Skip to content
Training manualGetting started

Roles and permissions

Build a role from individual permissions, cap what each role can discount, and protect the fiscal year.

A role is a named set of permissions — items, sales, purchasing, reports, each split into view and edit. Every user has one. This is where the system's discipline comes from: a cashier who cannot open the ledger, a supervisor who can approve a return but not change a price list, an accountant who can post journals but not close the year. None of it depends on anyone remembering a rule.

Roles and permissions
  1. Open Organization → Roles. The default roles cover the usual positions; open one to see exactly which permissions it holds before deciding whether you need a new one.

  2. To create a role, name it and tick permissions group by group. View lets someone see a screen; Edit lets them change it. A report role, for instance, might view everything and edit nothing.

    Roles and permissions — 2
  3. Set the role's maximum discount percentage. The register enforces it — a cashier cannot key in more, whatever they type. An individual user can be given their own limit that overrides the role's.

  4. Two permissions deserve care. Closing or reopening the fiscal year is its own permission, separate from general accounting access. And exporting reports is separate from viewing them, so figures do not leave the building by accident.

Good practice

  • Start from the tightest role that does the job and add permissions when someone actually needs them — the reverse is much harder to unwind.
  • Review the Activity log after granting a new role; it shows every add, edit and delete with who did it and when.