← Back to landing

Roles & permissions

Who can see what, and who can change it.

Roles & permissions

BizFlow controls access with a role-based permission system. Every module, action and page is checked against the signed-in user's role and permissions.

Tenants and organizations

  • A tenant is the top-level business (its own billing, storage and administrators).
  • An organization belongs to a tenant and groups people, settings and data. Users belong to one or more organizations and switch between them.
  • Requests carry the active organization (x-organization-id header) so every module shows the right data.

Roles

RoleScopeTypical permissions
Tenant Owner / AdminWhole tenantEverything, billing, storage, users, organizations
Super AdminOrganizationEverything in the organization
Admin ManagerOrganizationEverything except tenant-level billing
General ManagerOrganizationFull operational access
Organization roles (Member etc.)OrganizationPermission-dependent: read or write per module

People are further classified as employees, freelancers or funded trainees — each with its own directory, documents and payroll handling.

Permissions

The web sidebar gates every item behind a permission such as:

  • SYSTEMS_DASHBOARD — dashboard
  • Package_VIEW, POS_VIEW — catalog and point of sale
  • Financial, HR, tools, fleet, projects and shop permissions per module

The User Management page (Director section, /dashboard/human-resources/users) lets administrators:

  • Add and deactivate users
  • Change a user's role
  • Grant or revoke module-level permissions
  • See which organizations a user belongs to

Plan-based access

A module is only visible if the organization's subscription plan includes it. For example, the POS requires the pos feature, tools require tools, the AI Assistant requires ai_assistance. See Plans & subscription.

How to manage access

  1. Go to Human Resources → User Management (Directors/admins only).
  2. Find the user and open their form.
  3. Change their role or toggle permissions, then save.
  4. The change applies on the user's next action — no re-login needed.

Frequently asked

  • I can't see a module — either your role lacks the permission, or the plan does not include the feature. Check both with your tenant owner.
  • A user left the company — deactivate them in User Management; their data is kept for payroll and history.
  • Someone needs read-only access — assign a member role and grant only the modules they need.