Roles & Permission
The Roles & Permission module allows administrators to define Business Roles and assign permissions for every module, screen, and action within GEMS ERP. Rather than assigning permissions directly to individual users, permissions are grouped into Roles, making access management easier, more secure, and consistent across the organisation.
When a Business Role is assigned to a User, the user immediately inherits all permissions configured for that role.
Purpose
The Roles & Permission module enables your organisation to:
- Create Business Roles.
- Configure permissions across all ERP modules.
- Define Create, View, Update, Delete, and other action permissions.
- Standardise user access.
- Simplify onboarding.
- Update permissions centrally.
- Maintain permission audit history.
Navigation
Access Control → Roles & Permission
Key Features
The Roles & Permission module provides:
- Business Role creation
- Permission assignment by module
- Work Center permission management
- Screen-level access control
- Action-level permissions
- Select All permission option
- Role editing
- Change history
- Immediate permission updates for assigned users
Screen Overview
The Roles & Permission screen enables administrators to define Business Roles and configure permissions for each Work Center and application screen.
| Section | Description |
|---|---|
| Role Information | Captures the Business Role name and description. |
| Work Center & Permissions | Displays all ERP modules and available permissions for each screen. |
| Permission Matrix | Defines actions such as View, Create, Update, Delete, and other supported operations. |
| Audit Information | Displays creation details and permission change history. |
Data Model
Each Business Role contains a role definition together with permission assignments.
Business Role
The Business Role stores the overall access profile assigned to users.
Information Stored
| Category | Information |
|---|---|
| Role Information | Role ID, Role Name, Description |
| Permission Information | Work Centers, Modules, Screen Permissions, Allowed Actions |
| Audit Information | Created By, Created Date, Updated By, Updated Date |
Entity Relationship
Business Role
│
├── Work Centers
├── Module Permissions
├── Screen Permissions
└── Users
Users inherit all configured permissions from their assigned Business Role. Any changes to a Role immediately apply to all users assigned to that role.
How It Works
The Role management process generally follows these steps:
- Navigate to Access Control → Roles & Permission.
- Create a new Business Role.
- Enter the Role name and description.
- Configure permissions for each Work Center.
- Select the required actions for each screen.
- Save the Business Role.
- Assign the Role to Users.
- Edit permissions whenever business requirements change.
- Changes are applied immediately to all users assigned to the Role.
- Review Change History whenever required.
Business Benefits
Using the Roles & Permission module helps organisations to:
- Standardise user access across departments.
- Strengthen system security.
- Reduce administration effort.
- Simplify user onboarding.
- Ensure consistent permission management.
- Maintain comprehensive permission audit records.
Best Practices
- Create Business Roles based on job responsibilities.
- Follow the principle of least privilege.
- Review role permissions regularly.
- Modify existing Roles instead of creating duplicates where appropriate.
- Test new permission configurations before assigning them to production users.
- Periodically review Change History for compliance and auditing.
Next Steps
The Roles & Permission module includes the following functional areas:
- Role List
- Create Role
- Edit Role
- Configure Permissions
- Assign Users to Role
- Change History
- View Role