Evolution ERP Documentation

Setting Permissions

Control which modules and functions each staff member can access.

Setting Permissions

Permissions determine which modules and functions a staff member can see and use in Evolution ERP. They are configured per staff member and applied automatically each time the user logs in.

Where Permissions Are Set

Permissions are managed against each staff record. To edit them, navigate to a staff member's record and open the Permissions tab:

Staff Register → (select a staff member) → Permissions tab

The Permissions tab lists each module alongside a drop-down for its access level. Choose the appropriate level for every module, then save the staff record.

info Only users with Super User (administrator) access can view and edit the Permissions tab.

Access Levels

Most modules offer three levels of access:

Denied

The user has no access to the module. Its menu items, screens and related functions are hidden or blocked.

Allowed

Standard access. The user can use the module for everyday work, but cannot perform administrative or restricted actions within it.

Admin

Full access to the module, including elevated functions such as approvals, configuration and overrides that are not available at the Allowed level.

The Timesheets module uses the same three levels, with Denied shown as Not Allowed. Super User is a simple Yes / No setting (see below).

How Permissions Are Applied

Permissions are stored against the staff member and read into the user's session at login. Each screen in the system then checks the user's session to decide what to display and which actions to allow.

warning Because permissions are loaded at login, a user who is already signed in must log out and back in before any permission changes take effect.

Module Reference

The following modules can each be set to Denied, Allowed or Admin:

Module What it controls
Sales Quotes, sales orders and the sales side of customer transactions. At Admin, also the Sales reports on the reports dashboard.
Purchasing Purchase orders, supplier ordering and receipting of goods.
Accounts Payable Supplier invoices, supplier credit notes, payments and money owed to suppliers.
Accounts Receivable Customer invoices, customer credit notes, receipts and money owed by customers.
General Ledger Chart of accounts, journals and core financial reporting.
Job Costing Projects, job costing and tracking of costs against work.
Inventory Stock items, stock levels and inventory movements.
Payroll Pay runs, employee pay details and payroll processing.
Reports Access to the reporting screens and the reports available within them.
Business Registers Company registers and supporting business records.
Timesheets Entry and management of staff timesheets. Uses Not Allowed / Allowed / Admin.

Examples: Allowed vs Admin

For most modules, Allowed covers everyday work while Admin adds the elevated actions — approvals, un-committing locked transactions, deleting records, and seeing sensitive figures or reports. Denied hides the module from the menu entirely. The examples below show the practical difference for each module.

Module Allowed Admin
Sales View and work with sales leads, opportunities and quotes. Everything in Allowed, plus add and edit customer contracts, and open the Sales reports — quote performance by rep, converted quotes by customer, and the monthly invoicing / AR register reports. (Business Registers admin also grants these, so either module works.)
Purchasing Raise and view requisitions, purchase orders and back orders. Everything in Allowed, plus elevated purchasing actions.
Accounts Payable View and enter supplier bills, and view supplier credit notes. Everything in Allowed, plus un-commit a committed bill, approve staff leave requests, and create, edit, allocate and delete supplier credit notes. (Committing or un-committing a credit note also requires General Ledger access — see the note below.)
Accounts Receivable View and raise customer invoices, and view customer credit notes. Everything in Allowed, plus un-commit a committed invoice, flag a project for invoice review, see the admin-only sections on the customer record, and create, edit, allocate and delete customer credit notes. (Committing or un-committing a credit note also requires General Ledger access — see the note below.)
General Ledger View the general ledger and chart of accounts. Also required to commit or un-commit a credit note, because committing posts the credit to the general ledger. Everything in Allowed, plus access ticket and project billing screens.
Job Costing View and work with projects and project costs. Everything in Allowed, plus approve / un-approve timesheets against projects, delete notes, update project work status, and view the project WIP, billable-items and closed-variation reports.
Inventory View stock items; cost figures are shown but are read-only. Everything in Allowed, plus edit the true cost field, approve items flagged for review, and delete inventory categories and specifications.
Payroll View staff and submit leave requests. Everything in Allowed, plus payroll administration. (Leave approval itself is controlled by Accounts Payable.)
Reports Open the reporting screens and run standard reports. Everything in Allowed. Note that the most sensitive report areas are gated by their own module instead — Financials by General Ledger, and Sales by Sales or Business Registers.
Business Registers View the company business registers. Everything in Allowed, plus manage register entries, view the Qualifications reports, and view the Sales reports (staff performance / invoicing). Sales admin also grants the Sales reports, so a sales manager no longer needs this module for them.
Timesheets Enter and edit your own timesheets only. View and approve all staff timesheets, and invoice work directly from timesheets.
info A user set to Denied for a module does not see it in the menu at all, so none of the above is available.
receipt_long Credit notes span more than one module. Customer (AR) credit notes are controlled by Accounts Receivable and supplier (AP) credit notes by Accounts Payable:
  • Allowed — view the credit note register and open existing credit notes (read only).
  • Admin — create, edit, allocate and delete credit notes.
  • Committing or un-committing a credit note posts to the general ledger, so it also requires General Ledger access (at least Allowed) in addition to the Admin level on the relevant AR/AP module.
If a user is missing one of these, the credit note screen now tells them exactly which access is required.

Super User

The Super User setting is separate from the module access levels. When set to Yes, the staff member is treated as an administrator across the system and is granted access to administrative areas — including the Permissions tab itself, where they can set access for other staff.

priority_high Grant Super User access sparingly. It overrides normal module restrictions and should be reserved for trusted administrators.
  • Start from Denied and grant only the modules a staff member needs for their role.
  • Use Allowed for day-to-day users and reserve Admin for those who manage or approve within a module.
  • Keep Super User limited to a small number of trusted administrators.
  • Remind users that permission changes only apply after they next log in.

Support

For help mapping roles to permission levels in your organisation, please contact Evolution ERP Support.