. |
| Patient Profile Configure | Study | This privilege allows users (without the 'Data Central Designer' privilege) to create and manage patient profiles. |
| Patient Profile View | Study | This privilege is no longer needed for new users; however, legacy users will continue to see this as a separate privilege. Users with the Data Central privilege can view the Graphical Patient Profile within Data Central as it was configured. |
| Protocol Deviation Edit | Study | This privilege provides the user with access to the study Protocol Deviations (PDs) Dashboard and allows them to manually add PDs or edit existing PDs. |
| Protocol Deviation View | Study | This privilege provides the user a read-only view of the Protocol Deviations Dashboard. |
| RACT Assessment Read Only | Study | This privilege provides the user read-only access for users to view data in the RACT module. |
| RACT Assessment Read Write | Study | This privilege provides the user with access to the RACT module, and the ability to conduct assessments. |
| RACT Configure | System | This privilege allows the user to configure the RACT module. |
| Read Only User | System | This privilege provides the user with read-only access to the elluminate platform for comprehensive visibility of audit events across all users and actions in the URL. |
| RBM | Study | This privilege provides the user with access to the Risk Based Quality Management (RBQM) module in Data Central. |
| Reporting DB | System | This privilege provides the user with access to the Reporting Database for studies configured for the Reporting Database. Each user with this privilege must also have a Reporting Database username and password. |
| Run Reports | System | This privilege provides the user with access to the Reports module, allowing them to run administrative reports. |
| SAS Exporter | Study |
This privilege provides the user with access to export SAS-specific formats like XPT or sas7bdat. This privilege requires the 'Exporter' privilege, and allows the user to select the option to export in SAS and SAS XPORT formats. |
| SCE | System | This privilege provides the user with access to the SCE module and the ability to navigate to SCE components. |
| SCE Configure | System | This privilege provides the user the ability to edit URL and study settings in SCE. |
| Schedule Reports | System | This privilege provides the user with the ability to schedule reports to run. This privilege requires the 'Run Reports' privilege. |
| Specifications | System | This privilege provides the user with access to the Specifications module, where the user can view and manage specifications for dataset mapping or exception listings for each study. Users will only see and have access to specifications for the studies for which they have permissions. |
| Study Configure | Study | This privilege provides the user with access to create a new study or update any of the configurations related to a study. This privilege also provides the user with the ability to use eForms Designer, create a data Snapshot within elluminate, and configure Data Central studies. |
| System Configure | System | This privilege provides the user with access to the Configuration module, where a user can configure various URL level objects, such as Compounds, Phases, Staging Areas, Data Marts, etc. This privilege is also required for users who will upload to the Standards module. |
| Task Edit | System | This privilege provides the user with the ability to edit and delete all tasks. By default, users can edit and delete only their tasks; with this privilege, they can edit and delete tasks created by other users. |
| Template Configure | System | This privilege provides the user with the ability to create and manage templates. Templates can be used in the creation and management of Studies, Data Sources, and Import Definitions. |
| Unlicensed User | Assigned Issues | This privilege allows non-elluminate users to access Issues that are assigned to them so they can respond. They will have no other access to the elluminate platform. |
| Validator Configure | Studies, Global Data Stores, Compounds, Programs or Therapeutic Areas | This privilege provides the user with the ability to create Validator definitions. This privilege requires the 'Validator View' privilege to work. |
| Validator View | Studies, Global Data Stores, Compounds, Programs or Therapeutic Areas | This privilege provides users to view Validator definitions, run or schedule them, and see the results validation jobs. |
| View | Study | This privilege allows the user to view a study on the elluminate Home Page. The View privilege has the highest precedence; therefore, it must be selected for a study to display on the user’s landing page. Most actions cannot be completed without the 'View' privilege selected. |
For additional privilege details, refer to the elluminate Privilege Definitions and Training Requirements article.