Common symptoms
- A module is missing from the sidebar.
- Save or Delete buttons are greyed out.
- An API or export call returns 403.
- A record is visible but another branch's data is not.
Check the permission triangle
Access is the sum of the user's roles, the branch scope, and the module's own settings. A change to any one of these changes access.
- Open the user's profile and confirm their role list.
- Verify the role includes the module and action.
- Confirm the branch scope matches the record's branch.
- Check module settings for role-level overrides.
When to escalate
If all three look correct and access still fails, capture the screen and send it to support with the user and role names. Include a sample record ID if relevant.

