Roles and permissions
This page lists what each role opens and what it is allowed to do. To create users and assign roles, see Users and roles.
How access works
- Roles are built in. There are fifteen, and you choose which ones each user holds. You cannot define your own roles or switch individual permissions on and off.
- A user can hold several roles. Access adds up: someone with Purchase Admin and Inventory Admin sees both sets of menus.
- Most modules have two levels. The User level can look at the module's records. The Admin level can also create, approve and cancel. The exact split is listed per module below.
- Menus the user may not open are hidden, and the server refuses the matching requests as well.
- A role change applies at the user's next sign-in. Changing someone's roles signs them out.
The roles
| Role (as shown) | Code | In one line |
|---|---|---|
| Super Admin | ROLE_SUPER_ADMIN | The built-in admin account. Everything, and the only one who can make another user an Admin. |
| Admin | ROLE_ADMIN | Everything in every module, plus users, roles and company details. |
| User | ROLE_USER | Can sign in. Opens no module by itself. |
| Sales Admin | ROLE_SALES_ADMIN | Runs sales: orders, delivery challans, invoices, approvals. |
| Sales User | ROLE_SALES_USER | Works enquiries and quotations; sees orders and invoices. |
| Purchase Admin | ROLE_PURCHASE_ADMIN | Runs purchasing: approvals, receipts, vendor bills and payments. |
| Purchase User | ROLE_PURCHASE_USER | Raises requisitions and purchase orders for approval. |
| Inventory Admin | ROLE_INVENTORY_ADMIN | Runs the stores and the product master. |
| Inventory User | ROLE_INVENTORY_USER | Sees stock, warehouses and material requests. |
| Production Admin | ROLE_PRODUCTION_ADMIN | Runs production: BOMs, work orders, masters, job work. |
| Production User | ROLE_PRODUCTION_USER | Sees work orders, schedule and shop floor. |
| Accounts Head | ROLE_ACCOUNTS_HEAD | Accounting, plus filing returns and statutory entries. |
| Accounts Admin | ROLE_ACCOUNTS_ADMIN | Accounting, plus approval policies. |
| Accounts User | ROLE_ACCOUNTS_USER | Day-to-day accounting. |
| Planner | ROLE_PLANNER | The Planning Desk, with a view of purchase, inventory and production. |
Which menus each role sees
Every signed-in user sees the Dashboard and their own Account Settings. The rest depends on the roles held. The User and Admin level of a module see the same menus; they differ in what they may do there.
| Menu | Sales | Purchase | Inventory | Production | Accounts | Planner | Admin |
|---|---|---|---|---|---|---|---|
| Products → Master | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Products → Bill Of Material | ✓ | ✓ | ✓ | ||||
| Production | ✓ | ✓ | ✓ | ||||
| Manufacturing | ✓ | ✓ | ✓ | ||||
| Sales | ✓ | ✓ | |||||
| Company (customers and vendors) | ✓ | ✓ | ✓ | ✓ | |||
| Purchase | ✓ | ✓ | ✓ | ||||
| Inventory | ✓ | ✓ | ✓ | ||||
| Quality → Inspections | ✓ | ✓ | ✓ | ✓ | |||
| Configuration → Item Code | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| SuperAdmin (users, roles, company details) | ✓ | ||||||
| Accounting module | ✓ | ✓ | |||||
| Planning module | ✓ | ✓ |
What sits under each menu:
| Menu | Screens |
|---|---|
| Production | Schedule Views, Shop Floor, Work Orders, Job Work Challan, Make or Buy, Machine Assets, OEE Dashboard (and Planning Desk for planners) |
| Manufacturing | Work Center, Downtime Reasons, Production Job, Labor Roles, Holiday Calendar |
| Sales | Pipeline Desk, Revenue Desk, Enquiries, Quotations, Sales Orders, Delivery Challans, Invoices |
| Purchase | Purchase Orders, Requisitions |
| Inventory | Dashboard, Warehouses, Stock Transfers, Pick Lists, Packing Slips, Material Requests |
| Accounting | Masters, Vouchers, Reports, Approvals, GST, TDS |
What each level can do
Sales
| Sales User | Sales Admin | |
|---|---|---|
| Pipeline Desk and Revenue Desk | ✓ | ✓ |
| Create and edit enquiries and quotations | ✓ | ✓ |
| See the sales order, delivery challan and invoice lists | ✓ | ✓ |
| Create or edit a sales order | ✓ | |
| Approve or reject a sales order | ✓ | |
| Create a delivery challan or an invoice | ✓ | |
| Cancel an invoice; raise and confirm a credit note | ✓ | |
| See an order's profitability | ✓ | |
| Customers under Company | ✓ | ✓ |
Purchase
| Purchase User | Purchase Admin | |
|---|---|---|
| Create and edit requisitions and purchase orders | ✓ | ✓ |
| Approve or reject a requisition or a purchase order | ✓ | |
| Record a goods receipt (GRN) | ✓ | |
| Enter and post vendor invoices; record vendor payments | ✓ | |
| Raise and confirm a debit note | ✓ | |
| Purchase analytics, pending-receipt and overdue lists | ✓ | |
| Vendors under Company | ✓ | ✓ |
An Inventory Admin can also record goods receipts, vendor invoices, vendor payments and debit notes, so the stores can take in material without a purchase role.
Inventory
| Inventory User | Inventory Admin | |
|---|---|---|
| See stock, warehouses, transfers, pick lists, packing slips, material requests | ✓ | ✓ |
| Create or edit a product in the master | ✓ | |
| Add, correct or remove stock; opening stock | ✓ | |
| Approve or reject material requests | ✓ | |
| Create, dispatch, receive or cancel a stock transfer | ✓ | |
| Create or edit warehouses and locations | ✓ | |
| Stock count and stock reconciliation | ✓ | |
| Raise an inspection | ✓ |
Production
| Production User | Production Admin | |
|---|---|---|
| See work orders, schedule, shop floor, machines and the OEE dashboard | ✓ | ✓ |
| See bills of material and the manufacturing masters | ✓ | ✓ |
| Create or edit a work order | ✓ | |
| Issue material, cancel or short-close a work order | ✓ | |
| Create or edit a bill of material; change its status | ✓ | |
| Create or edit work centers, production jobs, labor roles, calendars, machines | ✓ | |
| Job work challans | ✓ | |
| Make or Buy analysis | ✓ | |
| Raise, judge or cancel an inspection; decide a non-conformance | ✓ |
Accounting
| Accounts User | Accounts Admin | Accounts Head | |
|---|---|---|---|
| Chart of accounts, financial years, opening balances | ✓ | ✓ | ✓ |
| Journal, receipt, payment and contra vouchers | ✓ | ✓ | ✓ |
| Day book, ledger, trial balance, ageing, stock vs GL | ✓ | ✓ | ✓ |
| GST returns and registers, TDS register (viewing) | ✓ | ✓ | ✓ |
| Approval policies | ✓ | ||
| File GSTR-1 and GSTR-3B | ✓ | ||
| Record TDS challans; edit TDS sections | ✓ | ||
| Payroll and depreciation vouchers | ✓ | ||
| Customers and vendors under Company | ✓ | ✓ | ✓ |
Give the person who signs off the books both Accounts Admin and Accounts Head if they should set approval policies and file returns.
Planner
The Planner opens the Planning module and its Planning Desk, where shortfalls from approved sales orders are decided as make or buy. To support those decisions the Planner also sees the Purchase, Inventory, Production and Manufacturing menus at the User level.
Admin and Super Admin
An Admin can do everything listed above in every module, and in addition:
- create users, change their roles, lock, unlock and delete them, and reset passwords;
- edit company details and document branding (logo and letterhead);
- maintain vendor prices on a product;
- cancel a posted vendor invoice, a debit note or a credit note;
- waive an inspection.
Only the Super Admin can give or take away the Admin role, or change the Super Admin account itself.
Who sees costs and prices
Money figures are restricted in the places below. A role without the tick does not see the tab, column or export at all.
| Figure | Where | Sales Admin | Purchase Admin | Inventory Admin | Production Admin | Admin |
|---|---|---|---|---|---|---|
| Standard cost, selling cost, selling price, GST slab | Product → Finance tab | ✓ | ✓ | |||
| Vendor-wise purchase prices | Product → Vendor Prices tab | ✓ (view) | ✓ | |||
| Internal price list (cost, margin, floor price, maximum discount) | Product list → Export → Price List | ✓ | ✓ | |||
| Customer price list (selling prices only) | Product list → Export → Price List | ✓ | ✓ | ✓ | ||
| Vendor price comparison | Product list → Export | ✓ | ✓ | ✓ | ||
| Average rate and stock value | Inventory → stock valuation | ✓ | ✓ | ✓ | ✓ | |
| Order profitability | Sales order | ✓ | ✓ | |||
| Purchase spend analytics | Purchase orders | ✓ | ✓ | |||
| Make-versus-buy cost comparison | Production → Make or Buy | ✓ | ✓ |
The User level of every module, the Accounts roles and the Planner see none of the figures above, with one exception: a Purchase User can download the vendor price comparison.
Three things follow from this table:
- An Inventory Admin creates products but does not see their cost or price. The Finance tab is filled in by a Sales Admin or an Admin. If the storekeeper should not know selling prices, this is the setup you want.
- Without the stock-value tick, the valuation report still opens and shows quantities only.
- Vendor prices on a product are changed by an Admin only.
:::caution Amounts on documents are not hidden The restrictions above are the only ones. On a document, the amounts are shown to everyone who can open it: a quotation, sales order or invoice shows its selling prices, a purchase order or vendor invoice shows its purchase prices, and a bill of material or work order shows its cost. Control those by deciding who gets the module role in the first place. :::
Who should get what
For a small company, start with one role set per person and add roles only when someone is blocked.
| Person | Roles to give |
|---|---|
| Owner or managing director | Admin |
| Sales in-charge | Sales Admin |
| Sales executive who only quotes | Sales User |
| Purchase and stores in-charge | Purchase Admin + Inventory Admin |
| Production in-charge | Production Admin |
| Supervisor who only follows the schedule | Production User |
| Accountant | Accounts Head + Accounts Admin |
| Accounts assistant | Accounts User |
| Whoever decides make or buy | Planner |
Each person needs their own login. One username can be signed in at only one place at a time, so a shared login throws the first person out when the second signs in.
A user who holds only the plain User role can sign in but sees no module. Always add at least one module role.