Creating a custom role (group)
Build a role tailored to your business by mixing and matching specific permissions.
Creating a custom role (group)
The built-in roles (Administrator, Finance, Operations) cover common scenarios, but your business may need something different. A custom role lets you pick exactly which permissions users should have. For example, you might create a role for a junior accountant who can view invoices but cannot delete them, or a cashier who can only receive payments.
Before you start
- You must have Administrator access.
- Know what tasks this role needs to perform. List the areas (invoicing, inventory, payroll, etc.) that the role will touch.
- Know which specific actions the role should be able to do or prevent (create, edit, delete, view, export, etc.).
Steps
-
Go to Settings → Users & Roles → Roles (or Groups). Open in Usystems
-
Click Add Role, New Role, or Create Group.
-
Enter the role name. Use a clear, simple name that describes the job (e.g., "Junior Accountant", "Cashier", "Inventory Auditor").
-
(Optional) Enter a description to explain what this role is for.
-
In the Permissions section, you will see a list of all available permissions grouped by area (Invoicing, Inventory, Payroll, HR, Reports, Settings, etc.).
-
For each area, check the boxes next to the permissions you want this role to have:
- View = the user can see this data or report
- Create = the user can create new documents or records
- Edit = the user can modify existing documents
- Delete = the user can remove documents (use cautiously)
- Export = the user can download or export data
-
Scroll through all sections and select only the permissions the role needs. Leave unchecked any permission you want to withhold.
-
Click Save or Create Role.
-
A confirmation message appears. The role is now available. You can now assign it to users.
Tips & common mistakes
- Be conservative with Delete—the ability to delete documents is powerful and risky. Restrict it to trusted users only. Junior staff should usually not have delete permission.
- View implies nothing else—a user with only "View Invoices" permission cannot create, edit, or delete. Permissions are additive only for the actions you explicitly choose.
- Test your role—after creating it, assign it to a test user and log in as that user to verify they can do only what you intend.
- Use meaningful names—avoid vague names like "Staff" or "User". Use "Vendor Accountant" or "Branch Manager" so it is clear what the role is for.
- Document your roles—keep a list of your custom roles and what they do, so future administrators understand your setup.
Accounting impact
Creating a custom role does not affect your accounts or financial data. It only controls who can see and act on documents. However, be aware that restricting permissions can slow down workflows—for example, if you prevent a Finance user from editing invoices, they cannot correct mistakes. Balance security with usability.
Bu faydalı oldu mu?