Roles and access: how permissions work

How BSuit decides what each person can see and do, how access is requested and reviewed, and multi-factor sign-in.

On this page

#The model in one paragraph

A person has one or more roles; a role holds permissions; a permission is written module.record.action — for example finance.fiscalyear.edit. The standard actions are view, create, edit and delete. Vouchers use record_type.<code>.<action>, for example record_type.CASH-REC.create. A superuser account passes every check. Business actions such as approve, post, close or release are checked by their own rules, which are described in each process chapter.

#Where to manage access

Access screens
TaskScreen
Create and deactivate usersUsers
Create roles and assign permissionsUser roles
Browse all permissionsPermissions
Give people rolesRole assignment
See what one person can actually doEffective permissions
Request temporary accessAccess requests
Periodic recertificationAccess review
Who changed which permissionPermission audit

#Roles delivered with BSuit

Each module seeds its standard roles (for example Finance Manager, Warehouse Clerk, Technician, Maintenance Manager, HR Payroll Admin, Registrar, Bursar, Faculty, Doctor, Nurse). The Roles and permissions directory lists every role with what it can do: Roles and permissions. Some seeded roles are created empty and must be given permissions before use; the directory shows only roles that currently hold permissions.

#Requesting temporary access

  1. Open Identity › Access requests and choose New request.
  2. Pick the role, a duration between 1 and 720 hours, and write a justification (required).
  3. An administrator approves or denies it. Approval is refused if the role would create a segregation-of-duties conflict with roles you already hold.
  4. Approved access is time-bound and ends automatically.

#Access reviews

In an access review an administrator decides, for each person and role, to keep or revoke. Revoking removes the access immediately and the decision is recorded for audit.

#Multi-factor sign-in

  1. Open your own security page (Administration › My security).
  2. Scan the code with an authenticator app and enter the 6-digit code to confirm.
  3. Store the recovery codes safely; each works once.

#Troubleshooting access

Common access problems
SymptomLikely causeWhat to do
A menu item or button is missingYour roles lack the view or create permissionAsk an administrator to check Effective permissions for you.
"You do not have permission…" on saveMissing create/edit permission for that record or voucher typeRequest the specific role, or temporary access.
Approve or post is refused although you can editThese actions have their own rules (see the process chapter)Check the process chapter for who may approve or post.

About this guide

Status
Partially reviewed
Application
BSuit ERP
Audience
Administrators, managers and anyone requesting access
Owner
BSuit documentation team
Reviewer
Editorial review pending
Last verified
2026-09-25
Checked against
cb3691bbf
Seen on a running system
Not yet
Help version
2026.0.0-preview
Guide ID
erp:article/guide/roles-and-access

Known limits: Written from a line-by-line read of the implementation (every statement traced to source). Not yet walked through end to end by a trainer on a running system.

Need more help?If feedback above cannot be sent, email support and quote guide ID erp:article/guide/roles-and-access.
Email support