Skip to content

Permission management: fine-tuning roles

Revoking permissions — for entire roles or individual users. Why there is only revocation, no added permissions, and which permissions are untouchable.

The five roles come with sensible default permissions. Where the business wants to run tighter — the team lead shouldn't see costings, a particular employee shouldn't withdraw materials — permission management comes into play, under Settings → "Permissions". It sits right at the top of the settings menu, and only the Admin sees the entry at all.

Two levels

  • "Role permissions" — restrictions for all users of a role: "These settings apply to all users of the respective role…"
  • "User permissions" — additionally for individual people; both levels work together.

The roughly 80 individual permissions are grouped by topic ("Orders & planning", "Materials & inventory", "Trash", …) and each comes with a plain-language description.

The revocation model

Gantway can only revoke permissions, never add them: an employee doesn't gain Admin capabilities with a checkbox — anyone who should be able to do more needs the appropriate role. This keeps the model manageable and prevents permission sprawl.

Three guardrails:

  • Mandatory permissions (badge "Mandatory") cannot be revoked — "Basic permissions cannot be revoked." No one can be stripped of their own dashboard, for instance.
  • "Your own permissions cannot be restricted." — the Admin doesn't lock themselves out.
  • Entries with "Not enabled by the platform" are not part of this role's default permissions at all — they cannot be enabled here either; that requires a different role.

Auch bekannt als: Permissions, Authorizations, Roles, Restrict, Permission management, hide prices, hide purchase prices, hide cost prices.

Zuletzt aktualisiert am

Passt dazu

Frage offen geblieben?

Schreiben Sie uns — wir antworten und ergänzen den Artikel.

Frage stellen