Administration
Roles, permissions and location boundaries
Roles describe the work a person performs; location membership describes where they may perform it. Treat both as explicit business decisions and test them with non-administrator accounts.
01
Start with job responsibilities
List what administrators, service advisors, technicians, parts staff, finance users and managers need to view, create, approve and change. Avoid giving administrator access to solve a single missing permission.
02
Apply location scope
Assign each internal user to the locations they support. Consolidated managers may need network reporting while local staff should remain inside their operating location.
03
Separate sensitive authority
Restrict user administration, financial configuration, refunds, purchasing approval, inventory adjustment and consolidated reporting to accountable roles.
04
Test and review
Use representative accounts to verify menus, direct URLs, search results, exports and approval actions. Review access after role changes, location transfers and departures.
- Disable departed users promptly.
- Review administrators and cross-location users regularly.
- Document exceptions with an owner and expiry date.
Ready to move forward?
Need help with your configuration?
Existing customers should use in-product support for account-aware assistance. Evaluation teams can contact us to discuss requirements.