ERP roles and permissions checklist
People need enough access to do their work and clear limits around sensitive actions. A role design should follow the transaction: who enters a customer, approves a price, receives stock, validates an invoice or approves a data export. Datrylo has separate business application roles and Manager account/operator controls; they should not be confused.
Separate entry, approval, validation and export
Proposed responsibility matrix, not a certification of installed access rules. Record company/location, inherited groups and export tests for each role.
| Record / decision | Filled example and next owner |
|---|---|
| Sales clerk | Create quotes: yes; approve discounts: no; validate delivery: no; report: own team; export: separately granted. |
| Warehouse supervisor | Create/validate stock moves: agreed location; approve sales prices: no; report: location; export: explicitly reviewed. |
| Finance reviewer | Approve invoice/payment decisions; no stock validation unless separately assigned. Test allowed and denied actions with ordinary accounts. |
Use this worksheet to organise your requirements, assign owners and plan the next steps.
Map the responsibilities
List every team and the records it must read, create, change, approve, export or delete. Include temporary staff, support access and the last administrator. Identify actions needing two-person review or recent authentication. Do not assume a user needs global administration merely to resolve an operational issue.
Test with real accounts
Use non-administrator accounts to check everyday tasks and restricted actions. Include company boundaries, exports, attachments and connected systems. Record the agreed permissions in a role matrix that your team can maintain as responsibilities change.
Review after change
Record who owns role changes and how access is removed when someone leaves. Retest permissions after installing modules, upgrading the release or changing company structure. Include roles in your implementation review.