Getting started
Users, roles, and permissions
Invite teammates, choose base roles, assign modules, and diagnose restricted controls.
Open Users & Roles at /roles. Every installed module still checks the signed in user, workspace, role, module grants, and record scope on the server. Hiding a menu item is helpful navigation, but it is not the security boundary.
Base roles
| Role | Typical use |
|---|---|
| SUPER_ADMIN | Workspace owner with billing, security, role, and destructive administrative control |
| MANAGER | Operational administrator for most create, edit, approval, and reporting workflows |
| DEVELOPER | Broad product and developer access without owner billing and destructive workspace authority |
| EMPLOYEE | Day to day access to assigned or permitted records and self service workflows |
| VIEWER | Read only access to installed and granted modules |
Module actions may use an exact role policy. For example, payroll administration, bank import, contact mutation, and supply chain mutation are generally restricted to SUPER_ADMIN and MANAGER even when another role can read the page.
Invite a teammate
- Open
/roles?tab=members. - Create an invitation with the teammate email and base role.
- Assign module access and an access group if your workspace uses them.
- Send the invite code or email link.
- After redemption, verify that the member is approved and not suspended.
Managers can invite and manage ordinary roles. Only a SUPER_ADMIN can grant SUPER_ADMIN, manage module access at the owner boundary, or permanently delete a member.
Permission sets and access groups
The Permission sets tab and /settings/access-rights support finer controls over groups, record scope, fields, permissions, and menu visibility. Only Access Rights administrators can change these controls. Other users see a restricted explanation instead of a partially functioning editor.
Use the smallest access needed. A base role grants a broad operating posture. Module grants determine available products. Permission sets and groups narrow what the member can see or change inside them.
Review access
The Access reviews tab shows privileged access and pending invitations to authorized reviewers. Run a review after staffing changes and before sensitive finance or payroll cycles.
Common problems
| What you see | What it means |
|---|---|
| A module appears but create is disabled | You can read the module but do not satisfy its mutation policy, or the workspace is read only. |
| A module is missing | It is not installed, not assigned to you, or hidden by a permission set. |
| Permission sets are restricted | You are not an Access Rights administrator. |
| A manager cannot grant SUPER_ADMIN | Only an existing SUPER_ADMIN can grant owner level access. |
| An invited user cannot join | Confirm the code or token is current, the email matches when required, and a seat is available. |