Access is decided in three layers, and all three have to agree before a user sees a screen.
| Layer | Decides | Set by |
|---|---|---|
| Entitlement | Which modules your workspace has bought. | Us, when the workspace is set up or changed. |
| Module access | Which of those screens this user may reach. | Your administrator. |
| Ability | What they may do there — view, create, edit, delete, and the workflow rights. | Your administrator. |
Giving someone a login
Workspaces that use HR create logins from the Employees screen — people and their access are managed in one place rather than two.
- Open HR Management → Employees.
- Add the person, or open the one you want to give access to.
- Set Create Portal Login to "Yes — let them sign in". The email on the record becomes their username.
- Leave Temporary Password blank to have one generated, or set one of at least eight characters.
- Save, and tell them to change it under My Account after their first sign-in.
The abilities
Most screens grant four: view, create, edit and delete. Screens that carry a workflow grant more — a freight money document adds print, void and unvoid; a finance voucher adds check, uncheck, final, unfinal, void and unvoid; a courier consignment adds print, final, unfinal, void and unvoid.
That granularity is the point: a clerk can be allowed to key and check vouchers while only the accountant may finalise or void them.
Checking what someone can do
Their sidebar is the answer — it is built from exactly these rights. If a screen is missing, one of the three layers is closed.