The Role Function Matrix of Invantive Studio holds every role of the repository against every function of every application, so that the authorisations of a role can be granted and withdrawn in one place. It shows the same rows as "Role Functions" under a function and under a role, which show one function or one role at a time. ## Opening the matrix Select "Role Function Matrix" under "Security" in the tree. A window opens for the matrix; it is not a dialog, so it stays open beside the tree while other work goes on, and selecting the node again brings it to the front rather than opening a second one. It closes with Invantive Studio. Opening it needs the function right "Role Function List". Changing a cell needs the right "Role Function Details" granted for changes; without it the matrix opens for reading and the "Save" button is not shown. ## The matrix A row is a function and a column is a role. The functions are those of every application in the repository, in the order of their code, so the functions of one application stand together; the name of a function carries its code as well as its description. The column on the left names the row and stays in view while the roles are scrolled past. A cell says what the role is granted on that function: - `-`: nothing. The role does not see the function at all. - `R`: the role sees what the function shows, but may not change it. - `R&W`: the role sees the function and may change what it shows. A click moves the cell to the next of the three, and the three levels are told apart by their letter as well as by their colour. A cell which differs from what the repository holds is outlined until it is saved. ## Setting a block of cells at once Press the mouse on a cell and drag to select an area; `Ctrl` adds a second area to the first and `Shift` extends one from the keyboard. A click inside a selected area moves every cell of it to the level after the one the cell pointed at moved to, so an area of mixed levels ends up at one level. The area stays selected, and clicking again carries it on to the next level. The right mouse button offers the three levels by name, plus "Next Level" for the same step a click makes. A menu entry acts on the selected area when it is opened inside it, and otherwise on the one cell it was opened on. The toolbar carries the same three levels as buttons: "No Rights", "Read" and "Read and Write". A button sets the selected cells to its level, or the current cell when no cell is selected. The buttons make the matrix usable from assistive technology such as a screen reader, which reaches neither a click on a cell nor the menu of the right mouse button. They are not shown when the matrix is opened for reading only. A selected cell whose row or column has been left out of view is not changed, whichever of these ways sets the area. ## Finding a role or a function The search box narrows the matrix to what its text names, matched against the names of the roles and of the functions at once. A text which names a role keeps every function and only the columns of that role; a text which names a function keeps every role and only the rows of that function. A text which names neither leaves the matrix empty. The Escape key empties the box and shows the whole matrix again. Narrowing the matrix changes nothing about the authorisations: a cell which was changed and is no longer shown keeps its new value and is saved along with the rest. ## Leaving out what is granted nowhere The matrix is mostly empty: a function is granted to a handful of roles, so most of what stands on the screen is a row of `-`. Two boxes in the toolbar leave that out. - "Hide Columns Without a Value" leaves out every role which grants nothing. - "Hide Rows Without a Value" leaves out every function which is granted to no role. The boxes work on what the search box leaves standing, so searching one role and leaving out the empty rows shows the functions of that role and nothing else. What is left out keeps whatever was changed in it and is saved along with the rest. Nothing is recomputed while cells are being changed, so a cell which is set to nothing does not take its row away from under the mouse; clearing the box and ticking it again asks for a fresh answer. ## Saving "Save" writes the cells which differ from what the repository holds; the others cost no statement. Raising a cell from nothing creates a role function, and returning it to nothing deletes that role function again, which is also what the list under a function or a role does. Saving a large matrix takes a statement per changed cell and can be ended while it runs. The cells written before it was ended keep their new value; pressing "Save" again writes the remainder. ## Closing with Unsaved Cells Closing the window while some cells are not saved asks whether to save them. "Yes" saves the cells and then closes the window, "No" closes the window without saving, and "Cancel" keeps the window open. "Cancel" is the default answer, so pressing `Enter` neither saves nor discards anything. When saving is ended or fails, the window stays open and shows the cells which were not written. In release 27.0 closing the window discards the unsaved cells without asking. Also, a cell which is withdrawn, saved, granted again and saved in the same window shows as granted, but the grant is not created again; opening the matrix again shows the cell as not granted. Release 28.0 and its BETA release 27.1 correct both.