Managing roles and authorisations
Last updated:
14 July, 2025
Read this article to find out about the roles used in Formcentric and their associated rights.
Issue your authorisations according to the ‘principle of least privilege’: always give your users only the authorisations that they actually need to do their work. As many rights as they need – but as few as necessary. This reduces the risk of accidental or unapproved changes and protects sensitive form data from unauthorised access.
The two main Formcentric roles
Formcentric makes use of two main roles, which have different sets of responsibilities and access privileges.
Normal users
Typical users : Employees who create and manage forms, but who do not handle any administrative tasks.
Basic functions
Create and edit forms Manage own forms Use form designs Use media
Restricted rights
No access to the Admin centre Cannot invite new users Cannot change the organisational settings
Administrators
Typical users: Team leaders, IT managers or other individuals who are responsible for managing the Formcentric account.
Additional rights
Full access to the Admin centre Management of users and organisational settings Group management and authorisation management System configuration
Administrator rights in detail
3. Form management
Terminating form editing – Terminating editing of a form by other users
5. Authorisations for submissions
What are submissions? Submissions are the form data that is sent in by website visitors. This data is sensitive and business-critical, and must therefore be well-protected.
Group-related rights
Show submissions : View form data → Submissions area Export submissions : Download data as CSV/Excel → Exporting submissions Delete submissions : Remove individual submissions → Deleting submissions
Scope
Individual forms : Rights apply only for specific forms All forms : Rights apply for all of the organisation’s forms
→ Specifying permissions for submissions
Administrators always have all rights for all submissions, independently of their group memberships. These rights cannot be restricted: administrators can always view, export and delete all form data. If a user is a member of more than one group, these rights are cumulative . If Group 1 gives User A read rights for Form X and Group 2 gives this user delete rights for Form Y, then the user can execute both actions.
Important security notes
Grant admin rights sparingly - only to trustworthy individuals Make regular checks of who has which rights Delete accounts of former employees immediately
Other security precautions