Help center / Guide 02

users, roles& permissions

Give every person exactly the access they need, and nothing more.

How access works

Simbako ERP is deny-by-default. A person can only open an app or take an action if one of their roles grants the matching permission. There are 119 permissions:

  • view and manage for every app (for example CRM: view lets someone read leads, CRM: manage lets them create and edit them);
  • extra approval permissions for sensitive steps: confirming sales and purchase orders, posting invoices and journal entries, approving expenses, time off and timesheets, confirming payroll, approving product changes and closing point-of-sale sessions;
  • HR sensitive data: needed to reveal salary, bank and national ID numbers;
  • administration: users, roles, security policy, audit trail and billing;
  • API access: needed to create API tokens.

The workspace owner (the person who signed up) always has full access.

Ready-made roles

Every workspace starts with these roles. Use them as they are or copy their idea into your own.

Role Good for
Administrator Full access to every app and setting
Manager Every app, including approvals, but no administration
Sales / Sales Manager CRM, quotations, subscriptions, rentals, store and events; managers also confirm orders and run campaigns
Cashier Point of sale and restaurant
Purchasing Vendors and purchase orders
Warehouse Stock, manufacturing, maintenance and quality
Accountant Ledger, invoices, expenses and payments
HR Manager People, payroll and recruitment, including sensitive data
Project Manager Projects, timesheets, planning and helpdesk
Support Agent Helpdesk, live chat and wiki
Marketing Campaigns, website and content
Employee Self-service: time off, expenses, chat, wiki
Auditor Read-only across every app, plus the audit trail

Add a user

  1. Administration → Users → New user.
  2. Enter name and email, pick one or more roles, and set a temporary password that meets the password rules.
  3. Tell the person their temporary password through a separate channel. They must replace it at first sign-in.

Change, lock out or remove access

  • Edit a user to change their roles; changes apply on their next page load.
  • Deactivate a user (untick Account active) to sign them out everywhere and revoke their API tokens. Their history (records they created, audit entries) is kept.
  • Unlock a user who was locked out after too many failed sign-ins.
  • Reset two-factor if someone lost their authenticator and recovery codes. They will set it up again at next sign-in.

Every one of these actions is written to the Audit Trail.

Create a custom role

  1. Administration → Roles & Access → New role.
  2. Name it and tick the permissions it should grant, app by app.
  3. Assign it to users.

Safety rule: you can't grant a permission you don't hold yourself, so nobody can quietly give themselves more power through a role.

Separation of duties

Some approvals are protected against self-approval: nobody can review their own time-off request, approve their own expense, approve their own timesheet, confirm their own payslip, or approve a product change they requested, even if they hold the approval permission. A colleague with the permission has to do it.

Tips

  • Prefer several small roles over one big one; people can have more than one.
  • Give HR sensitive data to as few people as possible. Every reveal is logged.
  • Use Auditor for accountants or advisers who only need to look.