Configure, for each employee, shop by shop and module by module (workshop, warehouse, POS, documents, customers, marketplace, hub), the view, create, edit, and delete permissions.
Beyond the general role/uLevel assigned when inviting a staff member, each employee at a repair shop can have granular permissions configured shop by shop and module by module, with four independent control levels — view, create, edit, delete — to limit access to exactly what they need, no more and no less.
Why it matters for a repair shop
In a repair business with several shops or with very different roles — a workshop technician, a front-desk cashier, a shop manager, an administrator — it makes no sense for everyone to see everything. A technician repairing smartphones and PCs needs to work in the repairs module and the parts warehouse of their own shop, but doesn't necessarily need to see fiscal documents or the customer database of every connected shop. A POS cashier needs to be able to take payments, but shouldn't be able to delete an entire repair history.
Granular permissions are how a management system for smartphone and PC repair shops turns this separation of roles into practice: they reduce the risk of operational mistakes, protect sensitive company and customer data, and let you grow your technical staff without having to grant full access to every new hire.
In practice
Permissions are configured from the employee's record, in a dedicated section separate from their personal details. The modules you can act on are: shop/storefront, workshop (repair management), warehouse, POS, documents, customers, marketplace, and the cross-shop repair hub. For each module, and for each shop the employee is associated with, you can independently enable or disable four actions: view, create, edit, and delete.
This means you can build very precise combinations: a technician can have view and edit access to the workshop module of their own shop, without being able to delete repairs already recorded; a shop manager can have full view access to warehouse and documents but no delete permission, reserved only for the owner. Permissions are organized by shop: if an employee works across several outlets, you can assign different combinations of modules and actions per shop, or quickly replicate the same configuration across all of them using the bulk enable/disable action per shop.
These granular permissions add to the employee's general role/uLevel, which remains the first access filter to the system's features: the role sets the overall scope (for example operational staff or administration), while module and shop permissions further refine exactly what that employee can view, create, edit, or delete.
Quick guide
- Go to Company > Staff users and open the employee's record.
- Enter the dedicated permissions section inside the user record.
- Select the shop you want to configure permissions for.
- For each module (workshop, warehouse, POS, documents, customers, marketplace, hub...) enable or disable view, create, edit, and delete.
- Use bulk enable/disable if you want to turn on or block every module for a shop in a single action.
- Repeat the configuration for every other shop the employee works in, with different permissions if needed.
- Save the changes: the new permissions apply from the employee's next login to the system.
Real-world use cases
Junior workshop technician. A repair shop hires a new, inexperienced technician: they get view and edit access to only the workshop module of the shop they work in, with no delete permission and no access to the documents module, so they can't accidentally delete a repair's history or issue fiscal documents.
Front-desk cashier. An employee who only handles reception and checkout gets permissions on the POS module and view access on the customers module, to record sales and payments, but stays excluded from warehouse and marketplace, modules they don't need for their daily work.
Multi-shop manager. A repair business with three outlets gives a manager full view access to warehouse, documents, and repairs across all three shops, but limits delete permissions to the owner only, to keep centralized control over the most sensitive operations.
Tips and best practices
Always start from the principle of least privilege: assign only the modules and actions a given employee's role genuinely needs, and widen access only when truly required. Periodically review the permission setup, especially when an employee changes role or shop. Reserve delete permission for higher-responsibility roles, since it's the most sensitive action on data such as repairs, fiscal documents, and customer records. Keep a record of who has access to what: a quick per-shop permissions summary lets the owner respond immediately to internal audits, a customer dispute, or requests related to the personal data handled during repairs.
Common mistakes to avoid
Don't grant full access to every module to every new employee just for convenience: it's the most common shortcut, but it exposes sensitive company and customer data to people who don't actually need it. Don't forget to configure permissions for every shop the employee works in: a permission set only on the main shop leaves the others uncovered. Don't confuse the general role/uLevel with granular permissions: the former sets the scope, the latter the detail, and both need checking.
Frequently asked questions
Do permissions replace the employee's role/uLevel? No, they add to the general role and let you refine, module by module and shop by shop, exactly what that employee can view, create, edit, or delete.
Which modules can I configure permissions for? Shop/storefront, workshop, warehouse, POS, documents, customers, marketplace, and the cross-shop repair hub.
Can I give an employee different permissions in different shops? Yes, permissions are configured shop by shop, so you can assign different combinations depending on the outlet the employee works in.
What are the four view/create/edit/delete levels? They're the four independent actions you can enable or disable per module: an employee could, for example, view and edit without being able to delete.
Is there a quick way to enable or block every module for a shop? Yes, a bulk enable/disable action per shop is available, useful when setting up a new employee from scratch.
When do new permissions become active? From the employee's next login to the system, after saving the changes in their record.