Roles & Permissions
A role is a named set of permissions. Permissions are granted to roles, never to individuals, which is what keeps access reviewable.
Overview
Section titled “Overview”Permissions are granted at three levels: the module (can the user see Sales at all), the document (can they see Sales Invoices), and the action (can they create, edit, cancel or only view). A user needs permission at every level for an action to succeed, which is why “I can see the menu but the button is greyed out” is usually a missing action permission.
Prerequisites
Section titled “Prerequisites”Before you begin
- You are signed in with an administrator role
- You have told affected users that a change is coming
Opening the screen
Section titled “Opening the screen”- Administration
- Security
- Roles
Procedure
Section titled “Procedure”Open the configuration screen
Use the navigation path above. Administrator rights are required.
Make the change
Edit the settings you need. Changes are validated as you type and the screen tells you what else they affect.
Save and verify
Click Save, then sign in as a normal user (or ask a colleague to) and confirm the change behaves as intended before telling the team.
Expected result
The setting is saved and an entry is written to the audit log recording who changed what, and when.
Field reference
Section titled “Field reference”| Field | Type | Required | Default | Description |
|---|---|---|---|---|
| Name | Text | Yes | — | Display name for this roles & Permissions entry. |
| Description | Text area | No | — | What this configuration is for. Shown to other administrators. |
| Applies To | Dropdown | Yes | All branches | Scope of the setting. |
| Status | Dropdown | No | Active | Inactive entries are retained for audit but no longer applied. |
Roles & Permissions fields
Permission levels
Section titled “Permission levels”| Step | Action | Who | Result |
|---|---|---|---|
| 1 | Module permission | Role | Decides whether the menu appears at all |
| 2 | Document permission | Role | Decides whether the screen opens |
| 3 | Action permission | Role | Decides which buttons are enabled |
| 4 | Branch access | User | Decides which records are visible |
| 5 | Approval limit | User | Decides what the user may approve |
How a permission check resolves
A worked example: three roles against the Sales Invoice
| Aspect | Sales Executive | Accounts Clerk | Branch Manager |
|---|---|---|---|
| See the Sales menu | Yes | Yes | Yes |
| Open Sales Invoice | Yes | Yes | Yes |
| Create | Yes | No | Yes |
| Edit a draft | Own only | No | Any |
| Confirm | No | Yes | Yes |
| Cancel a confirmed invoice | No | No | Yes |
| Override the price list | No | No | Yes |
Important notes
Section titled “Important notes”Common problems
Section titled “Common problems”The Save button is disabled
A required field is empty or invalid. Fields in error are outlined in red with the reason underneath — scroll up, the first error is usually in the header.
You do not have permission to perform this action
Your role is missing the relevant permission for this screen. Ask an administrator to check it against Roles & Permissions.
Frequently asked questions
Section titled “Frequently asked questions”Who can perform this task?
Any user whose role grants access to this screen. Roles and Permissions lists exactly which permission controls it.
Is the change audited?
Yes. Every create, edit and cancel is recorded with the user, timestamp and the before-and-after values.