Creating and editing a role — the two-tab window
Name, description, administrator switch, and two permission tabs. Duplicating an existing role is usually faster than setting everything up from scratch.
The Roles and permissions tab shows the company’s role list with the number of permissions and assigned people.
Step by step
- Go to Settings → Team and access → Roles and permissions.
- Click Add role to build a role from scratch. It is faster, though, to find a similar role and click its copy icon — Duplicate role.
- In the Create new role window, enter a Role name (required and unique within the company) and a Description.
- Leave Company administrator switched off when building an ordinary role. Turning it on hides both permission tabs — see below.
- On the Module permissions tab, select Read, Write, and Create in the grid for the required modules. Select all selects everything, and the counter below the grid shows Selected N of M permissions (Module permissions — read, write, and create).
- Go to the Field permissions tab and expand the groups where you want to restrict something. Toggle all applies to the whole group at once (Field permissions — individual fields and individual actions).
- Save with Create role (or Update role when editing).
- If a window asks for a 2FA code, enter it. Saving sends two requests, but the window appears only once — the confirmation remains valid for 15 minutes (2FA confirmation when changing permissions).
- Assign the role to people — one at a time with Manage roles, or in bulk (Bulk role assignment — add, replace, or remove).
Actions in a role row
A role row has three icons, each with a tooltip on hover:
- Edit role — opens the configuration window.
- Duplicate role — creates a copy with the full configuration and (copy) appended to the name.
- Delete role — the icon is hidden for roles with company administrator enabled.
Duplicate role is the most underrated action on this screen. Building a “Night warehouse worker” role from scratch means clicking through dozens of switches; copying “Warehouse worker” and changing three takes a minute and avoids accidental gaps.
The Users column shows how many people have the role. It is not clickable — you cannot see names here; filter the user list by this role to see them (User list — cards, columns, and filters). Always check that list before editing a role used by many people.
Configuration window
At the top are Role name, Description, and the Company administrator switch. Below are two tabs:
- Module permissions — a grid of all modules × Read / Write / Create, with whole-row selection and a Select all button (Module permissions — read, write, and create).
- Field permissions — fields and actions grouped under module names, expandable, with search and a Toggle all button for each group (Field permissions — individual fields and individual actions).
The administrator switch hides both tabs
When you turn it on, both tabs disappear — correctly. A company administrator bypasses all permission checks, so detailed permissions would not matter. Field permissions are not saved in this state.
If you turn this switch off on an existing administrator role, you return to a role with no detailed permissions selected — not to its previous state. Check the tabs before saving.
Only a company administrator can set this switch (Company administrator and superadministrator — who bypasses what).
Saving is two operations
Saving a role sends two separate requests: one with module permissions, the other with field permissions. Both require 2FA confirmation (2FA confirmation when changing permissions).
There is one consequence to know: the second request deletes and saves field permissions again from scratch. If the database contains permission for a field that is no longer in the current catalogue, saving the role removes it without warning (Field permissions — individual fields and individual actions).
Want to see this with your orders? We’ll show you NOXTI with your sales channels and warehouse.
Book a demo