Change what a role can do¶
Who can do this¶
Administrators, and the screen is deliberately protective — changing what a role can do is supervised for everyone, including managers.
The three states a permission can be in¶
Every action a role might take is in one of three states, and they are the same three a person meets in use:
| State | Means |
|---|---|
| Granted | the role can do it |
| Denied | the role cannot, at all |
| Needs manager approval | the role can, with someone senior approving each time |
The middle option is the useful one. A cashier who can never discount is inflexible; a cashier who can discount freely is unsupervised. Needs manager approval is the answer for actions that are legitimate but should not be silent.
An outlet can restrict, never widen¶
A grant made for the brand is the ceiling. An individual outlet can hold a role to less than the brand allows, but it can never give a role more. The screen states the rule at the top: "An Outlet may restrict a Brand grant further — it can never expand one."
So if a role needs more than it has, the brand is where that is settled — tightening one outlet is not the way to loosen another.
Finding what you want to change¶
Permissions are searchable — there are a lot of them, and hunting through a list is how the wrong one gets changed. They are also grouped by area, matching the areas of the product: Overview, Serve, Operations, Manage, Books and Setup.
Steps¶
- Open Setup ▸ Roles & Permissions.
-
Choose the role you are changing from Role.
3. Find the permission — either search under Find a permission, by area, module or action key, or
pick it out of its area group.
4. Set it to granted, denied, or needing approval.
What you are looking at is the role's real, saved permissions, not a template or a default — the screen says so, and it matters when you are checking why someone was refused something.
The screen marks what has been changed for a role, so you can see how it differs from the standard.
Things to know¶
Changing a role changes it for everyone in it. This is not a per-person adjustment. If one person needs something different, the question is whether they are in the right role.
Prefer approval to a grant when you are unsure. It keeps the action possible and keeps a record of who allowed it.
Roles can be added, renamed and deleted. A new role is a real decision — every role you add is another thing to keep correct as the product changes.
Related¶
- Who can do what — the same three answers, from the user's side
- Add a user — putting someone into a role