Module permissions — read, write, and create
A grid of modules with three fields for each. Note: deletion is covered by “write”, while some “run now” buttons require “create”.
Each system module has three independent fields in a role: Read, Write, and Create. In the role window, the third column is labelled more briefly — Create.
Step by step
Build a role from scratch
- Go to Team and access → Roles and permissions. You will see the Company roles list with the label Configured roles: {n}.
- Click Add role. The Create new role window opens with the subtitle Configure role permissions.
- Enter a Role name — the field hint is e.g. Sales manager. The save button is inactive without a name. Description is optional.
- Leave Company administrator switched off — when it is on, the module grid is hidden entirely (Company administrator and superadministrator — who bypasses what).
- On the Module permissions tab, under Module access, select fields in the grid. The columns are Module, Read, Write, and Create.
- Remember two things from this article: Write includes deletion, and buttons such as “sync now” require Create.
- The Select all checkbox in the section’s upper-right corner selects all three columns in every row. Use it carefully — it is equivalent to full access without the crown.
- Check the counter below the grid: Selected {n} of {total} permissions. The No permissions selected chip means the role grants nothing.
- Click Create role (or Update role when editing an existing role).
- In the 2FA verification required window, enter the Verification code and click Confirm (2FA confirmation when changing permissions).
- The window closes and the role appears in the list with a Modules: N chip in the Permissions column. On failure, you will see Could not save role.
You can also copy the whole grid from an existing role using the Duplicate role icon instead of selecting everything again — the window is described in Creating and editing a role — the two-tab window.
Check what a role grants in practice
- Assign the role to a person (User accounts → three-dot menu → Manage roles).
- In the same menu, open Effective permissions and compare the Module permissions table with the grid in the role window. This is the only way to see the combined permissions from all of that person’s roles (“Why can’t they see it?” — diagnosing permissions).
- The person whose permissions you changed may need to wait up to five minutes or reload the page before seeing the difference.
What corresponds to what
| Field | Covers |
|---|---|
| Read | Opening lists and details, retrieving data |
| Create | Creating new records |
| Write | Editing and deleting |
Two things are worth remembering because they are not obvious:
There is no separate permission for deletion. Anyone who can edit can delete. This model cannot let someone correct data without also letting them destroy it.
Some action buttons require “create”, not “write”. This applies to operations started by buttons — “sync now”, “recalculate”, “run”. A role with read and write but no create permission will be denied when using them. This is the most common “I have permission, but it doesn’t work” report.
Module list
The set of modules grows with the system; below is the basic set:
| Module | Scope |
|---|---|
| Orders | Orders and shipments |
| Products | Product catalogue |
| Warehouse and returns | Warehouse operations and returns |
| Locations | Warehouse structure, zones, stations |
| Inventory | Inventory tasks and adjustments |
| Receiving | Receiving goods |
| Replenishment | Shelf replenishment tasks |
| Deliveries | Deliveries and shipment tracking |
| Shipments and labels | Parcels, labels, manifests |
| Documents | Sales and warehouse documents |
| Order documents | Downloading documents attached to an order |
| Integrations | Marketplaces and carriers |
| Customers | Customer database |
| Issues | Reports and cases |
| Reports | Reports and analytics |
| Attendance | Schedules, leave, working time |
| Notifications | Message history and statistics, blocked recipients, accounts, and email/SMS templates. Custom notifications from the bell do not require this permission. |
| Print templates | Editing PDF/email/SMS templates |
| Users | Company accounts |
| Roles and permissions | Roles and permissions |
| Settings | Company and system configuration |
| Automations | Workflow rules, custom events, execution logs |
| AI Assistant | Assistant |
| Change log | Change audit |
| Advanced | Diagnostic section in the menu |
| System | System administration |
You can see the exact set in your deployment in the role editing window — it is generated from the database, not from this article.
Modules that behave differently from how they look
- Advanced is only a visibility switch for the menu section. Granting it gives access to nothing — every page under it has its own gate. Removing it blocks nothing either: anyone who knows the address can still open the page.
- Order documents works only in the interface. Removing it hides download buttons but does not block the file itself — the document link is a key in its own right (Document tracking — files attached to orders).
- Print templates applies to editing templates. Printing with an existing template does not require this permission.
- Roles and permissions also covers creating new companies. If you grant it, know that you are granting more than role management.
Beware of modules that do nothing
The grid may contain entries that no screen checks — leftovers from older versions or created by migrations despite having no use. Selecting them will not unlock anything. If you granted a permission and nothing changed, check whether it is one of these entries (Permission traps — why granting access sometimes changes nothing).
Want to see this with your orders? We’ll show you NOXTI with your sales channels and warehouse.
Book a demo