Role — what it is and how permissions are calculated
A role belongs to a company. A user can have several, and their permissions add up — there are no denials, so adding a role never takes anything away.
A role is a set of permissions assigned to a company. It is not global: each company has its own roles, even if they have the same names. There are no templates or roles shared between companies.
A role contains two things
- Module permissions — what you can see and do in a given area of the system (Module permissions — read, write, and create).
- Field permissions — access to specific fields and individual actions (Field permissions — individual fields and individual actions).
Plus a company administrator switch that replaces both (Company administrator and superadministrator — who bypasses what).
Multiple roles at once — and how they add up
A user can have any number of roles in one company. Their permissions add up.
This is the most important rule in the whole module, so let’s state it plainly:
There is no permission that denies access. A role can only grant access. Adding another role can only expand access — never restrict it.
Practical takeaway: to take something away from someone, remove it from all of their roles. Adding a “restricted” role will not restrict anything. If someone can see too much, check all of their roles, not just the most recently assigned one.
Roles belong to a company
The same person can be an administrator in one company and an operator in another. The system calculates permissions only for the active company (My companies — active company and switching context).
That explains a common report: “they have access here, but say they cannot see it” — they may have switched companies.
Role names must be unique within a company
Two roles with the same name cannot exist in one company. They can have the same name in two different companies.
Deleting a role has cascading effects
Deleting a role removes its module permissions, field permissions, and assignments to users. The confirmation window warns you if the role is assigned to someone — take that warning seriously, because there is no undo.
Want to see this with your orders? We’ll show you NOXTI with your sales channels and warehouse.
Book a demo