Administration • reference

Roles & Granular Permissions

Enforce role-based access control (RBAC) and segregation of duties with built-in system roles (Owner, Admin, Accountant, Warehouse) and custom permission builders.

Reviewed on 2026-10-07

Review the user's job#

Decide which tasks the user actually performs before changing a role. You need the “Manage users and role assignments” permission.

Assign only the access needed#

  1. 1
    Open Roles and review the permissions required for the job.
  2. 2
    Create or edit a role if you have the “Manage users and role assignments” permission.
  3. 3
    Assign it to the user and confirm they can see and perform the intended action.
  4. 4
    Ask the user to open the actual task screen and confirm the intended action is available.
  5. 5
    Review access again when their duties change or a plan feature is altered.

A visible menu item alone does not prove that posting or approval is authorized.

Check the user can work#

Plan features can still limit an action even when the role allows it. Review affected users before removing access.

WARNING: Removing a permission can immediately prevent a user from completing an in-progress workflow. Review affected users before changing or deleting a role.

Have a question about this workflow?

Subscribed customers can ask questions about this guide inside the authenticated dashboard.

Ask about Roles & Granular Permissions in Dashboard