The Application User Matrix of Invantive Studio holds every user of the repository against every application, so that access to the applications can be granted and withdrawn in one place. It shows the same rows as "Application Users" under an application, which shows one application at a time. The matrix is available from release 27.0.
What a user may do within an application is decided by the roles the user holds, set in the [[Invantive Studio/User Role Matrix|User Role Matrix]], and by what those roles may reach, set in the [[Invantive Studio/Role Function Matrix|Role Function Matrix]].
## Opening the Matrix
Select "Application User Matrix" under "Security" in the tree. A window opens for the matrix; it is not a dialog, so it stays open beside the tree while other work goes on, and selecting the node again brings it to the front rather than opening a second one. It closes with Invantive Studio.
Opening it needs the function right "Application User List". Changing a cell needs the right "Application User Details" granted for changes; without it the matrix opens for reading and the "Save" button is not shown.
## The Matrix
A row is a user and a column is an application. The users stand in the order of their code, and the name of a user carries the code as well as the full name. The applications are those visible to the user working with the matrix, in the order of their code, and each column is headed by that code. The column on the left names the row and stays in view while the applications are scrolled past.
A cell says what access the user has to that application:
- `-`: no access.
- `R`: read-only access; the user sees the application but may not change it.
- `R&W`: read and write access; the user sees the application and may change it.
A click moves the cell to the next of the three, and the three levels are told apart by their letter as well as by their colour. A cell which differs from what the repository holds is outlined until it is saved.
The access of users to an application can only be changed by a user who may change that application. The column of an application which the user working with the matrix may only read is shown but cannot be changed; a click on it, or a block set across it, leaves its cells as they are.
## Setting a Block of Cells at Once
Press the mouse on a cell and drag to select an area; `Ctrl` adds a second area to the first and `Shift` extends one from the keyboard. A click inside a selected area moves every cell of it to the level after the one the cell pointed at moved to, so an area of mixed levels ends up at one level.
The right mouse button offers "No Rights", "Read" and "Read and Write" by name, plus "Next Level" for the same step a click makes. A menu entry acts on the selected area when it is opened inside it, and otherwise on the one cell it was opened on.
The toolbar carries the same three levels as buttons: "No Rights", "Read" and "Read and Write". A button sets the selected cells to its level, or the current cell when no cell is selected. The buttons make the matrix usable from assistive technology such as a screen reader, which reaches neither a click on a cell nor the menu of the right mouse button. They are not shown when the matrix is opened for reading only.
A selected cell whose row or column has been left out of view is not changed, whichever of these ways sets the area.
## Finding a User or an Application
The search box narrows the matrix to what its text names, matched against the names of the users and the codes of the applications at once. A text which names an application keeps every user and only the column of that application; a text which names a user keeps every application and only the row of that user. The Escape key empties the box and shows the whole matrix again.
Narrowing the matrix changes nothing about the access: a cell which was changed and is no longer shown keeps its new value and is saved along with the rest.
## Leaving Out What Is Granted Nowhere
Two boxes in the toolbar leave out what stands empty.
- "Hide Columns Without a Value" leaves out every application to which no user has access.
- "Hide Rows Without a Value" leaves out every user who has access to no application.
The boxes work on what the search box leaves standing. What is left out keeps whatever was changed in it and is saved along with the rest.
## Saving
"Save" writes the cells which differ from what the repository holds; the others cost no statement. Granting access creates an application user, changing between read-only and read and write updates it, and withdrawing access deletes it again, which is also what the list under an application does.
Saving a large matrix takes a statement per changed cell and can be ended while it runs. The cells written before it was ended keep their new value; pressing "Save" again writes the remainder.
## Closing with Unsaved Cells
Closing the window while some cells are not saved asks whether to save them. "Yes" saves the cells and then closes the window, "No" closes the window without saving, and "Cancel" keeps the window open. "Cancel" is the default answer, so pressing `Enter` neither saves nor discards anything. When saving is ended or fails, the window stays open and shows the cells which were not written.
In release 27.0 closing the window discards the unsaved cells without asking. Also, a cell which is withdrawn, saved, granted again and saved in the same window shows as granted, but the grant is not created again; opening the matrix again shows the cell as not granted. Release 28.0 and its BETA release 27.1 correct both.