Appearance
Lab Management
What is a lab user?
A lab user (or lab member) is an authenticated end-user associated with one or more lab spaces. A successful authentication requires a valid email address or username along with a matching password. A lab user can be invited or join more than one lab. A lab user can only have one active lab during an active session. On the contrary, a guest is an unauthenticated session with limited access to the login page, the password reset page, and the registration page.
A lab user with multiple lab space memberships can freely switch the active lab space at without re-authenticating their session.
What is a lab space?
A lab or lab space is an isolated environment where its lab members can collaborate using resources allocated to the lab. Labs are uniquely identified by its name or its lab code.
There are two types of labs: partner labs and resident labs. A partner lab (also known as a partnership) is derived from a resident lab with similar collaborative tools. The resident lab that is used to create the partner lab is also known as the sponsor lab. The two main exceptions are: 1) that a partner lab cannot be used to create another partner lab and 2) that a sponsor lab bears all billing-related costs incurred by its partner labs.
What can a lab user do in their lab?
A lab user’s capability is usually restricted by their roles. The goal of using roles is to have a set of predefined permissions attached to each role - that way, when a lab user inherits a role, the lab user indirectly inherits the role’s permissions.
There are three roles:
- Lab Admin - The lab admin is also known as the lab administrator. The lab admin has the most important permissions that will allow them to control most resources of the lab.
- Power User - The power user is given some permissions related to some resource management.
- Regular User - The regular user is the role with the least privilege.
A lab user can only inherit one role within each lab that they are associated with. While each role inherits a set of permissions, not all permissions are exclusive to a particular role. Some resources such as project management and file management are open to all roles.
Here is a list of permissions and their description:
- Project Creation - This permission is for the management of projects created by the user.
- Job Creation - This permission is for the management of jobs created by the user.
- Dataset Creation - This permission is for the management of datasets created by the user.
- Image File Creation - This permission is for the management of image files created by the user.
- Lab Log Viewing - This permission is for the viewing of log entries created by various activities that occurred within the lab space.
- Field/Topic Creation - This permission is for the management of fields and topics.
- Field/Topic Switch - This permission allows users to change their working field. Without this permission, the user will always be restricted to the field that they selected during their initial lab registration. If a field selection is not available during the lab registration, then the user has an opportunity to select their field once the fields become available in the active lab.
- Lab Management - This permission allows users to edit the lab account details such as the lab’s introduction, policy statement, allowed email domains, and logo.
- Lab Invitation Limited Management - This permission allows users to invite other users from another lab or guest users to join the lab. However, the invitation can only be configured to grant a regular user or power user role to the invitee.
- Lab Invitation Full Management - This permission is similar to
Lab Invitation Limited Managementexcept for allowing the user to configure the invitation to grant the lab admin role to the invitee. - Partner Lab Management - This permission allows users to manage partner labs created by the resident lab and view other partner lab relationships that the current lab may belong to.
- Lab Users Management - This permission allows users to manage other lab users’ access to the lab.
- Module Creation - This permission allows users to make module submissions.
- File Sharing - This permission allows users to share files with the lab for image and dataset file uploads.
Here is a table showing a list of permissions and roles that inherit them:
| Permission | Regular User | Power User | Lab Admin |
|---|---|---|---|
| Project Creation | yes | yes | yes |
| Job Creation | yes | yes | yes |
| Dataset Creation | yes | yes | yes |
| Image File Creation | yes | yes | yes |
| Lab Log Viewing | no | no | yes |
| Field/Topic Creation | no | no | yes |
| Field/Topic Switch | no | yes | yes |
| Lab Management | no | no | yes |
| Lab Invitation Limited Management | no | yes | yes |
| Lab Invitation Full Management | no | no | yes |
| Partner Lab Management | no | no | yes |
| Lab Users Management | no | no | yes |
| Module Creation | no | no | yes |
| File Sharing | no | yes | yes |
