AlphaAlpha Docs

Roles & Permissions

Role-based access control in Alpha

Roles & Permissions

Configure role-based access control (RBAC) in Alpha.

Understanding Roles

Roles are named collections of permissions that define what actions users can perform in the system. Instead of assigning individual permissions to each user, you assign roles that bundle related permissions together.

How Roles Work

  1. Create a role with the permissions needed for a job function
  2. Assign the role to users who perform that function
  3. Users inherit all permissions from their assigned roles
  4. Update the role to change permissions for all users with that role

Roles control what a user can do. For controlling where they can do it (which subsidiaries and projects), see Access Control.

System Roles vs Tenant Roles

Alpha has two types of roles:

TypeScopeExamples
System RolesPlatform-wide, cannot be modifiedSuper Admin, User
Tenant RolesOrganization-specific, fully customizableSales Manager, Warehouse User

System roles are assigned by platform administrators. Tenant roles are managed within your organization.

Default Roles

Alpha automatically creates a few tenant roles in specific situations:

RoleCreated WhenPermissions
EmployeeHR module is enabledOwn time entries and leave requests, read tasks
HR ManagerHR module is enabledFull HR management (employees, tasks, sprints, epics, features, leave, recruiting)
Asset ViewerA client is added to an asset locationRead-only Asset Management access

All other roles are created and managed by your organization.

Managing Roles

Creating Roles

  1. Go to Administration > Roles
  2. Click Add Role
  3. Name the role
  4. Select permissions
  5. Save

Editing Roles

  1. Open role
  2. Add/remove permissions
  3. Save
  4. Affects all users with role

Deleting Roles

  1. Reassign users to other roles
  2. Delete role
  3. Cannot delete if users assigned

Permission Categories

Alpha organizes permissions by functional module. When creating or editing roles, you select permissions from these categories.

The role editor only shows permissions for modules that are enabled for your organization. If a category below is missing, that module is disabled for your tenant.

Application Permissions

Core system and administration permissions:

PermissionDescription
Tenant AdminFull administrative access to the organization. Also bypasses all subsidiary and project access checks (equivalent to the per-user Full Access flag — see Access Control).
Read TenantView organization settings
Update TenantModify organization settings
Read UsersView user accounts
Manage UsersCreate, edit, deactivate users
Manage RolesCreate and modify roles
Read StatsView dashboard statistics
Finance ManagerAccess to financial overview features
Create API KeysGenerate API keys for integrations
Read API KeysView existing API keys
Delete API KeysRemove API keys

Products Permissions

PermissionDescription
Create ProductsAdd new products
Read ProductsView product catalog
Update ProductsModify product information
Delete ProductsRemove products

Finance Permissions

Permissions for financial operations:

Clients

PermissionDescription
Create ClientsAdd new clients
Read ClientsView client information
Update ClientsModify client details
Delete ClientsRemove clients

Estimates

PermissionDescription
Create EstimatesCreate new estimates
Read EstimatesView estimates
Update EstimatesModify estimates
Delete EstimatesRemove estimates
Send EstimatesEmail estimates to clients

Purchase Orders

PermissionDescription
Create POCreate purchase orders
Read POView purchase orders
Update POModify purchase orders
Delete PORemove purchase orders
Review POReview and approve purchase orders
Close POClose completed purchase orders
Reinstate POReopen closed purchase orders
Manage Suppliers POManage supplier relationships
Manage PO ApprovalConfigure purchase order approval rules

Sales Orders

PermissionDescription
Create OrdersCreate sales orders
Read OrdersView sales orders
Update OrdersModify sales orders
Delete OrdersRemove sales orders

Invoices

PermissionDescription
Create InvoicesGenerate invoices
Read InvoicesView invoices
Update InvoicesModify invoices
Delete InvoicesRemove invoices
Send InvoicesEmail invoices to clients

Debit Notes

PermissionDescription
Create Debit NotesCreate debit notes
Read Debit NotesView debit notes
Update Debit NotesModify debit notes
Delete Debit NotesRemove debit notes
Send Debit NotesEmail debit notes

Suppliers

PermissionDescription
Create SuppliersAdd new suppliers
Read SuppliersView supplier information
Update SuppliersModify supplier details
Delete SuppliersRemove suppliers

Bank Accounts & Transactions

PermissionDescription
Create Bank AccountsAdd bank accounts
Read Bank AccountsView bank accounts
Update Bank AccountsModify bank accounts
Delete Bank AccountsRemove bank accounts
Import Bank TransactionsImport bank transaction files
Update Bank TransactionsModify bank transactions (e.g. matching)
Delete Bank TransactionsRemove bank transactions

Inventory Permissions

PermissionDescription
Create InventoryAdd inventory records
Read InventoryView stock levels
Update InventoryModify inventory
Delete InventoryRemove inventory records
Review TransferApprove or reject stock transfers
Create PicklistsGenerate pick lists
Read PicklistsView pick lists
Update PicklistsModify pick lists
Delete PicklistsRemove pick lists
Create CountStart stock counts
Read CountView stock counts
Update CountModify stock counts
Delete CountRemove stock counts
Review CountReview and approve counts
Close CountFinalize stock counts

Production Permissions

PermissionDescription
Create ProductionCreate production orders
Read ProductionView production orders
Update ProductionModify production orders
Delete ProductionRemove production orders
Create MaterialsAdd material records
Read MaterialsView materials
Update MaterialsModify materials
Delete MaterialsRemove materials
Create/Read/Update/Delete ShiftsManage production shifts
Manage ShiftsConfigure production shifts
Create/Read/Update/Delete WasteManage waste records
Manage WasteConfigure waste categories
Report WasteRecord production waste

Projects Permissions

PermissionDescription
Create ProjectsCreate new projects
Read ProjectsView project information
Update ProjectsModify project details
Delete ProjectsRemove projects

Configurator Permissions

For product configuration features:

PermissionDescription
Create/Read/Update/Delete ConceptsManage configurator concepts
Create/Read/Update/Delete TypesManage product types
Create/Read/Update/Delete OptionsManage configuration options
Create/Read/Update/Delete Option CodesManage option codes
Create/Read/Update/Delete VariablesManage configuration variables
Create/Read/Update/Delete Queue JobsManage processing queue
Create/Read/Update/Delete FacadesManage facades

Asset Management Permissions

PermissionDescription
Create AssetsAdd new assets
Read AssetsView asset information
Update AssetsModify asset details
Delete AssetsRemove assets

CRM Permissions

PermissionDescription
Create/Read/Update/Delete LeadsManage leads
Create/Read/Update/Delete OpportunitiesManage opportunities
Create/Read/Update/Delete ActivitiesManage CRM activities
Read CustomersView customers
Read CRM DashboardView the CRM dashboard
Manage CRM SettingsConfigure CRM settings
Read Quiz SubmissionsView questionnaire submissions

Calendar Permissions

PermissionDescription
Create Calendar EventsCreate calendar events
Read CalendarView the calendar
Update Calendar EventsModify calendar events
Delete Calendar EventsRemove calendar events
Manage CalendarAdminister calendar configuration

Communications Permissions

PermissionDescription
Create/Read/Update/Delete TemplatesManage email templates
Send CommunicationsSend emails
Read CommunicationsView sent communications
Delete CommunicationsRemove communications
Create/Read/Update/Delete Recipient ListsManage recipient lists
Read/Update Communication SettingsView and modify communication settings

HR Permissions

PermissionDescription
Create/Read/Update/Delete EmployeesManage employees
Create/Read/Update/Delete EpicsManage epics
Create/Read/Update/Delete FeaturesManage features
Create/Read/Update/Delete TasksManage tasks
Create/Read/Update/Delete SprintsManage sprints
Create/Read/Update/Delete Time EntriesManage time entries
Approve Time EntriesApprove submitted time entries
View Team TimeView team members' time
Create/Read/Update/Delete Leave RequestsManage leave requests
Approve Leave RequestsApprove leave requests
View Team LeaveView team members' leave
Manage Vacation BalanceAdjust vacation balances
Read HR DashboardView the HR dashboard
Create/Read/Update/Delete TeamsManage teams
Read Vacancies / Manage VacanciesView and manage vacancies
Read Applications / Manage ApplicationsView and manage job applications

Document Permissions

PermissionDescription
Create DocumentsUpload documents
Read DocumentsView documents
Update DocumentsModify documents
Delete DocumentsRemove documents
Share DocumentsShare documents with others

Reporting Permissions

PermissionDescription
Read Sales ReportsView the Sales report
Read Waste ReportsView the Waste report
Read Stock ReportsView the Stock report
Read Usage ReportsView the Usage report
View Stock ValueSee monetary stock value on the Inventory dashboard, the Inventory table, and the Stock report. See Hiding stock value below.

Hiding stock value from most users

By default the VIEW_STOCK_VALUE permission is not granted to any role. Users who don't have it can still see stock counts and units, but every monetary column ("Total Stock Value", "Value" per row, etc.) is hidden.

Grant it only to roles that legitimately need to see cost / inventory value:

  1. Go to Administration → Roles
  2. Open the role that should see stock value (e.g. Finance, Purchasing, Managing Director)
  3. Scroll to Reporting
  4. Tick View Stock Value
  5. Save

Users with that role will see the value columns on their next page load. Users without the role will see the same screens with the value columns removed — no separate "denied" view is needed.

This is a tenant-wide permission. There is no per-subsidiary stock-value gate — if a user can see a subsidiary's stock at all, the View Stock Value permission decides whether monetary columns are shown for it.

Permission Naming

Most permissions follow CRUD naming — Create, Read, Update, Delete — per entity, with extra action permissions where a workflow needs them (for example Review PO, Review Transfer, Send Invoices). Each permission is toggled individually in the role editor.

Role Hierarchy

Example Structure

Administrator (all permissions)
├── Manager Roles (department permissions)
│   ├── Sales Manager
│   ├── Warehouse Manager
│   └── Finance Manager
└── User Roles (limited permissions)
    ├── Sales User
    ├── Warehouse User
    └── Viewer

Assigning Roles

Single Role

Users typically have one role:

  1. Open user
  2. Select role
  3. Save

Multiple Roles

If needed:

  1. Create combined role
  2. Or assign multiple
  3. Permissions combine

Testing Roles

Before Deployment

  1. Create test user
  2. Assign role
  3. Test access
  4. Verify restrictions

Best Practices

Principle of Least Privilege

  • Grant minimum needed access
  • Start restrictive
  • Add permissions as needed

Role Maintenance

  • Review roles quarterly
  • Remove unused permissions
  • Document role purposes

Roles vs Access Control

It's important to understand the difference between roles and access control:

AspectRolesAccess Control
ControlsWhat actions users can performWhich resources users can see
ScopeFeature permissionsSubsidiaries and projects
InheritanceUsers inherit role permissionsSubsidiary access inherits to children
DocumentationThis pageAccess Control

A user needs both appropriate role permissions and resource access to perform an action on a specific resource.

On this page