Roles & Permissions
DraftUnderstand how roles work, why users see different modules, and how access is managed.
Goal
Explain how users, roles, and permissions work in ICONK OS in simple, non-technical language. Help users understand why they see different modules and features, and how roles are assigned.
Who This Guide Is For
Company owners, administrators, and any user who wants to understand why they can (or cannot) access certain features.
What You Can Do
- Understand what roles and permissions are
- See the default roles available in your company
- Understand why some users see different modules
- Learn how roles are assigned to team members
- Know the difference between Owner, Admin, and Employee access
What You Should Not Expect Yet
- This guide does not cover every individual access rule. It explains the concepts in plain language.
- Custom role creation is available, but the exact list of permissions you can assign may vary.
- Some access rules are still being refined. The system works, but the naming and grouping may improve over time.
What Are Roles and Permissions?
Permissions
A permission is a specific ability to do something in the system. Examples include:
- View invoices
- Create journal entries
- Access the POS terminal
- Manage users
- View reports
Roles
A role is a collection of permissions. Instead of assigning individual permissions to each person, you assign them a role. The role determines what they can and cannot do.
Users and Members
- A user is a person with an ICONK OS account (email and password).
- A member is a user who belongs to a specific company. A user can be a member of multiple companies.
- Each membership has a role assigned to it.
Default Roles
When a company is created, several default roles are set up automatically:
Owner
The person who created the company. The Owner has all permissions in that company. There is typically one Owner per company.
What an Owner can do:
- Everything in the company workspace
- Manage users, roles, and settings
- Activate or deactivate modules
- View all data and reports
- Delete the company
Admin
An elevated role with broad permissions for day-to-day management.
What an Admin can typically do:
- Manage most business operations (accounting, invoicing, inventory, sales, etc.)
- Manage users and assign roles (except changing the Owner)
- Configure company settings
- View reports
Employee
A standard role for team members who need access to specific tools.
What an Employee can typically do:
- Access the modules and features assigned to their role
- Use self-service features (view shifts, request leave, view payslips)
- Perform day-to-day tasks within their assigned area
Why Do Some Users See Different Modules?
The sidebar shows only the modules that a user has permission to access. This is controlled by their role.
Examples
| User | Role | What They See | |------|------|--------------| | Sarah | Owner | All modules — Accounting, Inventory, POS, HR, Settings, etc. | | James | Admin | Most business modules, but not platform-level settings | | Maria | Cashier | POS terminal, sales history, and maybe inventory view | | Alex | Accountant | Accounting, invoicing, expenses, payments, reports | | Tom | Employee | Only My Workspace (shifts, leave, payslips) |
How It Works
- When a user logs in, the system checks their role in the current company.
- The system looks up which permissions that role has.
- The sidebar is filtered to show only modules the user has permission to access.
- If a user tries to visit a page they do not have permission for, they will be redirected or shown an access denied message.
How Roles Are Assigned
During Invitation
When you invite someone to your company, you select a role for them. This role determines what they can do from the moment they accept.
Changing a Role
- Go to Company → Users in the sidebar.
- Find the user you want to update.
- Edit their role assignment.
- Save the changes.
The user's access will update the next time they log in or refresh the page.
Creating Custom Roles
If the default roles do not fit your needs, you can create custom roles:
- Go to Company → Roles & Permissions in the sidebar.
- Click Create Role (or similar action).
- Give the role a name and description.
- Select the permissions you want this role to have.
- Save the role.
You can then assign this custom role to users during invitation or by editing their membership.
Owner vs. Admin: What Is the Difference?
| Feature | Owner | Admin | |---------|-------|-------| | All permissions | Yes | Most, but not all | | Can delete the company | Yes | No | | Can manage billing and subscriptions | Yes | UNCERTAIN — may depend on plan | | Can change other users' roles | Yes | Yes (except Owner) | | Can create custom roles | Yes | Yes | | Can activate/deactivate modules | Yes | UNCERTAIN — may require Owner |
Note: The Owner is a special membership type. There is typically only one Owner per company. The Owner cannot be removed by other users.
Known Limitations
- Some access rules are still being refined. Some pages may use broader access rules. If access does not behave as expected, ask an administrator to review the role.
- HR-related access rules are still being refined. Some HR pages use broader access rules while specific access rules are still being refined.
- The CRM module does not have its own dedicated access rule family yet. It uses customer and loyalty access rules.
- UNCERTAIN: The exact behavior of some admin-level actions (like module activation) may require Owner-level access, but this has not been fully verified for all scenarios.
How to Get Help or Troubleshoot
- If a user cannot see a module they need, check their role assignment. They may need a different role or additional permissions. See Account and Company Setup for how to manage users.
- If you are unsure which permissions a role has, go to Company → Roles & Permissions and review the role details.
- If you think a permission is not working correctly, contact your company administrator or see the Troubleshooting Guide.
- For general questions, see the FAQ.