Skip to main content

Modules and access

Seeing a module and being able to change its data are separate decisions in SpaceRivers. Access is built from three layers:

  1. Subscription entitlements determine which product categories the tenant owns.
  2. Role permissions determine which modules and actions a user can perform.
  3. Job permissions can narrow the jobs, employees, and cost codes visible to that user.

Standard actions

Most modules use view, create, edit, and delete privileges. Reports and workflow screens can use specialized privileges. The application hides inaccessible navigation and protected pages also verify access when opened directly.

Default role patterns

New tenants can be initialized with role patterns such as Administrator, HR, Manager, Supervisor, Staff, and Worker. These names are starting points, not a guarantee of identical access: administrators can change role definitions for their organization.

Administrators

When changing access:

  • grant permissions to roles instead of managing every user independently;
  • give users the least access needed for their responsibilities;
  • confirm both module permission and job/data scope;
  • use a separate role for integration or billing administration when practical;
  • test the result with a non-administrator account; and
  • review access after an employee changes team or leaves the organization.

See Roles and Permissions for the management workflow.

Why a user cannot see a record

Check, in order:

  1. the tenant selected at sign-in;
  2. the subscription's enabled modules;
  3. the user's active status and assigned role;
  4. the role's module/action permission;
  5. employee-to-user linkage; and
  6. job, employee, and cost-code assignments.