Roles & Permissions
Role-based access control in Alpha
Roles & Permissions
Configure role-based access control (RBAC) in Alpha.
Understanding Roles
Roles are named collections of permissions that define what actions users can perform in the system. Instead of assigning individual permissions to each user, you assign roles that bundle related permissions together.
How Roles Work
- Create a role with the permissions needed for a job function
- Assign the role to users who perform that function
- Users inherit all permissions from their assigned roles
- Update the role to change permissions for all users with that role
Roles control what a user can do. For controlling where they can do it (which subsidiaries and projects), see Access Control.
System Roles vs Tenant Roles
Alpha has two types of roles:
| Type | Scope | Examples |
|---|---|---|
| System Roles | Platform-wide, cannot be modified | Super Admin, User |
| Tenant Roles | Organization-specific, fully customizable | Sales Manager, Warehouse User |
System roles are assigned by platform administrators. Tenant roles are managed within your organization.
Default Roles
Alpha automatically creates a few tenant roles in specific situations:
| Role | Created When | Permissions |
|---|---|---|
| Employee | HR module is enabled | Own time entries and leave requests, read tasks |
| HR Manager | HR module is enabled | Full HR management (employees, tasks, sprints, epics, features, leave, recruiting) |
| Asset Viewer | A client is added to an asset location | Read-only Asset Management access |
All other roles are created and managed by your organization.
Managing Roles
Creating Roles
- Go to Administration > Roles
- Click Add Role
- Name the role
- Select permissions
- Save
Editing Roles
- Open role
- Add/remove permissions
- Save
- Affects all users with role
Deleting Roles
- Reassign users to other roles
- Delete role
- Cannot delete if users assigned
Permission Categories
Alpha organizes permissions by functional module. When creating or editing roles, you select permissions from these categories.
The role editor only shows permissions for modules that are enabled for your organization. If a category below is missing, that module is disabled for your tenant.
Application Permissions
Core system and administration permissions:
| Permission | Description |
|---|---|
| Tenant Admin | Full administrative access to the organization. Also bypasses all subsidiary and project access checks (equivalent to the per-user Full Access flag — see Access Control). |
| Read Tenant | View organization settings |
| Update Tenant | Modify organization settings |
| Read Users | View user accounts |
| Manage Users | Create, edit, deactivate users |
| Manage Roles | Create and modify roles |
| Read Stats | View dashboard statistics |
| Finance Manager | Access to financial overview features |
| Create API Keys | Generate API keys for integrations |
| Read API Keys | View existing API keys |
| Delete API Keys | Remove API keys |
Products Permissions
| Permission | Description |
|---|---|
| Create Products | Add new products |
| Read Products | View product catalog |
| Update Products | Modify product information |
| Delete Products | Remove products |
Finance Permissions
Permissions for financial operations:
Clients
| Permission | Description |
|---|---|
| Create Clients | Add new clients |
| Read Clients | View client information |
| Update Clients | Modify client details |
| Delete Clients | Remove clients |
Estimates
| Permission | Description |
|---|---|
| Create Estimates | Create new estimates |
| Read Estimates | View estimates |
| Update Estimates | Modify estimates |
| Delete Estimates | Remove estimates |
| Send Estimates | Email estimates to clients |
Purchase Orders
| Permission | Description |
|---|---|
| Create PO | Create purchase orders |
| Read PO | View purchase orders |
| Update PO | Modify purchase orders |
| Delete PO | Remove purchase orders |
| Review PO | Review and approve purchase orders |
| Close PO | Close completed purchase orders |
| Reinstate PO | Reopen closed purchase orders |
| Manage Suppliers PO | Manage supplier relationships |
| Manage PO Approval | Configure purchase order approval rules |
Sales Orders
| Permission | Description |
|---|---|
| Create Orders | Create sales orders |
| Read Orders | View sales orders |
| Update Orders | Modify sales orders |
| Delete Orders | Remove sales orders |
Invoices
| Permission | Description |
|---|---|
| Create Invoices | Generate invoices |
| Read Invoices | View invoices |
| Update Invoices | Modify invoices |
| Delete Invoices | Remove invoices |
| Send Invoices | Email invoices to clients |
Debit Notes
| Permission | Description |
|---|---|
| Create Debit Notes | Create debit notes |
| Read Debit Notes | View debit notes |
| Update Debit Notes | Modify debit notes |
| Delete Debit Notes | Remove debit notes |
| Send Debit Notes | Email debit notes |
Suppliers
| Permission | Description |
|---|---|
| Create Suppliers | Add new suppliers |
| Read Suppliers | View supplier information |
| Update Suppliers | Modify supplier details |
| Delete Suppliers | Remove suppliers |
Bank Accounts & Transactions
| Permission | Description |
|---|---|
| Create Bank Accounts | Add bank accounts |
| Read Bank Accounts | View bank accounts |
| Update Bank Accounts | Modify bank accounts |
| Delete Bank Accounts | Remove bank accounts |
| Import Bank Transactions | Import bank transaction files |
| Update Bank Transactions | Modify bank transactions (e.g. matching) |
| Delete Bank Transactions | Remove bank transactions |
Inventory Permissions
| Permission | Description |
|---|---|
| Create Inventory | Add inventory records |
| Read Inventory | View stock levels |
| Update Inventory | Modify inventory |
| Delete Inventory | Remove inventory records |
| Review Transfer | Approve or reject stock transfers |
| Create Picklists | Generate pick lists |
| Read Picklists | View pick lists |
| Update Picklists | Modify pick lists |
| Delete Picklists | Remove pick lists |
| Create Count | Start stock counts |
| Read Count | View stock counts |
| Update Count | Modify stock counts |
| Delete Count | Remove stock counts |
| Review Count | Review and approve counts |
| Close Count | Finalize stock counts |
Production Permissions
| Permission | Description |
|---|---|
| Create Production | Create production orders |
| Read Production | View production orders |
| Update Production | Modify production orders |
| Delete Production | Remove production orders |
| Create Materials | Add material records |
| Read Materials | View materials |
| Update Materials | Modify materials |
| Delete Materials | Remove materials |
| Create/Read/Update/Delete Shifts | Manage production shifts |
| Manage Shifts | Configure production shifts |
| Create/Read/Update/Delete Waste | Manage waste records |
| Manage Waste | Configure waste categories |
| Report Waste | Record production waste |
Projects Permissions
| Permission | Description |
|---|---|
| Create Projects | Create new projects |
| Read Projects | View project information |
| Update Projects | Modify project details |
| Delete Projects | Remove projects |
Configurator Permissions
For product configuration features:
| Permission | Description |
|---|---|
| Create/Read/Update/Delete Concepts | Manage configurator concepts |
| Create/Read/Update/Delete Types | Manage product types |
| Create/Read/Update/Delete Options | Manage configuration options |
| Create/Read/Update/Delete Option Codes | Manage option codes |
| Create/Read/Update/Delete Variables | Manage configuration variables |
| Create/Read/Update/Delete Queue Jobs | Manage processing queue |
| Create/Read/Update/Delete Facades | Manage facades |
Asset Management Permissions
| Permission | Description |
|---|---|
| Create Assets | Add new assets |
| Read Assets | View asset information |
| Update Assets | Modify asset details |
| Delete Assets | Remove assets |
CRM Permissions
| Permission | Description |
|---|---|
| Create/Read/Update/Delete Leads | Manage leads |
| Create/Read/Update/Delete Opportunities | Manage opportunities |
| Create/Read/Update/Delete Activities | Manage CRM activities |
| Read Customers | View customers |
| Read CRM Dashboard | View the CRM dashboard |
| Manage CRM Settings | Configure CRM settings |
| Read Quiz Submissions | View questionnaire submissions |
Calendar Permissions
| Permission | Description |
|---|---|
| Create Calendar Events | Create calendar events |
| Read Calendar | View the calendar |
| Update Calendar Events | Modify calendar events |
| Delete Calendar Events | Remove calendar events |
| Manage Calendar | Administer calendar configuration |
Communications Permissions
| Permission | Description |
|---|---|
| Create/Read/Update/Delete Templates | Manage email templates |
| Send Communications | Send emails |
| Read Communications | View sent communications |
| Delete Communications | Remove communications |
| Create/Read/Update/Delete Recipient Lists | Manage recipient lists |
| Read/Update Communication Settings | View and modify communication settings |
HR Permissions
| Permission | Description |
|---|---|
| Create/Read/Update/Delete Employees | Manage employees |
| Create/Read/Update/Delete Epics | Manage epics |
| Create/Read/Update/Delete Features | Manage features |
| Create/Read/Update/Delete Tasks | Manage tasks |
| Create/Read/Update/Delete Sprints | Manage sprints |
| Create/Read/Update/Delete Time Entries | Manage time entries |
| Approve Time Entries | Approve submitted time entries |
| View Team Time | View team members' time |
| Create/Read/Update/Delete Leave Requests | Manage leave requests |
| Approve Leave Requests | Approve leave requests |
| View Team Leave | View team members' leave |
| Manage Vacation Balance | Adjust vacation balances |
| Read HR Dashboard | View the HR dashboard |
| Create/Read/Update/Delete Teams | Manage teams |
| Read Vacancies / Manage Vacancies | View and manage vacancies |
| Read Applications / Manage Applications | View and manage job applications |
Document Permissions
| Permission | Description |
|---|---|
| Create Documents | Upload documents |
| Read Documents | View documents |
| Update Documents | Modify documents |
| Delete Documents | Remove documents |
| Share Documents | Share documents with others |
Reporting Permissions
| Permission | Description |
|---|---|
| Read Sales Reports | View the Sales report |
| Read Waste Reports | View the Waste report |
| Read Stock Reports | View the Stock report |
| Read Usage Reports | View the Usage report |
| View Stock Value | See monetary stock value on the Inventory dashboard, the Inventory table, and the Stock report. See Hiding stock value below. |
Hiding stock value from most users
By default the VIEW_STOCK_VALUE permission is not granted to any role. Users who don't have it can still see stock counts and units, but every monetary column ("Total Stock Value", "Value" per row, etc.) is hidden.
Grant it only to roles that legitimately need to see cost / inventory value:
- Go to Administration → Roles
- Open the role that should see stock value (e.g. Finance, Purchasing, Managing Director)
- Scroll to Reporting
- Tick View Stock Value
- Save
Users with that role will see the value columns on their next page load. Users without the role will see the same screens with the value columns removed — no separate "denied" view is needed.
This is a tenant-wide permission. There is no per-subsidiary stock-value gate — if a user can see a subsidiary's stock at all, the View Stock Value permission decides whether monetary columns are shown for it.
Permission Naming
Most permissions follow CRUD naming — Create, Read, Update, Delete — per entity, with extra action permissions where a workflow needs them (for example Review PO, Review Transfer, Send Invoices). Each permission is toggled individually in the role editor.
Role Hierarchy
Example Structure
Administrator (all permissions)
├── Manager Roles (department permissions)
│ ├── Sales Manager
│ ├── Warehouse Manager
│ └── Finance Manager
└── User Roles (limited permissions)
├── Sales User
├── Warehouse User
└── ViewerAssigning Roles
Single Role
Users typically have one role:
- Open user
- Select role
- Save
Multiple Roles
If needed:
- Create combined role
- Or assign multiple
- Permissions combine
Testing Roles
Before Deployment
- Create test user
- Assign role
- Test access
- Verify restrictions
Best Practices
Principle of Least Privilege
- Grant minimum needed access
- Start restrictive
- Add permissions as needed
Role Maintenance
- Review roles quarterly
- Remove unused permissions
- Document role purposes
Roles vs Access Control
It's important to understand the difference between roles and access control:
| Aspect | Roles | Access Control |
|---|---|---|
| Controls | What actions users can perform | Which resources users can see |
| Scope | Feature permissions | Subsidiaries and projects |
| Inheritance | Users inherit role permissions | Subsidiary access inherits to children |
| Documentation | This page | Access Control |
A user needs both appropriate role permissions and resource access to perform an action on a specific resource.