IEMSuite
Account, team & security5 min read

Roles & permissions explained

How IEMSuite’s Entity:Action permissions work, and how to build roles that fit your operators, managers, and admins.

Access control that fits your team

IEMSuite controls who can do what with roles built from granular permissions. Each permission is an `Entity:Action` pair - like `Order:read`, `Product:create`, or `Inventory:manage` - so you can shape access precisely around real jobs.

How permissions are structured

Permissions cover every area of the product - orders, inventory, products, production, quality, costs, users, and more - each with its own actions (read, create, manage, and so on). A role is simply a bundle of the permissions that job needs.

Managing roles

  1. Open Settings → Roles & Permissions.
  2. Create a role with a name (e.g. "Quality Manager") and a short description.
  3. Select the permissions it should include.

Then assign the role to people under Settings → Team Members. See Inviting your team & assigning roles.

Designing good roles

  • Operators - receive stock, run batches, log QC; no access to costs or billing.
  • Managers - the above plus orders, analytics, and cost visibility.
  • Admins - full access, including users, roles, and billing.

Give each role the least access its job needs, then widen it only when required.

FAQ

Can I create custom roles?

Yes - build as many as you need with a tailored permission set and a clear name.

What controls whether someone sees costs or billing?

The permissions in their role. Leave finance/billing permissions out of operator roles to keep those figures private.