Skip to content

Users and roles

Verified

Every team member has one role, which decides what they see in the side menu and what they may do. Roles are set in System → Settings → Users. The split follows the work, not trust: a warehouse worker does not need finance, so they do not see it.

There are six roles, ordered from the widest access to the narrowest.

Role What it allows
Administrator Full access, including installation settings and managing other administrators.
Manager Runs the company — everything except admin accounts and installation settings.
HR Invoices, reports and selling prices. Cannot see purchase prices.
Customer support Handles claims, sees stock and packing. Cannot see finance.
Warehouse worker Packing and stock movements. Sees neither claims nor finance.
Read only Views operations. Changes nothing and sees no prices or invoices.

HR, Customer support and Warehouse worker sit at the same level — none outranks the others, each covers a different slice. Support is therefore not “more” than the warehouse; they are parallel roles for different work.

The role is the coarse setting. When something finer is needed, access is tuned with permissions per area. Access is granted as a pair of area + action:

  • areas include Products, Categories, Stock and movements, Stocktake, Stock sync, Purchase prices, Cases, Refunds, Orders, Packing, Shipments and Carriers,
  • actions are Read, Create, Edit, Delete, Export, Import, Print, Approve, Change status, Stock movement, Settings, Payout and Reply.

This is how a warehouse worker can be allowed to print labels without ever seeing purchase prices.

  1. Open System → Settings → Users.
  2. Send an invitation to your colleague’s e-mail address.
  3. Assign the role that matches what they actually do in the system — not their job title.
  4. If needed, fine-tune access with permissions for individual areas.
  5. They set a password through the link in the invitation and sign in.

After their first sign-in, check together that they can see what they need. A missing menu item is almost always a role or permission question, not a fault.

An account can be protected with a second factor: in addition to the password, the application asks for a code from an authenticator app on your phone (for example Google Authenticator or 1Password).

  1. In account settings choose Enable two-factor.
  2. Scan the displayed code with your authenticator app. If scanning is not possible, the key can be entered manually.
  3. Type the six-digit code from the app and confirm.
  4. Store your backup codes away from the phone. If you lose the phone, they are the only way back in.

The number of unused backup codes is shown in settings. When they run out, issue new ones — without them, a lost phone means lost access.

The application distinguishes three different situations, each resolved elsewhere:

  • “You do not have access to this section” — the role lacks permission. An administrator at your company resolves it.
  • “Module not activated” — the role is fine, but that part of the application is not activated for the account. Handled with support.
  • “This section is not available yet” — the record exists, but no screen for it exists in the application yet. Nothing is wrong on the user’s side.
  • A colleague cannot see a screen they need. Check the role first, then the permissions for that area.
  • HR cannot see margin. That is intended: HR cannot see purchase prices, so gross margin derived from them is hidden too.
  • I want to give someone access to just one thing. Assign the narrowest sensible role and top it up with a permission. Do not raise the role for one screen.
  • Even a manager cannot change an administrator. Managing administrators is reserved for administrators. This is deliberate.