Every user in MyQ operates within a defined rights scope that controls what they can see and do in MyQ. Most end users do not need explicit rights. A standard user account can still use normal print and scan workflows where the required queues, terminal actions, and policies are already configured. Rights become relevant for the people who need to administer or oversee some part of the environment.
The strategic goal is to match rights to roles, not to individuals. Design your rights model around the administrative roles that exist in your organization before go-live, assign those profiles to groups, and add individuals to the relevant group. This scales better as staff changes: when rights are assigned to groups, a new office administrator can receive the appropriate rights by joining the relevant group.
Available Rights
MyQ provides the following rights, each scoping a specific area of the system:
|
Right |
Scope |
|---|---|
|
Administrator |
Administrator-level access. Delete Cards is assigned separately. |
|
Manage Settings |
Access to Settings management, excluding the Rights tab. Check the current Rights documentation for exact exceptions. |
|
Manage Users |
Access to user and group management, user settings, policies, and limited related accounting, credit, and quota areas. |
|
Manage Printers |
Monitor printers, device settings, terminals configuration. |
|
Manage Queues |
Create, edit, and manage queue status. |
|
Manage Jobs |
Edit other users’ jobs. |
|
Read Jobs |
View other users’ jobs without editing. |
|
Manage Reports |
Create, edit, and organize reports. |
|
Manage Licenses |
View and manage MyQ licenses. |
|
Manage Payments |
Access to the Payments tab. |
|
Manage Projects |
Project creation and management. |
|
Manage Vouchers |
Voucher batch management. |
|
Boost Quotas |
Access to Quota boosts. |
|
Recharge Credit |
Credit recharging, including the user's own. |
|
View Log |
Read-only access to Log and Audit Log. |
|
View Printers |
Read-only access to the Printers tab. |
|
Delete Cards |
Delete other users’ ID cards from the User profile widget, where this right is available. |
Rights accumulate – if a user has individual rights and is also a member of a group with additional rights, they hold all of them simultaneously.
Users With No Rights Assigned
A user with no explicit rights still has access to the Web UI – they are not locked out. Their access is limited compared with users who have administrative rights. They can use the standard user-facing areas of the Web UI, but they cannot access administrative settings or agendas unless rights are granted.
For the majority of end users – people who print, scan, and manage their own jobs – this default state is sufficient. Rights assignments are for people with an administrative or oversight role, not for the general user population.
Assigning Rights in Practice
The following examples show how rights can be matched to administrative roles.
Separating IT administration from user management
An IT administrator needs full system access to configure network settings, printers, and queues – grant them Administrator or Manage Settings. An office manager responsible for user administration and credit recharge may need Manage Users and Recharge Credit. Giving the office manager full Administrator rights is unnecessary and creates risk – they have access to infrastructure settings they are unlikely to understand and should not be changing.
Controlling reporting information
Manage Reports grants broad control over reports. Limit this right to users responsible for maintaining the report structure, otherwise report ownership and organization can become difficult to manage. Restrict Manage Reports to a small number of designated individuals responsible for maintaining a clean report structure. Other users can be left without Manage Reports unless they need to create or maintain shared reports.
Protecting confidential data while allowing administration
In environments where print or scan jobs can contain sensitive or personally identifiable information – legal documents, patient records, financial statements, HR correspondence, etc. – controlling who can see job content may be a compliance requirement. Under GDPR and similar frameworks, access to personal data should be limited to those with a legitimate need, and organizations must be able to demonstrate that technical controls are in place to enforce that limitation. MyQ's rights model supports this directly.
Granting an IT specialist Manage Settings or Manage Queues gives them the access they need to configure and maintain the environment, while withholding Read Jobs and Manage Jobs means job content remains inaccessible to them. The same principle applies to log access: View Log exposes metadata about who printed what and when, which may itself constitute personal data under GDPR. Grant it only to roles with a documented need.
The Audit Log can help show which administrative actions were performed and by whom. Include Audit Log retention in your broader data retention policy where audit records are needed for operational, privacy, or compliance reasons.