Roles and Permissions

Updated August 3, 2026 4 min read

Roles & Permissions is where you control exactly what each user can see and do across GEMS CRM. Every Business Role bundles together a set of permissions — View, Create, Update, Delete — mapped against the CRM’s Work Centers, and once assigned to a user, that configuration drives what they’re authorized to do at runtime.

Roles & Permissions List View

A searchable overview of every business role configured in the system.

What You’ll See

  • Header Badges – Total, Active, and Inactive counts
  • View Dropdown – switch between saved role views (e.g., “All Roles”)
  • Search Bar – find a role by name or ID
  • Roles Grid – every role with its description and status

Grid Columns

ColumnDescription
Role IDUnique, system-generated reference
Role NameThe role’s business-friendly name
DescriptionA brief explanation of the role’s scope
StatusActive or Inactive
Created AtWhen the role was created

Each row includes View, Edit, and Delete actions.

Toolbar Actions

  • + New – opens the role creation form
  • Refresh, Column Settings, Filter, Sort, Reset
  • Actions – Mass Delete, which only applies to roles with no active users assigned

Good to Know

  • Deleting a role is blocked if it’s currently assigned to any active user — you’ll need to reassign those users first

Creating a New Business Role

General Information

  • Role ID – system-generated and always read-only
  • Business Role Name – mandatory, up to 80 characters, and must be unique across every role in the system
  • Description – optional, free text

Work Center & Permissions

This is where you define exactly what the role can access.

  • Search Modules – filter the Work Center tree as you type
  • Expand All / Collapse All – open or close every node in the hierarchical tree at once
  • The tree itself mirrors your CRM’s structure (User Cockpit, Sales Cockpit, Business Partners → Customers/Contacts, and so on)
  • For each Work Center, you can grant View, Create, Update, and Delete individually, or use Select All to grant everything at once
The View Dependency Rule

This is the one rule to keep in mind while configuring permissions:

  • View is the parent permission for every Work Center
  • Selecting Update or Delete automatically selects and locks View for that same Work Center — you can’t grant edit or delete access without also granting read access
  • Once locked this way, View can’t be manually unchecked while Update or Delete remains selected
  • If you later deselect both Update and Delete, View stays selected but becomes unlocked again, so you’re free to remove it if you want to

Business Rules Worth Knowing

  • Every new role starts as Inactive. It isn’t usable or assignable to anyone until you explicitly activate it from the List View’s Actions menu — this gives you a chance to fully configure permissions before the role goes live
  • Only Active roles are eligible for assignment to users, and only an Active role’s permissions have any effect at runtime — an Inactive role’s configuration simply doesn’t count, no matter how it’s set up

Saving

  • Save – validates the role name and permission dependencies, then creates the role in Inactive status
  • Save and New – saves the current role and opens a blank form for the next one
  • Cancel – discards everything and returns you to the list, with nothing created

Role Detailed View

Opens in read-only mode by default, across three tabs: General Information, Work Center & Permissions, and Change History.

General Information & Work Center & Permissions

In Edit mode, everything here works exactly like the Create page — the same name/description editing, the same permission tree, and the same View dependency rule. Role ID remains permanently locked, in every mode.

Change History

A complete, read-only audit trail of every change made to the role’s general information and its permission configuration — the field changed, its old and new value, who changed it, and when. Shown most recent first, and can never be edited or added to manually in either View or Edit mode.

Activating and Deactivating Roles

Status changes happen from the List View’s Actions menu, not from within the role itself:

  • Activate Selected – only has an effect on roles currently Inactive; makes them eligible for assignment
  • Deactivate Selected – only has an effect on roles currently Active; immediately removes runtime authorization for anyone assigned that role, even though the assignment itself stays on record

Leave a Reply

Your email address will not be published. Required fields are marked *

Scroll to Top