Access control that fits your team
IEMSuite controls who can do what with roles built from granular permissions. Each permission is an `Entity:Action` pair - like `Order:read`, `Product:create`, or `Inventory:manage` - so you can shape access precisely around real jobs.
How permissions are structured
Permissions cover every area of the product - orders, inventory, products, production, quality, costs, users, and more - each with its own actions (read, create, manage, and so on). A role is simply a bundle of the permissions that job needs.
Managing roles
- Open Settings → Roles & Permissions.
- Create a role with a name (e.g. "Quality Manager") and a short description.
- Select the permissions it should include.
Then assign the role to people under Settings → Team Members. See Inviting your team & assigning roles.
Designing good roles
- Operators - receive stock, run batches, log QC; no access to costs or billing.
- Managers - the above plus orders, analytics, and cost visibility.
- Admins - full access, including users, roles, and billing.
Give each role the least access its job needs, then widen it only when required.
FAQ
Can I create custom roles?
Yes - build as many as you need with a tailored permission set and a clear name.
What controls whether someone sees costs or billing?
The permissions in their role. Leave finance/billing permissions out of operator roles to keep those figures private.