Roles and access: how permissions work
How BSuit decides what each person can see and do, how access is requested and reviewed, and multi-factor sign-in.
On this page
#The model in one paragraph
A person has one or more roles; a role holds permissions; a permission is written module.record.action — for example finance.fiscalyear.edit. The standard actions are view, create, edit and delete. Vouchers use record_type.<code>.<action>, for example record_type.CASH-REC.create. A superuser account passes every check. Business actions such as approve, post, close or release are checked by their own rules, which are described in each process chapter.
#Where to manage access
| Task | Screen |
|---|---|
| Create and deactivate users | Users |
| Create roles and assign permissions | User roles |
| Browse all permissions | Permissions |
| Give people roles | Role assignment |
| See what one person can actually do | Effective permissions |
| Request temporary access | Access requests |
| Periodic recertification | Access review |
| Who changed which permission | Permission audit |
#Roles delivered with BSuit
Each module seeds its standard roles (for example Finance Manager, Warehouse Clerk, Technician, Maintenance Manager, HR Payroll Admin, Registrar, Bursar, Faculty, Doctor, Nurse). The Roles and permissions directory lists every role with what it can do: Roles and permissions. Some seeded roles are created empty and must be given permissions before use; the directory shows only roles that currently hold permissions.
#Requesting temporary access
- Open Identity › Access requests and choose New request.
- Pick the role, a duration between 1 and 720 hours, and write a justification (required).
- An administrator approves or denies it. Approval is refused if the role would create a segregation-of-duties conflict with roles you already hold.
- Approved access is time-bound and ends automatically.
#Access reviews
In an access review an administrator decides, for each person and role, to keep or revoke. Revoking removes the access immediately and the decision is recorded for audit.
#Multi-factor sign-in
- Open your own security page (Administration › My security).
- Scan the code with an authenticator app and enter the 6-digit code to confirm.
- Store the recovery codes safely; each works once.
#Troubleshooting access
| Symptom | Likely cause | What to do |
|---|---|---|
| A menu item or button is missing | Your roles lack the view or create permission | Ask an administrator to check Effective permissions for you. |
| "You do not have permission…" on save | Missing create/edit permission for that record or voucher type | Request the specific role, or temporary access. |
| Approve or post is refused although you can edit | These actions have their own rules (see the process chapter) | Check the process chapter for who may approve or post. |
About this guide
- Status
- Partially reviewed
- Application
- BSuit ERP
- Audience
- Administrators, managers and anyone requesting access
- Owner
- BSuit documentation team
- Reviewer
- Editorial review pending
- Last verified
- 2026-09-25
- Checked against
- cb3691bbf
- Seen on a running system
- Not yet
- Help version
- 2026.0.0-preview
- Guide ID
erp:article/guide/roles-and-access
Known limits: Written from a line-by-line read of the implementation (every statement traced to source). Not yet walked through end to end by a trainer on a running system.