Assigning permissions to a role
Grant specific permissions to a role so its members can perform allowed actions.
Roles group permissions together, making it easy to manage access for teams of users. When you assign permissions to a role, every user in that role automatically gains those permissions.
Before you start
- You must have administrator access (or explicit permission to manage roles).
- Know which actions the role should allow (view documents, create invoices, export reports, etc.).
- Understand that a user's actual access is the combination of all the roles assigned to them.
Steps
-
Go to Settings → Users & Roles → Roles, then open or create the role you want to configure. Open in Usystems
-
Look for the Permissions section on the role edit page. You will see checkboxes for each available permission.
-
Check the boxes for the permissions you want to grant. Each permission controls a specific action:
- View documents or data (read-only)
- Create new documents
- Edit existing documents
- Delete documents
- Export data
-
For report permissions, see the separate guide Controlling which reports each role can see.
-
Save the role by clicking the save button.
How permissions work
A permission gives a user or role the right to perform one specific action in one area of the system. For example:
- "Create invoices" allows the user to open the invoice form and submit it.
- "Delete bills" allows the user to mark a bill as deleted.
- "Export contacts" allows the user to download a contact list.
If a user belongs to multiple roles, they have all the permissions of all their roles combined.
Tips & common mistakes
- Permissions are additive: if a user is in two roles and one has "Edit invoices" and the other has "Delete invoices," they can both edit and delete.
- Removing a permission is not instant: if you unchecked a permission while a user is logged in, they may need to log out and back in to see the change.
- Not seeing a permission? It may be product-specific. Some permissions only apply to certain product types (e.g., POS, Pharmacy, Hospital).
- Err on the side of restriction: start with fewer permissions and add more as needed. It is easier to grant access later than to lock down an overly permissive role.
Bu faydalı oldu mu?