Skip to main content

Roles and permissions

A role is a named set of modules, each at an access level. Users hold one or more roles, and between them those roles decide what the platform shows.

A module that does not offer the three levels grants full access as soon as it is ticked.

Creating a role

Create Role asks for the Domain, the Project it belongs to and a User Role Name, then opens the permission tree.

The permission tree

The tree mirrors the sidebar, so what you tick here is what the user sees there. Search modules... narrows it when the list is long.

Ticking a group ticks everything inside it. Un-ticking removes them.

The three access levels

Modules that support it show three options:

LevelWhat it allows
AllFull access - create, read, update and delete
EditChange existing records - no create or delete
Read onlyView only - no changes of any kind

New selections default to All. Setting a level on a group applies it to everything already ticked inside - it never grants anything new.

Not every module offers the three levels

The radios appear only on modules that genuinely enforce them - Adapter, Connection, DB Lookup, Integrations, Lookup Tables, Partner Network, Rate Inbox, Script, Template Manager, Transmission and Workflow. A module without the option grants full access once selected. So for anything else, ticking it means the user can change it.

A user whose role restricts a module sees a Read only or Edit only badge on that screen, so they know why a button is disabled.

Which role is in effect

A user with several roles picks one in the top bar, and that single role decides what they see. Switching reloads the app. If something is missing for a user who should have it, check which role they have selected before changing the role itself.

Copying a role to other projects

Roles belong to a project. Copy to Projects recreates the same role in the projects you pick, reporting Copied N · Skipped N - a project that already has a role of that name is skipped rather than overwritten.

Restricting Administration itself

A role can also narrow which Administration tabs an administrator sees - Users, Roles, Projects, Plans, Products and Certificate can each be ticked.

Ticking one Administration tab restricts the role to the ticked ones

An administrator whose role ticks none of them keeps every tab. Tick even one and the role is narrowed to exactly what is ticked. A role grant alone never gets a non-administrator into Administration.

Setting up the homepage for a role

Configure Homepage, on an existing role, opens the homepage in edit mode so you can lay out which cards that role lands on.