Articles in this section

Assign permissions to a custom role

Published:
Updated:

This article explains how to set the permissions on a custom role in MobilityManager. Assigning permissions is what turns an empty custom role into a working access profile.

Before you start

Setting a role's permissions requires the roles:manage permission, held by the SystemAdmin role. You can only edit the permissions of custom roles; the built-in SystemAdmin, FleetManager, and Driver roles have fixed permission sets that cannot be changed.

How permission setting works

When you save permissions for a custom role, the platform replaces the role's entire permission set with the list you submit. This is not additive: any permission you leave out is removed, and any you include is added. Always submit the complete list of permissions the role should have, not just the ones you are changing.

Warning: Because saving replaces the whole set, submitting an empty list removes every permission from the role. Users who hold that role keep the role assignment but lose all access it granted.

Assign the permissions

  1. Open the roles area and select the custom role you want to configure.
  2. Review the permission catalog, grouped by category (for example Vehicles, Bookings, Belege, Users, Roles).
  3. Select every permission the role should grant. Include coarse and fine permissions as needed — for example both a "view" and a "manage" permission within a module.
  4. Save. The role's permission set is updated to exactly your selection.

Only valid, current permissions are accepted

The platform validates your selection against the live permission catalog:

  • Every key you submit must exist in the catalog. If any key is unknown, the whole save is rejected and the unknown keys are named.
  • Deprecated permissions are not available to assign; only current permissions can be added to a role.
  • Duplicate keys are ignored, so listing the same permission twice has no effect.

Choosing the right permissions

GoalInclude permissions such as
Read-only auditorThe "view" permissions across the modules you want visible.
Tenant user administratorusers:manage plus roles:assign and roles:remove.
Expense clerkThe Belege view, transition, and mark-paid permissions.
Note: Even a custom role that grants roles:assign cannot grant the SystemAdmin role — that remains reserved for existing SystemAdmins. Likewise the most sensitive financial permissions, such as correcting expense financials and managing fleet-cost budgets, exist in the catalog but should be granted only with care.
Tip: After changing a role's permissions, ask a user who holds that role to sign out and back in, or re-check their access, so their session reflects the new permission set.

Related

  • Create a custom role
  • The permission catalog and categories
  • Troubleshooting "Access Denied" errors
  • Assign and remove user roles
AH
Written by Alexander Hagemann
Updated:
Access denied
Access denied