Role-Based Access

Role-based access grants actions according to a person's job and the records they are authorised to use. It should be tested with ordinary users and across company boundaries.

A worked example

A practical example to make the concept clear.

StepIllustrative record and result
Starting recordExample sales role: read customers and create quotations for Company A.
Change or calculationFinance approves refunds; warehouse validates deliveries. A salesperson should be denied these approval actions if the agreed role excludes them.
Meaning and exceptionTest with the ordinary sales account: allowed quotation succeeds; prohibited refund approval and Company B records are denied. A role name alone does not prove isolation.

Why it matters

Map read, write, approve and export actions to each role. This gives people the tools they need while protecting sensitive decisions and records.

Make it practical

Can an ordinary user complete their task while being denied another company’s records? Test the answer with the exact release and application package under consideration. Explore Datrylo applications.

Choose which optional services you allow. You can change or withdraw your choices at any time.