Permission reference: Settings & administration
Control who can manage system settings, users, groups, and permissions.
Jul 11, 2026
Permission Reference: Settings & Administration
This table lists all permissions that control access to system administration, configuration, and user/group management in Usystems.
| Permission | What It Controls | Allowed Actions |
|---|---|---|
| settings.manage | Manage system settings | Users can configure system preferences (fiscal year, company details, tax rates, currencies, business rules), and manage product-level settings. |
| user.view | View users | Users can see a list of all system users and their roles. |
| user.manage | Manage users | Users can create new user accounts, edit existing users (name, email, password), deactivate users, and assign roles. |
| group.view | View groups/roles | Users can see all user groups and their members. |
| group.manage | Manage groups/roles | Users can create new groups, assign permissions to groups, modify group memberships, and delete groups. |
| permission.view | View permissions | Users can see the list of all available permissions and who has them. |
| permission.manage | Manage permissions | Users can modify permission assignments and create custom permission profiles (advanced feature). |
Related Actions
| Action | Required Permissions | Notes |
|---|---|---|
| Create a new user | user.manage | Setting up employee or staff access. |
| Reset user password | user.manage | Helping locked-out users. |
| Assign permissions to a user | user.manage + permission.manage | Granular access control (if using role-based assignment). |
| Create custom role | group.manage | Bundling permissions for a specific job function. |
| Lock/unlock user account | user.manage | Disabling access without deleting the user. |
| Audit permission changes | permission.view | Reviewing who changed access and when. |
Which roles typically need these?
- System administrator → all settings and user/group/permission permissions (for full system management)
- HR manager → user.view, user.manage (for onboarding and offboarding)
- Finance manager → settings.manage (to configure fiscal settings and tax rates)
- Super admin → all permissions (ultimate control)
What happens without these permissions?
Without settings.manage, users cannot configure system parameters and the company cannot adapt Usystems to their business rules. Without user.manage, new employees cannot be added. Without group.manage, custom roles cannot be created, limiting access control flexibility.
Was this helpful?