🔐 Users & permissions

Adding users and granting rights

How access is decided — entitlement, then module, then ability.

Access is decided in three layers, and all three have to agree before a user sees a screen.

LayerDecidesSet by
EntitlementWhich modules your workspace has bought.Us, when the workspace is set up or changed.
Module accessWhich of those screens this user may reach.Your administrator.
AbilityWhat they may do there — view, create, edit, delete, and the workflow rights.Your administrator.
Note A user only ever sees what all three allow, which is why two colleagues can have very different sidebars.

Giving someone a login

Workspaces that use HR create logins from the Employees screen — people and their access are managed in one place rather than two.

  1. Open HR Management → Employees.
  2. Add the person, or open the one you want to give access to.
  3. Set Create Portal Login to "Yes — let them sign in". The email on the record becomes their username.
  4. Leave Temporary Password blank to have one generated, or set one of at least eight characters.
  5. Save, and tell them to change it under My Account after their first sign-in.
Note Operations staff who work the freight screens are managed on Management → Users instead — see "Freight Users, User Roles and User Category".

The abilities

Most screens grant four: view, create, edit and delete. Screens that carry a workflow grant more — a freight money document adds print, void and unvoid; a finance voucher adds check, uncheck, final, unfinal, void and unvoid; a courier consignment adds print, final, unfinal, void and unvoid.

That granularity is the point: a clerk can be allowed to key and check vouchers while only the accountant may finalise or void them.

Checking what someone can do

Their sidebar is the answer — it is built from exactly these rights. If a screen is missing, one of the three layers is closed.