Roles and permissions
Build roles out of allow and deny permissions, then assign them to users and invitations.
Roles decide what each user can do. You build a role once — a set of Allow permissions and, if needed, some Deny exceptions — and then assign it to as many people as you like.
The Roles grid sits at the bottom of Configuration → General → Management.
Create a role
- Go to Configuration → General → Management.
- Click Create role at the top of the page.
- Give the role a Name that says what the person does — Cashier, Warehouse, Accounting.
- Under Allow Permissions, search for a permission and pick it. Repeat for everything the role should be able to do.
- Under Deny Permissions, add anything this role must never do, even if another of its permissions would cover it.
- Save the role.
Allow and deny
- Allow grants. A user with no matching allow permission can't reach the screen or action at all.
- Deny takes precedence. If a permission is denied anywhere, it stays blocked no matter how many roles allow it.
Use deny sparingly — for carving one exception out of a broad grant, such as a role that may work with invoices but must never delete them.
Assign roles
Roles are assigned in the same Roles field in two places:
- On the Invite user form, so the person already has the right access the moment they accept. See Invite a user.
- On an existing user, by opening them from the users grid. See Edit or remove a user.
A user can hold several roles; their permissions add up, minus anything denied.
Edit or delete a role
Use the edit and delete icons on the role's row in the Roles grid. Deleting a role removes it from every user who had it, so make sure they still have another role covering the work they do.
The Group field
Alongside roles, each user still has a Group (Legacy) — Default user or Admin. This is the older, coarser access setting that predates roles and is kept for compatibility. Set it to match the person's broad level of access, and use roles for the detail.
Was this article helpful?
