Setting Permissions
Permissions determine which modules and functions a staff member can see and use in Evolution ERP. They are configured per staff member and applied automatically each time the user logs in.
Where Permissions Are Set
Permissions are managed against each staff record. To edit them, navigate to a staff member's record and open the Permissions tab:
The Permissions tab lists each module alongside a drop-down for its access level. Choose the appropriate level for every module, then save the staff record.
Access Levels
Most modules offer three levels of access:
Denied
The user has no access to the module. Its menu items, screens and related functions are hidden or blocked.
Allowed
Standard access. The user can use the module for everyday work, but cannot perform administrative or restricted actions within it.
Admin
Full access to the module, including elevated functions such as approvals, configuration and overrides that are not available at the Allowed level.
The Timesheets module uses the same three levels, with Denied shown as Not Allowed. Super User is a simple Yes / No setting (see below).
How Permissions Are Applied
Permissions are stored against the staff member and read into the user's session at login. Each screen in the system then checks the user's session to decide what to display and which actions to allow.
Module Reference
The following modules can each be set to Denied, Allowed or Admin:
| Module | What it controls |
|---|---|
| Sales | Quotes, sales orders and the sales side of customer transactions. At Admin, also the Sales reports on the reports dashboard. |
| Purchasing | Purchase orders, supplier ordering and receipting of goods. |
| Accounts Payable | Supplier invoices, supplier credit notes, payments and money owed to suppliers. |
| Accounts Receivable | Customer invoices, customer credit notes, receipts and money owed by customers. |
| General Ledger | Chart of accounts, journals and core financial reporting. |
| Job Costing | Projects, job costing and tracking of costs against work. |
| Inventory | Stock items, stock levels and inventory movements. |
| Payroll | Pay runs, employee pay details and payroll processing. |
| Reports | Access to the reporting screens and the reports available within them. |
| Business Registers | Company registers and supporting business records. |
| Timesheets | Entry and management of staff timesheets. Uses Not Allowed / Allowed / Admin. |
Examples: Allowed vs Admin
For most modules, Allowed covers everyday work while Admin adds the elevated actions — approvals, un-committing locked transactions, deleting records, and seeing sensitive figures or reports. Denied hides the module from the menu entirely. The examples below show the practical difference for each module.
| Module | Allowed | Admin |
|---|---|---|
| Sales | View and work with sales leads, opportunities and quotes. | Everything in Allowed, plus add and edit customer contracts, and open the Sales reports — quote performance by rep, converted quotes by customer, and the monthly invoicing / AR register reports. (Business Registers admin also grants these, so either module works.) |
| Purchasing | Raise and view requisitions, purchase orders and back orders. | Everything in Allowed, plus elevated purchasing actions. |
| Accounts Payable | View and enter supplier bills, and view supplier credit notes. | Everything in Allowed, plus un-commit a committed bill, approve staff leave requests, and create, edit, allocate and delete supplier credit notes. (Committing or un-committing a credit note also requires General Ledger access — see the note below.) |
| Accounts Receivable | View and raise customer invoices, and view customer credit notes. | Everything in Allowed, plus un-commit a committed invoice, flag a project for invoice review, see the admin-only sections on the customer record, and create, edit, allocate and delete customer credit notes. (Committing or un-committing a credit note also requires General Ledger access — see the note below.) |
| General Ledger | View the general ledger and chart of accounts. Also required to commit or un-commit a credit note, because committing posts the credit to the general ledger. | Everything in Allowed, plus access ticket and project billing screens. |
| Job Costing | View and work with projects and project costs. | Everything in Allowed, plus approve / un-approve timesheets against projects, delete notes, update project work status, and view the project WIP, billable-items and closed-variation reports. |
| Inventory | View stock items; cost figures are shown but are read-only. | Everything in Allowed, plus edit the true cost field, approve items flagged for review, and delete inventory categories and specifications. |
| Payroll | View staff and submit leave requests. | Everything in Allowed, plus payroll administration. (Leave approval itself is controlled by Accounts Payable.) |
| Reports | Open the reporting screens and run standard reports. | Everything in Allowed. Note that the most sensitive report areas are gated by their own module instead — Financials by General Ledger, and Sales by Sales or Business Registers. |
| Business Registers | View the company business registers. | Everything in Allowed, plus manage register entries, view the Qualifications reports, and view the Sales reports (staff performance / invoicing). Sales admin also grants the Sales reports, so a sales manager no longer needs this module for them. |
| Timesheets | Enter and edit your own timesheets only. | View and approve all staff timesheets, and invoice work directly from timesheets. |
- Allowed — view the credit note register and open existing credit notes (read only).
- Admin — create, edit, allocate and delete credit notes.
- Committing or un-committing a credit note posts to the general ledger, so it also requires General Ledger access (at least Allowed) in addition to the Admin level on the relevant AR/AP module.
Super User
The Super User setting is separate from the module access levels. When set to Yes, the staff member is treated as an administrator across the system and is granted access to administrative areas — including the Permissions tab itself, where they can set access for other staff.
Recommended Approach
- Start from Denied and grant only the modules a staff member needs for their role.
- Use Allowed for day-to-day users and reserve Admin for those who manage or approve within a module.
- Keep Super User limited to a small number of trusted administrators.
- Remind users that permission changes only apply after they next log in.
Support
For help mapping roles to permission levels in your organisation, please contact Evolution ERP Support.