Getting started

Users, roles, and permissions

Invite teammates, choose base roles, assign modules, and diagnose restricted controls.

Open Users & Roles at /roles. Every installed module still checks the signed in user, workspace, role, module grants, and record scope on the server. Hiding a menu item is helpful navigation, but it is not the security boundary.

Base roles

RoleTypical use
SUPER_ADMINWorkspace owner with billing, security, role, and destructive administrative control
MANAGEROperational administrator for most create, edit, approval, and reporting workflows
DEVELOPERBroad product and developer access without owner billing and destructive workspace authority
EMPLOYEEDay to day access to assigned or permitted records and self service workflows
VIEWERRead only access to installed and granted modules

Module actions may use an exact role policy. For example, payroll administration, bank import, contact mutation, and supply chain mutation are generally restricted to SUPER_ADMIN and MANAGER even when another role can read the page.

Invite a teammate

  1. Open /roles?tab=members.
  2. Create an invitation with the teammate email and base role.
  3. Assign module access and an access group if your workspace uses them.
  4. Send the invite code or email link.
  5. After redemption, verify that the member is approved and not suspended.

Managers can invite and manage ordinary roles. Only a SUPER_ADMIN can grant SUPER_ADMIN, manage module access at the owner boundary, or permanently delete a member.

Permission sets and access groups

The Permission sets tab and /settings/access-rights support finer controls over groups, record scope, fields, permissions, and menu visibility. Only Access Rights administrators can change these controls. Other users see a restricted explanation instead of a partially functioning editor.

Use the smallest access needed. A base role grants a broad operating posture. Module grants determine available products. Permission sets and groups narrow what the member can see or change inside them.

Review access

The Access reviews tab shows privileged access and pending invitations to authorized reviewers. Run a review after staffing changes and before sensitive finance or payroll cycles.

Common problems

What you seeWhat it means
A module appears but create is disabledYou can read the module but do not satisfy its mutation policy, or the workspace is read only.
A module is missingIt is not installed, not assigned to you, or hidden by a permission set.
Permission sets are restrictedYou are not an Access Rights administrator.
A manager cannot grant SUPER_ADMINOnly an existing SUPER_ADMIN can grant owner level access.
An invited user cannot joinConfirm the code or token is current, the email matches when required, and a seat is available.