Administration
Roles and permissions
Who can do what. A cooperative starts with six roles; the administrator can change any of them, or add more, under Settings → Roles & permissions.
Scope
Every role is either own branch — the user acts only at the branches assigned to them — or all branches. Permissions are checked on the server for every request; hiding a button is never the only guard.
The starting roles
| Role | Scope | What it is for |
|---|---|---|
| Billing operator | Own branch | Bills, returns and day close; sees stock |
| Stock keeper | Own branch | Goods receipt, transfers out and in, stock take, Handloom labels, issuing and receiving job work; branch reports |
| Outlet manager | Own branch | Everything at the branch: bills and cancellations, discount, credit and stock approvals, catalogue, purchases and returns to suppliers, stock adjustments, purchase orders, job work including excess wastage, proposing markdowns, expos and GeM orders |
| Head office accountant | All branches | Vouchers and reversals, supplier payments, parties, period lock, GST returns and GST TDS, rebate claims, Marketing Incentive claims and the weaver roll, purchase orders, expos and GeM, consolidated reports |
| Head office administrator | All branches | Users, branches, master data, rebate schemes, settings, licence; catalogue; approving markdowns; Marketing Incentive rules; the audit trail and pack |
| Auditor | All branches | Reads and exports everything; changes nothing |
Separation of duties
- The administrator is not all-powerful. The person who manages users cannot post vouchers or unlock a closed period — no default role can unlock one; an owner grants it deliberately.
- The auditor role can only read. Giving it a permission that changes anything is refused, so its independence cannot be undone by accident.
- Approvals are split from requests: whoever proposes a markdown cannot approve it, and whoever counts an expo cannot approve its variance.
- Whoever prepares a Marketing Incentive claim cannot change the rules it is worked out by.
Permission reference
A permission ending in .view or .export only reads; everything else changes something.
| Area | Permissions |
|---|---|
| Sales | sales.bill.create sales.bill.view sales.bill.cancel sales.return.create sales.discount.approve sales.credit.approve sales.stock.override sales.channel.override sales.dayclose.perform sales.expo.view sales.expo.manage sales.gem.view sales.gem.manage |
| Inventory | inventory.item.view inventory.item.manage inventory.grn.create inventory.purchase.view inventory.purchase.return inventory.transfer.initiate inventory.transfer.receive inventory.stocktake.perform inventory.adjustment.approve inventory.purchase_order.view inventory.purchase_order.manage inventory.job_work.view inventory.job_work.issue inventory.job_work.receive inventory.job_work.approve inventory.label.manage inventory.markdown.manage inventory.markdown.approve |
| Accounts | accounts.voucher.create accounts.voucher.view accounts.voucher.reverse accounts.payment.create accounts.books.view accounts.period.lock accounts.period.unlock accounts.party.manage accounts.rebate.claim accounts.rebate.view |
| Weavers and incentives | weavers.roll.view weavers.roll.manage incentives.claim.view incentives.claim.manage incentives.rules.manage |
| GST | gst.return.prepare gst.return.export gst.tds.view gst.tds.manage |
| Reports and audit | reports.branch.view reports.consolidated.view reports.export audit.trail.view audit.trail.export |
| Administration | admin.user.manage admin.branch.manage admin.masterdata.manage admin.rebate.manage admin.settings.manage admin.licence.view |