Roles and permissions

4 min read ·Updated

A role is a set of permissions granted to several users at once. Read this before you create your first employee, so you know which template to start from and what each key means.

On this page
  1. What is a role?
  2. Ready-made templates
  3. Reading the matrix
  4. Overrides for a single user
  5. Permissions worth attention

What is a role?

A role (also called a permission group) is the list of what its holder may see and do in the system. You define a role once under Home, then Roles and permissions, and grant it to any number of users. When you change the role, everyone who holds it changes at the same moment.

Every permission in Sahl is a three-part key: module.resource.action. For example sales.documents.post means "post sales documents" and cashier.returns.create means "create a return from the cashier screen". You do not need to memorise keys; the screen shows them as a table with plain names.

Ready-made templates

When creating a role, choose Start from a template to fill the matrix with a tested setup, then adjust. The templates are:

TemplateWhat it does
OwnerEverything, no exceptions.
ManagerEverything except posting accounts, reopening locked periods and changing features.
AccountantAdvanced accounting, treasury, financial and tax reports, parties; cannot edit items.
TreasurerReceipts and payments on their own cash accounts, cheques (no return or cancel), statements.
Sales officerInvoices, returns, quotations, orders and customers, with no view of cost or profit.
Purchasing officerSupplier invoices, goods receipts and orders, suppliers, items including cost.
Warehouse keeperBalances, transfers, adjustments, stocktakes (create and count; posting is for the manager), no sale prices.
CashierSelling, returns and receipts from the POS app only.
SalesmanTheir own customers, invoices and field receipts through the app.
Read onlyView and export every screen and report, no edits and no cost.

If the restaurant module is enabled, three more templates appear: Staff (opens tables and takes orders from their device; does not collect payment or close bills), Kitchen (kitchen display only) and Floor manager (every floor operation: transfer, merge, discount, void and reservations). Read more in Enabling the restaurant module.

Reading the matrix

The screen shows each module in its own box (catalog, sales, purchasing, treasury, inventory, accounting, users and security, and so on). Inside, one row per resource and one column per action: view, create, update, delete, post, cancel, export, plus special actions such as "credit limit override", "discount above limit" or "other cashbox".

  1. The module checkbox selects or clears every permission of the module.
  2. The resource checkbox selects every action of that resource.
  3. Individual boxes grant one action. Any action implies "view" automatically: whoever creates an invoice can see it.

A module that depends on a feature not enabled in your subscription (such as point of sale or restaurant) is dimmed with a Feature not enabled badge. Its keys are saved but have no effect until the feature is turned on.

Tip

Under the role name a counter reads "selected: X of Y permissions". Use it as a sanity check: a typical cashier has 10 to 15 keys, a manager is close to the full count.

Overrides for a single user

Sometimes one employee needs one extra thing without a whole new role. In the user form, tab Role and permissions, there are two fields:

  • Extra grants: keys added on top of the role for this user only.
  • Deny: keys blocked even though the role grants them. Deny always wins over grant.

Example: the sales officer role for your most senior salesman with an extra grant of sales.returns.cash_refund so they can refund in cash, while the others refund as customer credit. More examples in Creating a user.

Permissions worth attention

  • Credit sale in a customer's name for the cashier: without it, every cashier invoice stays cash even when a customer is named.
  • Return without an original invoice and cash refund: explicitly denied in the cashier template because they are the widest doors to abuse; give them to the sales officer or manager only.
  • Other cashbox on receipts and payments: allows collecting or paying on a cash account outside the user's scope.
  • Approve on payments: who approves a payment voucher above the user's amount limit.
  • Unlock a locked period in accounting: reverses the closing entry; grant it to the head of accounts only.

How do you control which warehouses, cash accounts and branches each user works on? That is the subject of Scopes, not permissions.

Warning

Roles marked "(system)" are the original templates. Edit them carefully; it is better to copy a new role named after your shop and edit the copy.

Frequently asked questions

What is the difference between a role and a permission?

A permission is one key for one action on one resource. A role is a bundle of permissions granted to several users together, and it changes for all of them when edited.

Can I give one employee a permission without changing the role?

Yes, through the Extra grants field in the user form. The Deny field does the opposite: it blocks a permission the role grants.

Why is a module dimmed in the matrix?

Because it depends on a feature not enabled in your subscription, such as point of sale or restaurant. The keys are saved and work as soon as the feature is enabled.

Was this article helpful?