This section is specific to DriveWorks 24 onwards, for earlier DriveWorks versions please see Security Settings.
The security settings task provides the ability to administer Users, Teams and Roles in order to control who can login to the group.
The Security Settings task lists all Users, Teams and Roles that have been added to the Group.
When a group is created the following security details are created:
Allows editing and running of all projects added to the group.
Belongs to the Administrators team.
These defaults adopt a simplistic security model, based on a flat team structure where permissions are granted for each project.
A more scalable, hierarchical model can also be adopted where permissions are assigned to Roles.
With a permissions based security model Teams can have a hierarchical structure, for example:

This is important when defining the scope for a Role.
With Roles the required actions and scope are applied to securable features to form a permission.
A securable feature can be the following:
Projects can have the following actions applied:
Business Objects can have many other actions applied such as:
The scope tells the Role where the permission is allowed in the Team hierarchy.

When a user logs into a group, DriveWorks will determine what securable feature the user can access.
This is decided by both the user and the securable feature existing in the Team hierarchy.
For instance:
If a User and a Project (the securable feature) are in the same Team, the Role will say the user has access to the Project because they are in the same Team.
Roles can be applied to Teams and Users and each can have one or more Roles.
Access is given if any applied Role grants the permission.
For example:
In the image below the User will have Specify and Update permissions granted.
| ![]() |
The logged in user must belong to a team that has the Administer Group Security option checked (see Edit Team) in order to Add and Edit Teams.
To add a new team:
Each Team Name must be unique
Team Names must be alphanumeric but can contain _ or a space.
See Info: DriveWorks Limits for more information.
The Edit Team dialog launches immediately after a team is added.
To edit an existing team:
The Edit Team dialog can also be launched by double clicking on any property (excluding the Name) in the list view.
The Edit Team dialog has six tabs that allow options to be selected:
This is the name given when the team was created.
The team name cannot be changed.
The team must be recreated to apply a new name.
The team display name can be surfaced in various security functions.
Determines if members of the Team can use the Security Settings task to administer group security.
Determines if members of the Team can administer DriveApps.
This setting requires the Group to be re-opened for the changes to be applied.
Determines if members of the Team can use the SOLIDWORKS addin to administer captured information in the group.
Determines whether members of the Team can see and edit all specifications created in the group, even if they are created by members of other Teams.
Checking this setting will override any Team permissions applied in the Specification Flow.
See To Edit Teams for an Operation or Transition for more information.
If the team is to be a child of another team select the parent from the drop down box.
A Role given to a team will observe the applied scope.
This allows users to be added to the team
When adding users the following can be applied:
The user must exist in order to add it to the team memberships.
This allows a Role to be assigned to the user in the Team.
Roles can also be assigned to a Team (see Roles) in which case the Role will apply to each user in the team.
The Role must exist in order to add it to the user memberships.
To add a membership:
This is optional select (None) to not apply a role.
To edit a role applied to a user:
Ctrl select to edit multiple existing users.
To remove a membership
Ctrl select to edit multiple existing users.
All roles added to the Security Settings will be displayed in the list.
For example:

All projects that exist in the group will be displayed in the list.
For example:

This is a legacy setting from versions prior to DriveWorks 24.
When implementing role based security please disregard this setting.
To change permissions for Group Table access:
Available permissions are:
The Team Name cannot be changed.
The team must be recreated to apply a new Team Name.
To change the display name:
The display name can also be changed by:
Or
A team can be deleted from the system by:
Ctrl select to delete multiple teams.
Clicking No will cancel the operation.
The logged in user must belong to a team that has the Administer Group Security option checked (see Edit Team) in order to Add and Edit Roles.
To add a new role:
Each role name must be unique
Role names must be alphanumeric but can contain _ or a space.
See Info: DriveWorks Limits for more information.
The Edit Role dialog launches immediately after a team is added.
To edit an existing role:
The Edit Role dialog can also be launched by double clicking on any property (excluding the Name) in the list view.
The Edit Role dialog has two tabs that allow options to be selected:
This is the name given when the role was created.
This tab displays all the permissions that can be applied for the role.
The view is split into the Actions that can be applied, and the Scope for that action.
Typically the view will only show Project actions.
More action types will be displayed if, for instance, CPQ Sales Portal is being used (in which case all actions that can be applied to Business Objects will be shown).
A Role (for a project) has two actions:
This allows the role to specify projects.
Access to individual projects is defined in the team. (See Edit Team - Projects)
This allows the role to update projects.
Access to individual projects is defined in the team. (See Edit Team - Projects)
Each action can have a scope applied.
The action will apply anywhere in the team hierarchy (parent of the team, the team and descendants (children) of the team).
The action will apply to the team only.
The action will apply to descendants (children) of the team.
The action will apply to the team and its descendants (children).
To configure permissions for the role:
For example:

For example:

The logged in user must belong to a team that has the Administer Group Security option checked (see Edit Team) in order to Add and Edit Users or Reset and Clear User Passwords.
Each user required to have access to the group must be added individually.
This is the Login name.
Each login name must be unique.
Login names must only contain alpha or numeric characters.
See Info: DriveWorks Limits - User Name for more information.
The Edit User dialog launches immediately after a user is added.
To edit an existing user:
The Edit User dialog can also be launched by double clicking on any property (excluding the Name) in the list view.
The Edit User dialog has two tabs that allow options to be selected:
The General tab displays the following:
This is the name given when the user was created.
The Login name cannot be changed.
The user must be recreated to apply a new login name.
The Login Name of the logged in user can be used in a rule by referencing the Special Variable - DWCurrentUserName
The Display Name of the logged in user can be used in a rule by referencing the Special Variable - DWCurrentUserDisplayName
The Email Address of the logged in user can be used in a rule by referencing the Special Variable - DWCurrentUserEmailAddress
A Team Leader (checked) can see all specifications (in the Specification Explorer or History page of DriveWorks Live) created by other users in the same Team.
When unchecked only specifications created by this user will be visible.
When checked the user is active and will be able to login to the group.
Uncheck to disable a user from logging in.
This allows the users memberships to be added, edited or removed.
The user can be assigned memberships of the following:
The Team must exist in order to add it to the users memberships.
This allows a Role to be assigned to the user in a Team.
Roles can also be assigned to a Team (see Edit Team) in which case the Role will apply to each user in the team.
The Role must exist in order to add it to the users memberships.
To add a membership:
This is optional select (None) to not apply a role.
To edit a role applied to a membership
Ctrl select to edit multiple existing memberships.
To remove a membership
Ctrl select to edit multiple existing memberships.
The Login name cannot be changed.
The user must be recreated to apply a new login name.
To change the display name:
The display name can also be changed by:
Or
A user can be deleted from the system by:
Ctrl select to delete multiple users.
Clicking No will cancel the operation.
This will apply a password or an existing password can be reset for a user.
There are no limits or restrictions to the length or characters that can be used for a password.
See Info: DriveWorks Limits - User Password for more information.
The default Admin password can be changed and we do recommend this is done.
However, once changed this is irretrievable if lost or forgotten.
Please take care to remember the Admin password.
It can be reset by DriveWorks Ltd. However this may incur a charge.
The Specification Task Update User Password can be used to implement password update in a project.
The password for any user can be cleared.
This will allow the user to login without a password.
Clicking No will cancel the operation.
The list of Teams and Users is refreshed by clicking the Refresh button from the command bar.
When a Project in the Group uses any of the Security Tasks (for example Add New Team) the Team and User data can become out of sync.
Use the Refresh button to get the latest Security data.
The Security Settings list can be be filtered by using the filter at the top of the list.
Please see the topic How To Use Filters for more advanced filtering information.
To filter on a specific column include the column name followed by a colon and the filter term, for example:
Type:Team
Will filter the list to display all Teams only.
Each column can be sorted by clicking on the column heading.
Each click will step through sorting the column by ascending, descending or no sorting.
DriveWorks Pro Server supports Microsoft Entra ID Single Sign-On.
Using this authentication method, users added to the Security Settings view are mapped to Microsoft Entra ID Accounts.
Permissions to edit and run projects are administered in Security Settings.
The following functions return information about security settings:
The following special variables return information from security settings:
The following specification tasks can be used administer security settings:
The user logged into the group that uses these tasks must be a member of a team that can administer group security.
Users are added to teams to control their access to projects. Each user has a name and a password which they use to log on to a group.
Teams are groups of users. Each team has a configurable set of permissions which govern whether the users in that team can capture models, and edit and/or specify certain projects in the group.