---
url: /process-functions/userSecurity-user.md
description: A user account, with its security groups, access levels and application tags.
---

# &#x20;User&#x20;

A user account, with its security groups, access levels and application tags.

```js
const user = userSecurity.users.getCurrent();

if (!user.hasGroup("Finance")) {
    user.addGroup("Finance");
}
```

## Constructor

Returned by [userSecurity.users](/process-functions/userSecurity-users) and by [security.application(...).users](/process-functions/security-application-users-interface). It can't be created directly.

## Overview

* **Groups by name or object:** methods that take a group accept its name or a [Group](/process-functions/userSecurity-group).
* **Access levels:** access levels are `"NO_ACCESS"`, `"READ_ACCESS"` or `"WRITE_ACCESS"`.
* **Object types:** object access levels use `"CUBES"`, `"CARDS"`, `"WORKVIEWS"`, `"DIMENSIONS"`, `"PROCESSES"`, `"SCHEDULES"`, `"TABLES"`, `"APPLICATIONS"`, `"MAPPINGS"` or `"VARIABLES"`.

## Methods

### getId `getId()`  {#getid}

Returns the user's id.

### getName `getName()`  {#getname}

Returns the user's name.

### getEmail `getEmail()`  {#getemail}

Returns the user's email address.

### getRole `getRole()`  {#getrole}

Returns the user's role, such as `"MODELLER"`, `"COLLABORATOR"` or `"ANALYST"`.

### isTwoFactorEnabled `isTwoFactorEnabled()`  {#istwofactorenabled}

Returns `true` when the user has two-factor authentication turned on.

### groups `groups()`  {#groups}

Returns the user's groups, as an object with `primary_group` and `groups`.

### hasGroup `hasGroup(group)`  {#hasgroup}

Returns `true` when the user is in a group.

| Parameter | Type | Description |
|---|---|---|
| `group` | `string \| Group` | The group's name, or the group. |

### hasAdminGroup `hasAdminGroup()`  {#hasadmingroup}

Returns `true` when the user is in the admin group.

### addGroup `addGroup(group)`  {#addgroup}

Adds the user to a group. Returns `true` when they were added.

| Parameter | Type | Description |
|---|---|---|
| `group` | `string \| Group` | The group's name, or the group. |

### removeGroup `removeGroup(group)`  {#removegroup}

Removes the user from a group. Returns `true` when they were removed.

| Parameter | Type | Description |
|---|---|---|
| `group` | `string \| Group` | The group's name, or the group. |

### setPrimaryGroup `setPrimaryGroup(group)`  {#setprimarygroup}

Sets the user's primary group. Returns `true` when it changed.

| Parameter | Type | Description |
|---|---|---|
| `group` | `string \| Group` | The group's name, or the group. |

### clearGroups `clearGroups()`  {#cleargroups}

Removes the user from every group.

### getModelAccessLevel `getModelAccessLevel(modelIdOrName)`  {#getmodelaccesslevel}

Returns the user's access level for a model, across all of their groups.

| Parameter | Type | Description |
|---|---|---|
| `modelIdOrName` | `string` | The model's name or id. |

### getObjectAccessLevel `getObjectAccessLevel(modelIdOrName, objectType, objectKey, breakOnAccessLevel)`  {#getobjectaccesslevel}

Returns the user's access level for one object in a model.

| Parameter | Type | Description |
|---|---|---|
| `modelIdOrName` | `string` | The model's name or id. |
| `objectType` | `string` | The object type. See the [list of object types](#overview). |
| `objectKey` | `string` | The object's name or id. |
| `breakOnAccessLevel` | `string` | Optional. Stops checking once this access level is reached. |

### getElementAccessLevel `getElementAccessLevel(modelIdOrName, dimensionIdOrName, elementName, breakOnAccessLevel)`  {#getelementaccesslevel}

Returns the user's access level for an element in a dimension.

| Parameter | Type | Description |
|---|---|---|
| `modelIdOrName` | `string` | The model's name or id. |
| `dimensionIdOrName` | `string` | The dimension's name or id. |
| `elementName` | `string` | The element's name. |
| `breakOnAccessLevel` | `string` | Optional. Stops checking once this access level is reached. |

## Access Tag Methods&#x20;

### tags `tags(application)`  {#tags}

Returns the user's [ElementTag](/process-functions/security-application-elementtag) and [ScreenTag](/process-functions/security-application-screentag) tags in an application.

| Parameter | Type | Description |
|---|---|---|
| `application` | `string` | The application's name or id. |

### elementTags `elementTags(application)`  {#elementtags}

Returns the user's [ElementTag](/process-functions/security-application-elementtag) tags in an application.

| Parameter | Type | Description |
|---|---|---|
| `application` | `string` | The application's name or id. |

### screenTags `screenTags(application)`  {#screentags}

Returns the user's [ScreenTag](/process-functions/security-application-screentag) tags in an application.

| Parameter | Type | Description |
|---|---|---|
| `application` | `string` | The application's name or id. |

### hasTag `hasTag(application, tagNameOrId)`  {#hastag}

Returns `true` when the user has a tag in an application.

| Parameter | Type | Description |
|---|---|---|
| `application` | `string` | The application's name or id. |
| `tagNameOrId` | `string` | The tag's name or id. |

### hasTag `hasTag(tag)`  {#hastag-tag}

Returns `true` when the user has a tag.

| Parameter | Type | Description |
|---|---|---|
| `tag` | `ElementTag \| ScreenTag` | The tag. |

### addTag `addTag(application, tag)`  {#addtag}

Gives the user a tag in an application. Returns `true` when it was added.

| Parameter | Type | Description |
|---|---|---|
| `application` | `string` | The application's name or id. |
| `tag` | `string \| ElementTag \| ScreenTag` | The tag's name or id, or the tag. |

### removeTag `removeTag(application, tag)`  {#removetag}

Removes a tag from the user in an application. Returns `true` when it was removed.

| Parameter | Type | Description |
|---|---|---|
| `application` | `string` | The application's name or id. |
| `tag` | `string \| ElementTag \| ScreenTag` | The tag's name or id, or the tag. |

### setTags `setTags(application, tags)`  {#settags}

Replaces the user's tags in an application. Tags not in the list are removed.

| Parameter | Type | Description |
|---|---|---|
| `application` | `string` | The application's name or id. |
| `tags` | `array` | Tag names, or tags. |

### clearTags `clearTags(application)`  {#cleartags}

Removes all of the user's tags in an application.

| Parameter | Type | Description |
|---|---|---|
| `application` | `string` | The application's name or id. |

### getElementAccessTagLevel `getElementAccessTagLevel(application, dimension, element)`  {#getelementaccesstaglevel}

Returns the access level the user's tags give them for an element in a dimension.

| Parameter | Type | Description |
|---|---|---|
| `application` | `string` | The application's name or id. |
| `dimension` | `string` | The dimension's name or id. |
| `element` | `string` | The element's name. |

### getAvailableScreens `getAvailableScreens(application)`  {#getavailablescreens}

Returns the [ApplicationScreen](/process-functions/security-application-screen) screens the user's tags give them access to.

| Parameter | Type | Description |
|---|---|---|
| `application` | `string` | The application's name or id. |

### hasAvailableScreen `hasAvailableScreen(application, screenIdOrName)`  {#hasavailablescreen}

Returns `true` when the user's tags give them access to a screen. Returns `false` when the screen doesn't exist.

| Parameter | Type | Description |
|---|---|---|
| `application` | `string` | The application's name or id. |
| `screenIdOrName` | `string` | The screen's id or title. |

## Examples

### Manage a user's groups

```js
const user = userSecurity.users.getCurrent();

console.log("Is user in Test Group? " + (user.hasGroup("Test Group") ? "Yes" : "No"));

const added = user.addGroup("Example Group");
console.log("User added to Example Group: " + (added ? "Successful" : "Failed"));

const removed = user.removeGroup("Example Group");
console.log("User removed from Example Group: " + (removed ? "Successful" : "Failed"));

console.log("User Groups: ", user.groups());
```

### Check a user's access

```js
const user = userSecurity.users.getFromEmail("user@example.com");

if (user.getModelAccessLevel("Sales Model") === "NO_ACCESS") {
    script.fail(user.getName() + " can't access the Sales Model.");
}
```

### Give a user an application's tags

```js
const user = userSecurity.users.getFromEmail("user@example.com");

user.setTags("Planning", ["North Region", "Finance Screens"]);
console.log(user.tags("Planning"));
```

## Related

* [Users](/process-functions/userSecurity-users): looks up users.
* [Group](/process-functions/userSecurity-group): a security group.
