Administration · People and access

Roles and permissions explained

How a role decides what each person sees and may do in SeroBooks, the View and Allow columns, the ready-made roles, approvals, and every permission in the tree.

☰ Company ▸ Set Up Users and Roles… ▸ Manage roles & permissions☰ Menu ▸ Admin ▸ Users & Roles ▸ Manage roles & permissions
serobooks / company / set up users and roles… / manage roles & permissionsLive
Watch it in the appUsers, roles and permissions Staff accounts, roles, View and Allow on every screen and action, and approvals at the till.

A role is a named set of permissions. Every user has one role, and the role decides three things for every screen and every important button in SeroBooks:

  • whether the person can see it at all;
  • whether they can use it straight away;
  • or whether it is visible but locked, so that someone with the right to approve it must type their password first.

This article explains how roles work, walks through the Roles screen and the role editor, lists the ready-made roles, and documents every permission in the SeroBooks tree.

Opening the Roles screen

  1. Open Company ▸ Set Up Users and Roles… (or Menu ▸ Admin ▸ Users & Roles).
  2. Click Manage roles & permissions.

The Roles screen lists every role in your company.

ItemMeaning
Shield iconThe default Admin role. It has a padlock instead of buttons: it cannot be edited or deleted.
Role nameThe role's name.
Second lineHow many permissions the role holds, how many users have it, and Default role for the Admin role.
Edit (pencil)Opens the role editor.
Delete (bin)Deletes the role after you confirm. The bin is grey when users still have the role.
Add Role (bottom right)Opens the role editor for a new role.
RefreshReloads the list.

Three outcomes: hidden, locked, allowed

Every row in the SeroBooks permission tree has two tick boxes.

ViewAllowWhat the person experiences
OffOffHidden. The screen or button is not there. Use it for whole areas a role has no part in.
OnOffLocked. The screen or button is there with a padlock. Using it opens an Approval Required box; someone who holds the permission types their login and password to approve that one action.
OnOnAllowed. The person uses it normally.

Hover over the column headings for a reminder: VIEW — Shows the tab or button at all; ALLOW — Use it without asking anyone.

How ticking works

The editor keeps the tree consistent for you:

  • Allow includes View. Ticking Allow also ticks View on that row and on every row above it.
  • View works up the tree. Ticking View on a screen also ticks View on its module, because a screen inside a hidden module can never be reached.
  • Clearing View clears everything underneath. Unticking View on a module clears View and Allow on every screen and action inside it, so nothing stays granted out of sight.
  • Clearing Allow does not cascade. You can leave a module locked and still allow a screen inside it. The person approves once on the way in and then works without being asked again.

The row menu

Every module and screen row has a ⋮ menu (Apply to everything in …) with four choices:

ChoiceEffect on the row and everything under it
Full accessView and Allow on everything.
Read-only (hide actions)View on the module and its screens; every action button underneath is removed entirely. The person can look around but cannot change anything, and is never shown approval prompts.
Visible, every action needs approvalView on everything, Allow on nothing. Useful while someone is being trained.
No accessClears everything.

Adding or editing a role

  1. On the Roles screen click Add Role, or the pencil on an existing role.
  2. Type the Role name (for example Bookkeeper). Do not use # — it is removed.
  3. Optionally click Start from a role (top right) and pick a ready-made role. This replaces everything on the SeroBooks Access tab with that role's permissions; the other tabs are not changed.
  4. Adjust the tabs described below.
  5. Click Create Role (or Save Changes).

A green message confirms Role added successfully or Role updated successfully. Users on the role get the new permissions the next time they sign in.

The tabs of the role editor

TabWhat it controls
SeroBooks AccessThe View/Allow tree for every SeroBooks module, screen and sensitive action, plus Maya and Chat. The number in brackets is how many boxes are ticked.
WorkspaceSingle tick boxes for the left menu and the Admin screen: settings, printers, sync, the Admin tiles and similar.
Web AccessThe permissions used by the web Back Office, grouped by area (Users, Products, Sales, Purchases, Business Locations and so on). All and None at the top tick or clear the whole tab.

If your company has both SeroBooks and SeroPOS, an App access box also appears under the role name: Both apps (default), SeroPOS only — the till or SeroBooks only — the books. People with the role sign in to that app, and count towards that product's user allowance.

The SeroBooks Access tab

  • Search (Search tabs and actions — "refund", "reconcile"…) filters the tree. A match shows its module and everything inside it.
  • Click the arrow or the name of a module or screen to open or close it.
  • The count beside each module or screen (for example 12/34) shows how many rows inside it are granted.
  • The line above the columns reads X of Y granted for the whole tree.

When nothing on this tab is ticked, a blue note reads: Nothing ticked — this role is UNRESTRICTED in SeroBooks and sees every screen, exactly as it did before permissions existed. Tick anything at all and the role is governed from then on: only what is ticked will be visible.

Saving an empty role

A role must grant something. If no box is ticked on any tab, Create Role shows Tick at least one permission. A role with none grants no access at all. A role that grants nothing shows its users nothing.

Who is never restricted

WhoRule
Admin (the owner's role)Never restricted. The Admin role's own tick boxes are not consulted.
Manager (a role named Manager)Lives by the permissions ticked on the Manager role for their own work, but may approve anyone else's locked action, including actions their own role does not hold.
Everyone elseExactly what their role grants.

Roles with no SeroBooks policy

A role that holds Web Access or Workspace permissions but nothing on SeroBooks Access is ungoverned: it sees every SeroBooks screen, as roles did before SeroBooks permissions existed. Two exceptions apply even then:

  • The following areas are locked (visible, but need approval) for an ungoverned role: Accounting ▸ Banking, Accounting ▸ Year-End, Accounting ▸ Sales Tax, Accounting ▸ Setup (the posting map), Accounting ▸ General Journal Entries, Accounting ▸ Move from QuickBooks, and every Payroll screen (Pay Runs, Employees, Setup, Benefits & Deductions, Remittances, Records of Employment, Employer Levies, Year-End Slips). To let such a role use them without approval, give the role a SeroBooks policy and tick Allow on them.
  • Opening Purchases, Payments, Inventory, Transfers or Reports can ask for Manager Approval if the role lacks the older module permission for it. Giving the role a SeroBooks policy replaces these checks with the tree.

Approval dialogs

Two kinds of approval box appear in SeroBooks.

Approval Required

Shown when someone uses a locked SeroBooks screen or button. The box names the action being approved (for example Invoices › Refund / Credit Note) and reads This is locked for your role. Anyone who has access to it can approve this one action.

  1. The approver types their Login ID and Password.
  2. They click Approve.
MessageMeaning
Enter a login ID and password.One of the boxes is empty.
Invalid credentials.The login or password is wrong.
… does not have permission for this. Ask someone who does.The password was right, but that person's role does not hold this permission either. The Admin and any Manager can always approve.

An approval covers one action only. The next refund asks again. Nothing is remembered for the rest of the day.

Manager Approval

Shown for the Workspace and Admin permissions (for example opening App Settings or an Admin tile). It reads '…' is locked for your role. An Admin or Manager can approve this action. Only an Admin or Manager login is accepted; anyone else gets Please Enter Admin or Manager User id and password. This approval also covers one action only.

Admin Access

Opening Menu ▸ Admin asks for an Admin or Manager login (Admin Access — Manage products, categories, staff and settings) unless you are an Admin or Manager yourself, or your role holds at least one Admin tile permission. Once passed, it is not asked again until you sign out.

Where you see permissions in the app

  • A screen your role cannot view is simply not in the menus, the ribbon or Go To / Look Up.
  • A locked screen shows a small padlock beside its name. Clicking it asks for approval.
  • A screen your company's plan does not include shows a different mark (a small award-badge icon). That is not a permission: nobody in the company can open it until the plan changes. See Your subscription and plan.
  • If a document links you to a screen you cannot view, the window reads Your role does not have access to this screen. An administrator can grant it under Admin › Roles.

The ready-made roles

Start from a role offers six starting points. Each one only sets the SeroBooks Access tab; you can change anything afterwards.

RoleDescription shownWhat it grants
AccountantThe whole ledger, plus read access to the documents behind it.Full Accounting (every screen and action), Reports and Dashboard. The Sales, Purchases, Payments, Contacts and Inventory screens open, but none of their gated action buttons (edits, refunds, deletes and so on) are there. Maya in full except her Settings.
BookkeeperDay-to-day documents and payments. Can read the ledger, cannot post to it, close a period or change the posting map.Full Sales, Purchases, Payments, Contacts, Inventory, Reports and Dashboard. The Accounting screens open without their action buttons, and Year-End, Setup and Sales Tax are not visible. Full Banking except Remove Bank Account, Disconnect Bank Feed and Undo a Reconciliation. Full Deposits, Write Cheques and Credit Card Charges. Maya chat and approvals, with Approve: Journal Entry and Approve: Payment Run visible but needing approval.
AR ClerkMoney coming in: invoices, customer payments and customers.Every Sales screen, with Refund / Credit Note, Cancel Invoice and Override Price locked. Estimates, Sales Orders and Held in full. Customer Balances (with Send Statement), Receive Payments, Cheques and All Payments (without Delete Payment). The Contacts screens, with full customer editing. Dashboard.
AP ClerkMoney going out: supplier bills, payments and suppliers.Full Purchases. Vendor Balances, Pay Bills, Cheques and All Payments (without Delete Payment). The Contacts screens, with full vendor editing. Dashboard.
Sales ClerkRaises invoices and quotes. No cost, no margin, no refunds without approval.The Sales screens except Credit Memos, with Edit Saved Invoice, Refund / Credit Note and Override Price locked and Cancel Invoice hidden. Estimates and Held in full. Customer Centre and Price Levels, with full customer editing. Products and the other Inventory screens except Adjustments and Warehouse, without View Cost & Margin. Dashboard.
Auditor (read-only)Sees every screen. Cannot change a single thing — the mutation buttons are not there to press.Every module and screen (except Maya's Settings), with every action button removed.

Every permission in the SeroBooks tree

The tree follows the SeroBooks modules. Every module row and every screen row has View and Allow. Actions (indented under their screen) are the sensitive buttons. Screens are listed with the names SeroBooks shows; a few screens share another screen's permission and have no row of their own (Edit Invoice uses New Invoice, Edit Bill uses Enter Bills, the Home Page uses Overview, and Create Estimates uses Estimates).

Dashboard

Overview, Getting Set Up, My accountant (called Clients for an accounting practice), Sales Analytics, Inventory Health, Cash Flow. No separate actions.

Sales

ScreenActions
InvoicesEdit Saved Invoice — reopen a completed invoice and change it. Refund / Credit Note — return items, refund money or raise a credit note. Cancel Invoice — void a whole invoice and reverse it. Take Payment — settle an invoice from the invoice itself. Email / WhatsApp — send the document to a customer.
New InvoiceOverride Price — change a line price away from the price list. Apply Discount — discount a line or the whole invoice. Change the Invoice Date — date an invoice other than today.
EstimatesConvert to Invoice. Delete Quotation.
Sales OrdersFulfil / Invoice Order. Delete Sales Order.
New Sales Order—
Credit MemosCreate Credit Memo — credit a customer with no invoice behind it. Delete Credit Note — remove a credit note raised by mistake and put back everything it moved.
HeldResume Held Sale. Delete Held Sale. (Parked sales from the point-of-sale screens.)

Purchases

ScreenActions
BillsEdit Supplier Bill. Delete Supplier Bill — remove a bill entered by mistake and book its stock back out. Return to Supplier — send goods back and raise a debit note. Change the Bill Date.
Enter Bills—
Purchase OrdersApprove Purchase Order — release a PO to the supplier. Delete Purchase Order.
New PO—
Receive ItemsDelete Goods Receipt — undo a delivery booked in by mistake; the bill goes with it. Receive Goods — book stock in against a PO. Raise Debit Note — charge a shortfall or rejection back to the supplier.
Vendor CreditsDelete Debit Note.
ExpensesRecord Expense. Edit Expense. Record Supplier Refund. Delete Expense — remove an expense and its journal entry.
New Expense—

Inventory

ScreenActions
ProductsEdit Product — price, tax, category or details. View Cost & Margin — see purchase cost, margin and stock value. Merge Products — combine two records for the same item, adding their stock.
ServicesAdd or Edit Service.
Stock Levels—
WarehouseSet Up Bins. Put Away & Pick. Count Bins.
AdjustmentsPost Stock Adjustment — write stock off; this hits the ledger.
Assemblies, Expiry, Serial Lookup—
Labels / BarcodesPrint Labels.

Transfers

ScreenActions
All TransfersReceive Transfer. Cancel Transfer — void a transfer that has not landed.
New TransferSend Transfer.

Payments

ScreenActions
Customer BalancesSend Statement — email a customer what they owe.
Vendor Balances—
All PaymentsEdit Payment — change a payment's amount, date, method, reference, or its Deposit To or Payment Account. Delete Payment — remove a payment and put the document back to what it owes.
Receive PaymentsRecord Customer Payment.
Pay BillsRecord Supplier Payment.
Cheques—

Contacts

ScreenActions
Customer CentreAdd Customer. Edit Customer — details, terms or credit limit. Merge Customers.
Vendor CentreAdd Supplier. Edit Supplier. Merge Suppliers.
Price LevelsAdd or Edit Group. Delete Group.

Reports

ScreenActions
Report CentreBuild a Custom Report — create, change or delete a report of your own. Export / Download — save any list or report to Excel, CSV or PDF. This one permission governs the export button everywhere in SeroBooks.
Sales, Purchases, Inventory, Damaged, Tax (GST/PST), Saved Reports—

Accounting

ScreenActions
Chart of AccountsAdd Account. Edit Account. Merge Accounts (irreversible). Activate / Deactivate Account.
BankingAdd Bank Account. Connect Bank Feed. Disconnect Bank Feed. Remove Bank Account. Import Statement (CSV). Reconcile. Categorize Bank Lines. Manage Bank Rules. Undo a Reconciliation.
Write ChequesWrite Check. Edit Check. Delete Check.
Credit Card ChargesEnter Credit Card Charge / Credit. Edit …. Delete ….
Trial Balance, Profit & Loss, Balance Sheet, Cash Flow, General Ledger—
General Journal EntriesPost Journal Entry. Edit Journal Entry. Reverse Journal Entry — post the mirror image, leaving the original untouched. Delete Journal Entry.
DepositsMake Deposit — move Undeposited Funds into the bank. Void Deposit.
StatementsSend Statement.
Payment RunsExecute Payment Run.
Memorized TransactionsCreate Recurring Entry. Edit Recurring Entry. Raise One Now. Delete Recurring Entry (documents already raised are kept).
Budget vs Actual—
Fixed AssetsAdd Fixed Asset. Record Depreciation / CCA.
Sales TaxFile a Return — post the liability and close the books through the period end. Record a Remittance. Reverse a Filing. Remove a Remittance. Accrue Use Tax. Configure Registrations & Nexus. Manage Exemption Certificates.
Opening BalancesPost Opening Balance.
Consolidated Day—
ProjectsAdd Project. Edit Project. Delete Project. Record Billable Time. Write Off / Re-charge.
Time & CostsRecord Billable Time. Write Off / Re-charge.
ClassesAdd Class. Edit Class. Delete Class.
RegisterReclassify Entries — move a batch of ledger entries to another account, class or job.
Foreign Currency, Contractor Slips—
T2 / GIFIAccept Suggested GIFI Codes. Change a GIFI Code.
Year-EndClose the Books — lock everything on or before a date. Reopen the Books. Create Accountant Link. Revoke Accountant Link.
Audit TrailMark Documents Audited.
Numbering—
SetupEdit Posting Map — decide which account every kind of transaction lands in. Re-post History — rewrite past transactions through the current map.
Move from QuickBooksCommit a Migration. Undo a Migration.

In a United States company, T2 / GIFI is called Income Tax and Write Cheques is Write Checks.

Payroll

ScreenActions
Pay RunsOpen a Pay Period. Calculate Pay. Approve a Pay Run — the pay then counts towards the year and cannot be recalculated. Post Pay to the Ledger.
EmployeesEdit Payroll Setup — salary, pay frequency, province of employment and tax certificate.
Timesheets, Vacation & Banked Time, PIER Review—
Benefits & DeductionsDefine a Benefit or Deduction.
Year-End SlipsBuild the Year-End Return.
RemittancesRecord a Remittance.
Records of EmploymentDraft, Issue or Amend an ROE.
Employer LeviesSet Levy Rates.
SetupEdit Payroll Setup and Clock Rules.

Forecast

Forecast, Reorder Levels, Ship to Amazon, What's Coming. No separate actions.

Amazon

Overview, Insights, Settlements, Orders, Taxes, Products (Map a Listing), Issues (Resolve an Issue), Returns, Inbound, Storage, Recovery, Buy Box, Traffic, Settings (Edit Marketplace Settings), and Fees (Map a Fee).

Maya

RowMeaning
ChatAsk Maya about the books. Its actions decide who may approve what Maya drafts: Approve: Categorize Bank Line, Approve: Journal Entry (this posts to the ledger), Approve: Send Statements, Approve: Payment Run, Approve: Purchase Order. With View but not Allow, the person can ask Maya to draft the item and it waits for someone who holds Allow.
BriefingsSee the morning brief.
SettingsMaya's controls.

Chat

RowMeaning
MessagesMessage colleagues, and be listed as someone they can message.
Group conversationsStart a group and add or remove its people. Without this, a person can still take part in a group someone else started.

The Workspace tab

One tick box per item; these control the left menu and the Admin screen.

PermissionWhat it unlocks
App SettingsCompany ▸ App Settings… and Menu ▸ Settings.
Sync DatabaseMenu ▸ Sync DataBase.
Subscription & BillingView or change the subscription plan.
Printer SetupFile ▸ Printer Setup…, Menu ▸ Add/Edit Printer and the Printer Setup tile on the Admin screen.
Multi Monitor, Recent Transactions, Daily Sales ReportPoint-of-sale menu items. They are not in SeroBooks' menu; they matter only if your company also uses SeroPOS tills.
Products, Categories, Units, Taxes, Variation Groups, Users & Roles, Receipt Layout, Payment Methods, HRM & Payroll, Back Office, Catalogue QR, Server / Client Mode, Import / Export, Demo DataThe matching tiles on the Admin screen. Taxes also governs Lists ▸ Sales Tax Code List, Payment Methods governs Lists ▸ Customer & Vendor Profile Lists ▸ Payment Method List, and Users & Roles governs Company ▸ Set Up Users and Roles….

A role that holds any Admin tile permission goes straight into Menu ▸ Admin without the Admin Access box; each tile still checks its own permission.

The Web Access tab

These permissions apply in the web Back Office and to some server actions made from the app — for example adding tax rates or changing payment methods. They are grouped by area, with a tick box per group. Two entries matter for locations:

  • Allow multiple locations (under Business Locations) — users on this role may work at more than one location. When it is off, an orange note reads Allow multiple locations is off — each user on this role works in exactly one location, set on their user record.
  • The locations themselves are set on each user (Works at), not on the role.

If the tab reads No permissions synced yet. Run 'Sync Database' first., use Menu ▸ Sync DataBase and reopen the role.

Deleting a role

  1. Click the bin on the role's row.
  2. Confirm Delete in the Delete role …? box (This action cannot be undone.).
MessageWhat to do
Cannot delete: N user(s) still have this roleMove those users to another role first.
Default roles cannot be deletedThe Admin role is permanent.

Tips

  • Build roles around jobs, not people. A Bookkeeper role used by two people is easier to keep right than two personal roles.
  • Prefer locked to hidden for day-to-day actions. Staff who can see Refund / Credit Note with a padlock ask for approval; staff who cannot see it look for a workaround.
  • Use Read-only (hide actions) for auditors and outside reviewers. They see everything and are never interrupted by approval prompts.
  • Test a role. Create a test user on the role, sign in as that user on another computer, and walk through the screens they need.

Common problems

I ticked one box and the user lost everything else. Ticking any box on SeroBooks Access makes the role governed. Use Start from a role, or the ⋮ ▸ Full access menu on the modules the person needs.

A module shows with a padlock and every click asks for approval. The role has View on the module but no Allow on any screen inside it. Tick Allow on the screens they should use.

A Manager approved something their own role cannot do. That is by design: a Manager may approve anyone's locked action. Only the Manager's own work follows their role.

Changes to a role did not apply. Users pick up the new permissions when they next sign in.

Role already exists. Another role already has that name. Choose a different name.