Skip to main content
Permissions are grouped by feature area. They are assigned to roles, not individual users. Every action in the dashboard is gated by a specific permission — if a user cannot see a page, it means their role does not have the required permission.
Permissions configuration screen showing permission groups
A Manager role typically has all permissions. A Cashier role typically has no Manage or Users permissions — only what they need to operate the POS terminal.
These permissions are the building blocks of roles. To create a new role or assign permissions to a user, see Users and Roles. This page is a reference guide for understanding what each permission controls.

Permission Groups

Manage

Users

Staff

Reports

Online Ordering

E-Invoicing

Platform Admin (Root Users Only)

These permissions only apply to root admin accounts and are separate from the tenant role system above — a tenant role can never grant access to these.
The LHDN intermediary credential and signing-certificate endpoints (see LHDN Intermediary Setup) are restricted to root accounts but do not have a separate granular permission — any active root user can access them. Keep the root user list small (see Root Users).

How Permissions Work

  • Permissions are always assigned to a role, never directly to a user.
  • A user can have multiple roles — they receive the union of all permissions across their roles.
  • Removing a permission from a role takes effect immediately for all users with that role. Users currently logged in will lose access on their next page load.
Never grant the Users — Delete or Roles — Delete permissions to roles unless you fully trust those users. Misuse can remove accounts (including your own admin account) from the system. Always keep at least one active admin user with full access.

Frequently Asked Questions

Go to Users → Roles, open the role assigned to that user, and check whether the required permission (e.g. Reports — View) is toggled on. Save and ask the user to refresh their browser.
Yes. Create a role with only the permissions that feature requires (e.g. only Reports — View) and assign that role to the user.
The change takes effect on the user’s next page load or navigation. They will see an “Access Denied” message if they try to access a page the updated role no longer permits.
Not directly on the user page — you need to check each role assigned to the user and combine the permissions. A future update will show a merged permissions view per user.
Start with an existing role that is closest to your use case (e.g. Manager for admin, Cashier for POS operators). In the Users and Roles section, duplicate that role and remove or add specific permissions. For example, a Stock Manager might copy Manager permissions but remove Users — Delete and E-Invoicing permissions. Test the role with a test account to confirm access is correct.

Users & Roles

Create roles and assign them to users

Tenant Operations

Destructive root-only actions

Dashboard Overview

Understand what each section does

Login Problems

Fix access issues