users, roles& permissions
Give every person exactly the access they need, and nothing more.
- How access works
- Ready-made roles
- Add a user
- Change, lock out or remove access
- Create a custom role
- Separation of duties
- Tips
How access works
Simbako ERP is deny-by-default. A person can only open an app or take an action if one of their roles grants the matching permission. There are 119 permissions:
- view and manage for every app (for example CRM: view lets someone read leads, CRM: manage lets them create and edit them);
- extra approval permissions for sensitive steps: confirming sales and purchase orders, posting invoices and journal entries, approving expenses, time off and timesheets, confirming payroll, approving product changes and closing point-of-sale sessions;
- HR sensitive data: needed to reveal salary, bank and national ID numbers;
- administration: users, roles, security policy, audit trail and billing;
- API access: needed to create API tokens.
The workspace owner (the person who signed up) always has full access.
Ready-made roles
Every workspace starts with these roles. Use them as they are or copy their idea into your own.
| Role | Good for |
|---|---|
| Administrator | Full access to every app and setting |
| Manager | Every app, including approvals, but no administration |
| Sales / Sales Manager | CRM, quotations, subscriptions, rentals, store and events; managers also confirm orders and run campaigns |
| Cashier | Point of sale and restaurant |
| Purchasing | Vendors and purchase orders |
| Warehouse | Stock, manufacturing, maintenance and quality |
| Accountant | Ledger, invoices, expenses and payments |
| HR Manager | People, payroll and recruitment, including sensitive data |
| Project Manager | Projects, timesheets, planning and helpdesk |
| Support Agent | Helpdesk, live chat and wiki |
| Marketing | Campaigns, website and content |
| Employee | Self-service: time off, expenses, chat, wiki |
| Auditor | Read-only across every app, plus the audit trail |
Add a user
- Administration → Users → New user.
- Enter name and email, pick one or more roles, and set a temporary password that meets the password rules.
- Tell the person their temporary password through a separate channel. They must replace it at first sign-in.
Change, lock out or remove access
- Edit a user to change their roles; changes apply on their next page load.
- Deactivate a user (untick Account active) to sign them out everywhere and revoke their API tokens. Their history (records they created, audit entries) is kept.
- Unlock a user who was locked out after too many failed sign-ins.
- Reset two-factor if someone lost their authenticator and recovery codes. They will set it up again at next sign-in.
Every one of these actions is written to the Audit Trail.
Create a custom role
- Administration → Roles & Access → New role.
- Name it and tick the permissions it should grant, app by app.
- Assign it to users.
Safety rule: you can't grant a permission you don't hold yourself, so nobody can quietly give themselves more power through a role.
Separation of duties
Some approvals are protected against self-approval: nobody can review their own time-off request, approve their own expense, approve their own timesheet, confirm their own payslip, or approve a product change they requested, even if they hold the approval permission. A colleague with the permission has to do it.
Tips
- Prefer several small roles over one big one; people can have more than one.
- Give HR sensitive data to as few people as possible. Every reveal is logged.
- Use Auditor for accountants or advisers who only need to look.