Skip to content

Users and Roles

Users with Settings manage permission. System Manager role changes require a System Manager, even if another manager can administer ordinary roles.

Map the person’s real responsibilities to module actions and access level. Do not create a role solely to bypass an owner-scope restriction without reviewing the broader impact.

  1. Open Settings → Roles & Permissions and inspect the existing role hierarchy and permission rows.
  2. Create a custom role with a distinct display name and only the modules/actions it needs. Write permissions automatically imply read access in the stored role definition.
  3. Assign or revise roles through the approved team/role management workflow; confirm any System Manager role change with a System Manager.
  4. To delete a custom role, open the delete dialog, review the affected user count, select a replacement role when users still hold it, and type the exact role name to confirm.

Role changes invalidate authorization caches and write an audit event after the main mutation succeeds. System roles cannot be deleted.

  • Duplicate role name: display names are unique case-insensitively.
  • Role cannot be deleted: reassign all assigned users first or choose a replacement in the dialog.
  • A user still cannot act: check their resolved permission union and the target record’s owner scope.