Roles and Permissions
Roles & Permissions is where you control exactly what each user can see and do across GEMS CRM. Every Business Role bundles together a set of permissions — View, Create, Update, Delete — mapped against the CRM’s Work Centers, and once assigned to a user, that configuration drives what they’re authorized to do at runtime.
Roles & Permissions List View
A searchable overview of every business role configured in the system.
What You’ll See
- Header Badges – Total, Active, and Inactive counts
- View Dropdown – switch between saved role views (e.g., “All Roles”)
- Search Bar – find a role by name or ID
- Roles Grid – every role with its description and status
Grid Columns
| Column | Description |
|---|---|
| Role ID | Unique, system-generated reference |
| Role Name | The role’s business-friendly name |
| Description | A brief explanation of the role’s scope |
| Status | Active or Inactive |
| Created At | When the role was created |
Each row includes View, Edit, and Delete actions.
Toolbar Actions
- + New – opens the role creation form
- Refresh, Column Settings, Filter, Sort, Reset
- Actions – Mass Delete, which only applies to roles with no active users assigned
Good to Know
- Deleting a role is blocked if it’s currently assigned to any active user — you’ll need to reassign those users first
Creating a New Business Role
General Information
- Role ID – system-generated and always read-only
- Business Role Name – mandatory, up to 80 characters, and must be unique across every role in the system
- Description – optional, free text
Work Center & Permissions
This is where you define exactly what the role can access.
- Search Modules – filter the Work Center tree as you type
- Expand All / Collapse All – open or close every node in the hierarchical tree at once
- The tree itself mirrors your CRM’s structure (User Cockpit, Sales Cockpit, Business Partners → Customers/Contacts, and so on)
- For each Work Center, you can grant View, Create, Update, and Delete individually, or use Select All to grant everything at once
The View Dependency Rule
This is the one rule to keep in mind while configuring permissions:
- View is the parent permission for every Work Center
- Selecting Update or Delete automatically selects and locks View for that same Work Center — you can’t grant edit or delete access without also granting read access
- Once locked this way, View can’t be manually unchecked while Update or Delete remains selected
- If you later deselect both Update and Delete, View stays selected but becomes unlocked again, so you’re free to remove it if you want to
Business Rules Worth Knowing
- Every new role starts as Inactive. It isn’t usable or assignable to anyone until you explicitly activate it from the List View’s Actions menu — this gives you a chance to fully configure permissions before the role goes live
- Only Active roles are eligible for assignment to users, and only an Active role’s permissions have any effect at runtime — an Inactive role’s configuration simply doesn’t count, no matter how it’s set up
Saving
- Save – validates the role name and permission dependencies, then creates the role in Inactive status
- Save and New – saves the current role and opens a blank form for the next one
- Cancel – discards everything and returns you to the list, with nothing created
Role Detailed View
Opens in read-only mode by default, across three tabs: General Information, Work Center & Permissions, and Change History.
General Information & Work Center & Permissions
In Edit mode, everything here works exactly like the Create page — the same name/description editing, the same permission tree, and the same View dependency rule. Role ID remains permanently locked, in every mode.
Change History
A complete, read-only audit trail of every change made to the role’s general information and its permission configuration — the field changed, its old and new value, who changed it, and when. Shown most recent first, and can never be edited or added to manually in either View or Edit mode.
Activating and Deactivating Roles
Status changes happen from the List View’s Actions menu, not from within the role itself:
- Activate Selected – only has an effect on roles currently Inactive; makes them eligible for assignment
- Deactivate Selected – only has an effect on roles currently Active; immediately removes runtime authorization for anyone assigned that role, even though the assignment itself stays on record