X-ERP Help
04. Adjust rights
Roles and individual page rights give each person exactly the scope of action that their task requires - nothing more and nothing less.
Good rights are hardly noticeable in everyday life: the right path is visible, risky junctions remain closed.
Responsibility that carries with you in everyday life
X-ERP separates roles, page rights and API permissions. Reading, creating, modifying and deleting are your own decisions; Sensitive areas and interfaces require particularly tight approvals.
This creates a clean working environment
- Open on desktop Administration the area Rolls.
- Select the role whose access rights you want to edit or create a new role.
- Only activate the entries that are required for the actual tasks of the role.
- Check the registry Permissions Read, create, change and delete separately for each area.
- Only grant API rights to explicitly approved integrations.
- Go to the register System menus and determine which desktop menus are available for this role.
- Log in as a test user and play through normal and forbidden actions.
- For the new configuration to fully take effect, the user must log out and log in again.
The short handover check
- The user achieves his complete work route.
- Lists, fields and actions that have not been released remain inaccessible.
- Deletion and administration rights are particularly limited.
- The role decision is technically approved and documented.
What good administrators immediately think about
- “Reading” is often confused with “editing”; check each operation.
- Too many individual exceptions make roles incomprehensible.
- Tests with your own administrator account do not prove a user perspective.
This is what you take with you
The rights reflect the real area of responsibility – understandable, verifiable and maintainable.
Video
Related topics
- For company database managers – set up and maintain company databases › 03. Create users and link them to employee records
- For company database managers – setting up and maintaining company databases › 06. Basic settings, testing and handover
Frequently asked questions
**What does CRUD mean?**
Create, Read, Update and Delete – i.e. creating, reading, changing and deleting – can be permitted separately.
**Why don't I see a function despite the role?**
Additional page, action, or record permissions may apply. Test the specific task with the affected user.
