Skip to content
Docs — Upflow Sprint
Sign in

Roles and permissions explained

The standard roles, access levels, and how Organization Owners and Admins adjust permissions.

Updated Org OwnerOrg AdminPublic
On this page

Overview

Every user has one or more roles. A role decides, for each section of the ERP, whether the user has Edit, View or No Access. Some roles apply to the whole organization; others apply only at the sites they are assigned to.

Guidelines

  1. Give the least access needed

    Start from the closest standard role and only add access that the person needs for their job.

  2. Highest level wins

    If someone has several roles, they get the highest access level of those roles for each section.

Steps

  1. Step 1: Understand the access levels

    Edit — full access. View — read-only, with a View-only access banner. No Access — the section is hidden from the sidebar and blocked if opened directly.

  2. Step 2: Choose an organization-level role

    Organization Owner (highest; always full access), Organization Admin (full administration), Chain Operations (cross-site operations), Analytics Viewer (read-only analytics and reports), Finance Manager (payments, payables and bank — no inventory or catalog changes).

  3. Step 3: Choose a site-level role

    Store Manager, Warehouse Manager, Warehouse Operator (pick, pack, putaway, scan), POS Operator, Cashier, Auditor (audits and variances) and Security Officer (EAS alerts and evidence). Site roles apply only at the sites assigned to the user.

  4. Step 4: Adjust permissions for your organization

    Go to Settings → Roles & Permissions. In the Matrix tab change a role's level for a section, then click Save changes, review the staged changes and Confirm save. Reset to default undoes an override; History shows past changes.

  5. Step 5: Create a custom role

    Click New role, choose Org-wide or Site-scoped, optionally Copy permissions from an existing role, then Create role and fine-tune it in the matrix.

Terms

Org-level role

Applies across the whole organization.

Site-level role

Applies only at the sites the user is assigned to.

Override

A change your organization made to a role's default access.

Key points

  • Only Organization Owners and Admins can change permissions by default.

  • The Organization Owner role is locked to full access.

Notes

A typical chain has one Organization Owner, one or two Organization Admins, a Store Manager per store, a Warehouse Manager per warehouse, cashiers per store and an Auditor per site.

Warnings

Organization Owner and Organization Admin can never be reduced below Edit on Users, Settings or Roles & Permissions, so an organization can't lock itself out.

FAQs

A user sees View-only on a page. How do I give them Edit?

Give them a role with Edit on that section, or change their role's level for that section in Settings → Roles & Permissions.

Can a site-level user see other stores?

No. Site-level roles only apply at the sites assigned to the user.

Was this guide helpful?