Roles & permissions
Who can see what, and who can change it.
Roles & permissions
BizFlow controls access with a role-based permission system. Every module, action and page is checked against the signed-in user's role and permissions.
Tenants and organizations
- A tenant is the top-level business (its own billing, storage and administrators).
- An organization belongs to a tenant and groups people, settings and data. Users belong to one or more organizations and switch between them.
- Requests carry the active organization (
x-organization-idheader) so every module shows the right data.
Roles
| Role | Scope | Typical permissions |
|---|---|---|
| Tenant Owner / Admin | Whole tenant | Everything, billing, storage, users, organizations |
| Super Admin | Organization | Everything in the organization |
| Admin Manager | Organization | Everything except tenant-level billing |
| General Manager | Organization | Full operational access |
| Organization roles (Member etc.) | Organization | Permission-dependent: read or write per module |
People are further classified as employees, freelancers or funded trainees — each with its own directory, documents and payroll handling.
Permissions
The web sidebar gates every item behind a permission such as:
SYSTEMS_DASHBOARD— dashboardPackage_VIEW,POS_VIEW— catalog and point of sale- Financial, HR, tools, fleet, projects and shop permissions per module
The User Management page (Director section, /dashboard/human-resources/users) lets administrators:
- Add and deactivate users
- Change a user's role
- Grant or revoke module-level permissions
- See which organizations a user belongs to
Plan-based access
A module is only visible if the organization's subscription plan includes it. For example, the POS requires the pos feature, tools require tools, the AI Assistant requires ai_assistance. See Plans & subscription.
How to manage access
- Go to Human Resources → User Management (Directors/admins only).
- Find the user and open their form.
- Change their role or toggle permissions, then save.
- The change applies on the user's next action — no re-login needed.
Frequently asked
- I can't see a module — either your role lacks the permission, or the plan does not include the feature. Check both with your tenant owner.
- A user left the company — deactivate them in User Management; their data is kept for payroll and history.
- Someone needs read-only access — assign a member role and grant only the modules they need.