VMOTEK
Product education

Administration

Roles, permissions and location boundaries

Roles describe the work a person performs; location membership describes where they may perform it. Treat both as explicit business decisions and test them with non-administrator accounts.

01

Start with job responsibilities

List what administrators, service advisors, technicians, parts staff, finance users and managers need to view, create, approve and change. Avoid giving administrator access to solve a single missing permission.

02

Apply location scope

Assign each internal user to the locations they support. Consolidated managers may need network reporting while local staff should remain inside their operating location.

03

Separate sensitive authority

Restrict user administration, financial configuration, refunds, purchasing approval, inventory adjustment and consolidated reporting to accountable roles.

04

Test and review

Use representative accounts to verify menus, direct URLs, search results, exports and approval actions. Review access after role changes, location transfers and departures.

  • Disable departed users promptly.
  • Review administrators and cross-location users regularly.
  • Document exceptions with an owner and expiry date.

Ready to move forward?

Need help with your configuration?

Existing customers should use in-product support for account-aware assistance. Evaluation teams can contact us to discuss requirements.