Platform · Access control
Roles & permissions
Permissions combine an action set with a data scope, so a depot manager only sees and approves their own location while management sees everything read-only.
Permission matrix
Sample configuration for the proposed user groups
| Role | Users | Data scope | View | Create | Edit | Approve | Export | Admin |
|---|---|---|---|---|---|---|---|---|
| System Administrator | 3 | All locations | ||||||
| Warehouse Supervisor | 8 | Assigned warehouse | ||||||
| Inventory Controller | 14 | Assigned zones | ||||||
| Production Controller | 6 | Factory + production areas | ||||||
| Sales Representative | 62 | Assigned outlets | ||||||
| Sales Supervisor | 11 | Territory | ||||||
| Trade Marketing | 7 | All outlets (read) | ||||||
| Management | 5 | All (read + approve) |
Proposed user groups
- Sales representatives, supervisors and managers
- Marketing and trade marketing teams
- Inventory controllers and warehouse teams
- Production and depot operations
- IT, system administrators and senior management
Scope rules
Location scope
EnforcedUsers only see documents for their assigned factory, warehouse or depot.
Territory scope
EnforcedSales roles see outlets in their assigned territory only.
Approval separation
EnforcedThe creator of an adjustment can never approve it.
Export control
EnforcedExport permission is granted separately and always audited.