Role Based Permissions
Role Based Permissions allow you to control exactly what each role can do with each document type in YousrERP.
Using the Role Permissions Manager
Go to: Users and Permissions > Role Permissions Manager
Permissions are applied on a combination of:
- Roles: Users are assigned roles, and permission rules apply to those roles.
- Document Types: Each type of document (Sales Invoice, Leave Application, Stock Entry, etc.) has separate role-based permissions.
- Permission Levels: Fields can be grouped into levels (0-9), with different permissions for each level.
- Document Stages: Permissions apply at Creation, Saving, Submission, Cancellation, and Amendment.
Example: Leave Application Permissions
Here's how a typical permission setup works:
- Employee Role โ Read, Write, Create permissions on their own Leave Applications. User Permissions restrict them to only their own records.
- HR Manager โ Read access to all Leave Applications (no User Permission restriction).
- Leave Approver โ Read and Write access, with User Permissions limited to their subordinates.
- HR User โ Full access including the ability to Set User Permissions for others on Leave Application.
Adding a New Rule
- In the Role Permissions Manager, click Add a New Rule.
- Select a Role and Permission Level.
- Click Add โ a new row appears in the rules table.
- Check the permissions you want to grant.
- Click Save.
Permission Types
| Permission | Description | Example |
|---|---|---|
| Select | Search and see records | User can select a Customer in Sales Order but can't open the Customer master |
| Read | View the document | User can view Sales Invoices but can't change them |
| Write | Edit existing records | User can update a Customer address but can't create a new Customer |
| Create | Create new documents | User can create new Items but can't edit existing ones |
| Delete | Delete documents | User can delete submitted documents |
| Print or download PDF | Print button is enabled in the document | |
| Send emails from document | Email button is enabled in the document | |
| Report | Access related reports | User can view reports for the document type |
| Export | Export data from list view | User can export report data |
| Import | Import data to document | User can import data |
| Share | Share access with other users | User can share document access |
Permission Levels
Permission Levels allow you to restrict access to specific fields within a document. For example:
- Level 0: Basic fields visible to all with Read access
- Level 1: Sensitive fields (like "Status" or "Approved Amount") restricted to specific roles