Skip to content
ITEMRA
Documentation menu

Roles & permissions

The four roles, the permission matrix, customizing role permissions, and how capability gating interacts.

The four roles

RoleIntended for
OwnerFull control, including billing and destructive settings
AdminRuns the organization day to day
OperatorDoes the floor work — receive, move, count, pick
ViewerSees without touching

Every member has exactly one role; site scope narrows where it applies.

The permission matrix

Settings → Roles shows the full matrix: every permission (grouped by area — items, stock, counting, purchasing, users, settings, and so on) against every role.

What each role may do, per permission.

With the custom-roles plan capability, the matrix is editable: tighten or extend a role's permissions to fit your operation — an operator role that can also manage labels, an admin without cost visibility (the view-cost/edit-cost permissions are separate for exactly this). Reset to default returns a role to the stock definition. Changes apply to everyone holding the role and are recorded in the audit log.

Permissions vs plan capabilities

Two independent gates decide what someone sees: permissions (role — may this person do it?) and plan capabilities (subscription — does the organization have the feature?). A locked feature stays locked for every role until the plan includes it; a permission missing from your role hides the action even on the best plan. When someone "can't see" something, check both.