X-ERP Help

04. Adjust rights

Roles and individual page rights give each person exactly the scope of action that their task requires - nothing more and nothing less.

Good rights are hardly noticeable in everyday life: the right path is visible, risky junctions remain closed.

Responsibility that carries with you in everyday life

X-ERP separates roles, page rights and API permissions. Reading, creating, modifying and deleting are your own decisions; Sensitive areas and interfaces require particularly tight approvals.

This creates a clean working environment

  1. Open on desktop Administration the area Rolls.
  2. Select the role whose access rights you want to edit or create a new role.
  3. Only activate the entries that are required for the actual tasks of the role.
  4. Check the registry Permissions Read, create, change and delete separately for each area.
  5. Only grant API rights to explicitly approved integrations.
  6. Go to the register System menus and determine which desktop menus are available for this role.
  7. Log in as a test user and play through normal and forbidden actions.
  8. For the new configuration to fully take effect, the user must log out and log in again.

The short handover check

  • The user achieves his complete work route.
  • Lists, fields and actions that have not been released remain inaccessible.
  • Deletion and administration rights are particularly limited.
  • The role decision is technically approved and documented.

What good administrators immediately think about

  • “Reading” is often confused with “editing”; check each operation.
  • Too many individual exceptions make roles incomprehensible.
  • Tests with your own administrator account do not prove a user perspective.

This is what you take with you

The rights reflect the real area of responsibility – understandable, verifiable and maintainable.

Video

Adjust rights

Further information / source

Related topics

  1. For company database managers – set up and maintain company databases › 03. Create users and link them to employee records
  2. For company database managers – setting up and maintaining company databases › 06. Basic settings, testing and handover

Frequently asked questions

**What does CRUD mean?**

Create, Read, Update and Delete – i.e. creating, reading, changing and deleting – can be permitted separately.

**Why don't I see a function despite the role?**

Additional page, action, or record permissions may apply. Test the specific task with the affected user.