Skip to main content

Roles and permissions

This page lists what each role opens and what it is allowed to do. To create users and assign roles, see Users and roles.

How access works​

  • Roles are built in. There are fifteen, and you choose which ones each user holds. You cannot define your own roles or switch individual permissions on and off.
  • A user can hold several roles. Access adds up: someone with Purchase Admin and Inventory Admin sees both sets of menus.
  • Most modules have two levels. The User level can look at the module's records. The Admin level can also create, approve and cancel. The exact split is listed per module below.
  • Menus the user may not open are hidden, and the server refuses the matching requests as well.
  • A role change applies at the user's next sign-in. Changing someone's roles signs them out.

The roles​

Role (as shown)CodeIn one line
Super AdminROLE_SUPER_ADMINThe built-in admin account. Everything, and the only one who can make another user an Admin.
AdminROLE_ADMINEverything in every module, plus users, roles and company details.
UserROLE_USERCan sign in. Opens no module by itself.
Sales AdminROLE_SALES_ADMINRuns sales: orders, delivery challans, invoices, approvals.
Sales UserROLE_SALES_USERWorks enquiries and quotations; sees orders and invoices.
Purchase AdminROLE_PURCHASE_ADMINRuns purchasing: approvals, receipts, vendor bills and payments.
Purchase UserROLE_PURCHASE_USERRaises requisitions and purchase orders for approval.
Inventory AdminROLE_INVENTORY_ADMINRuns the stores and the product master.
Inventory UserROLE_INVENTORY_USERSees stock, warehouses and material requests.
Production AdminROLE_PRODUCTION_ADMINRuns production: BOMs, work orders, masters, job work.
Production UserROLE_PRODUCTION_USERSees work orders, schedule and shop floor.
Accounts HeadROLE_ACCOUNTS_HEADAccounting, plus filing returns and statutory entries.
Accounts AdminROLE_ACCOUNTS_ADMINAccounting, plus approval policies.
Accounts UserROLE_ACCOUNTS_USERDay-to-day accounting.
PlannerROLE_PLANNERThe Planning Desk, with a view of purchase, inventory and production.

Which menus each role sees​

Every signed-in user sees the Dashboard and their own Account Settings. The rest depends on the roles held. The User and Admin level of a module see the same menus; they differ in what they may do there.

MenuSalesPurchaseInventoryProductionAccountsPlannerAdmin
Products → Master✓✓✓✓✓✓✓
Products → Bill Of Material✓✓✓
Production✓✓✓
Manufacturing✓✓✓
Sales✓✓
Company (customers and vendors)✓✓✓✓
Purchase✓✓✓
Inventory✓✓✓
Quality → Inspections✓✓✓✓
Configuration → Item Code✓✓✓✓✓✓✓
SuperAdmin (users, roles, company details)✓
Accounting module✓✓
Planning module✓✓

What sits under each menu:

MenuScreens
ProductionSchedule Views, Shop Floor, Work Orders, Job Work Challan, Make or Buy, Machine Assets, OEE Dashboard (and Planning Desk for planners)
ManufacturingWork Center, Downtime Reasons, Production Job, Labor Roles, Holiday Calendar
SalesPipeline Desk, Revenue Desk, Enquiries, Quotations, Sales Orders, Delivery Challans, Invoices
PurchasePurchase Orders, Requisitions
InventoryDashboard, Warehouses, Stock Transfers, Pick Lists, Packing Slips, Material Requests
AccountingMasters, Vouchers, Reports, Approvals, GST, TDS

What each level can do​

Sales​

Sales UserSales Admin
Pipeline Desk and Revenue Desk✓✓
Create and edit enquiries and quotations✓✓
See the sales order, delivery challan and invoice lists✓✓
Create or edit a sales order✓
Approve or reject a sales order✓
Create a delivery challan or an invoice✓
Cancel an invoice; raise and confirm a credit note✓
See an order's profitability✓
Customers under Company✓✓

Purchase​

Purchase UserPurchase Admin
Create and edit requisitions and purchase orders✓✓
Approve or reject a requisition or a purchase order✓
Record a goods receipt (GRN)✓
Enter and post vendor invoices; record vendor payments✓
Raise and confirm a debit note✓
Purchase analytics, pending-receipt and overdue lists✓
Vendors under Company✓✓

An Inventory Admin can also record goods receipts, vendor invoices, vendor payments and debit notes, so the stores can take in material without a purchase role.

Inventory​

Inventory UserInventory Admin
See stock, warehouses, transfers, pick lists, packing slips, material requests✓✓
Create or edit a product in the master✓
Add, correct or remove stock; opening stock✓
Approve or reject material requests✓
Create, dispatch, receive or cancel a stock transfer✓
Create or edit warehouses and locations✓
Stock count and stock reconciliation✓
Raise an inspection✓

Production​

Production UserProduction Admin
See work orders, schedule, shop floor, machines and the OEE dashboard✓✓
See bills of material and the manufacturing masters✓✓
Create or edit a work order✓
Issue material, cancel or short-close a work order✓
Create or edit a bill of material; change its status✓
Create or edit work centers, production jobs, labor roles, calendars, machines✓
Job work challans✓
Make or Buy analysis✓
Raise, judge or cancel an inspection; decide a non-conformance✓

Accounting​

Accounts UserAccounts AdminAccounts Head
Chart of accounts, financial years, opening balances✓✓✓
Journal, receipt, payment and contra vouchers✓✓✓
Day book, ledger, trial balance, ageing, stock vs GL✓✓✓
GST returns and registers, TDS register (viewing)✓✓✓
Approval policies✓
File GSTR-1 and GSTR-3B✓
Record TDS challans; edit TDS sections✓
Payroll and depreciation vouchers✓
Customers and vendors under Company✓✓✓

Give the person who signs off the books both Accounts Admin and Accounts Head if they should set approval policies and file returns.

Planner​

The Planner opens the Planning module and its Planning Desk, where shortfalls from approved sales orders are decided as make or buy. To support those decisions the Planner also sees the Purchase, Inventory, Production and Manufacturing menus at the User level.

Admin and Super Admin​

An Admin can do everything listed above in every module, and in addition:

  • create users, change their roles, lock, unlock and delete them, and reset passwords;
  • edit company details and document branding (logo and letterhead);
  • maintain vendor prices on a product;
  • cancel a posted vendor invoice, a debit note or a credit note;
  • waive an inspection.

Only the Super Admin can give or take away the Admin role, or change the Super Admin account itself.

Who sees costs and prices​

Money figures are restricted in the places below. A role without the tick does not see the tab, column or export at all.

FigureWhereSales AdminPurchase AdminInventory AdminProduction AdminAdmin
Standard cost, selling cost, selling price, GST slabProduct → Finance tab✓✓
Vendor-wise purchase pricesProduct → Vendor Prices tab✓ (view)✓
Internal price list (cost, margin, floor price, maximum discount)Product list → Export → Price List✓✓
Customer price list (selling prices only)Product list → Export → Price List✓✓✓
Vendor price comparisonProduct list → Export✓✓✓
Average rate and stock valueInventory → stock valuation✓✓✓✓
Order profitabilitySales order✓✓
Purchase spend analyticsPurchase orders✓✓
Make-versus-buy cost comparisonProduction → Make or Buy✓✓

The User level of every module, the Accounts roles and the Planner see none of the figures above, with one exception: a Purchase User can download the vendor price comparison.

Three things follow from this table:

  • An Inventory Admin creates products but does not see their cost or price. The Finance tab is filled in by a Sales Admin or an Admin. If the storekeeper should not know selling prices, this is the setup you want.
  • Without the stock-value tick, the valuation report still opens and shows quantities only.
  • Vendor prices on a product are changed by an Admin only.

:::caution Amounts on documents are not hidden The restrictions above are the only ones. On a document, the amounts are shown to everyone who can open it: a quotation, sales order or invoice shows its selling prices, a purchase order or vendor invoice shows its purchase prices, and a bill of material or work order shows its cost. Control those by deciding who gets the module role in the first place. :::

Who should get what​

For a small company, start with one role set per person and add roles only when someone is blocked.

PersonRoles to give
Owner or managing directorAdmin
Sales in-chargeSales Admin
Sales executive who only quotesSales User
Purchase and stores in-chargePurchase Admin + Inventory Admin
Production in-chargeProduction Admin
Supervisor who only follows the scheduleProduction User
AccountantAccounts Head + Accounts Admin
Accounts assistantAccounts User
Whoever decides make or buyPlanner
tip

Each person needs their own login. One username can be signed in at only one place at a time, so a shared login throws the first person out when the second signs in.

note

A user who holds only the plain User role can sign in but sees no module. Always add at least one module role.