How access works
Permissions are role-based. A role is a security template, such as Billing Clerk or Finance Manager, and users are added to roles. Change a role and every member is updated at once.
Built-in roles
| Role | Typical access | Use when |
|---|---|---|
| Super Admin | Everything, including tenant settings | Owner or operations lead |
| Branch Manager | Their branches, most modules | Single-site supervisor |
| Operator / Clerk | Enter and edit data, limited delete | Billing and data entry |
| Viewer | Read-only | Audit and reporting users |
| Accountant | Finance modules and approvals | Accounts team |
Create or edit a role
- Open Settings, Users, then Roles and select New Role.
- Name the role and choose the modules it can open.
- Toggle the allowed actions — View, Create, Edit, Delete or Approve.
- Restrict some roles to branch-level data only.
- Save, then add team members to the role.
Tip
Keep roles broad and few. Spreading users across too many tiny roles makes revocations and audits slower.
Revoking access
Removing a departed member from their role invalidates active sessions. You can also deactivate the user so historical logs are retained for audits.

