Roles & Permissions
Every user has exactly one role. The role decides the sidebar, the landing dashboard, and which actions the server will accept โ the backend enforces permissions independently of what the UI shows.
๐ท Screenshot spot โ capture this screen and save it as static/img/screenshots/guide-roles-permissions.png, then replace this whole box with the single line:

The rolesโ
| Role | Focus | Lands on |
|---|---|---|
| Company Admin | Everything in their company โ settings, users, billing, all modules | Company Dashboard |
| Sales Executive | CRM, customers, quotations, orders, Quote Studio, Follow-ups | Sales Dashboard |
| Estimation Engineer | BOMs, drawings, costing, panel templates, quotation drafts | Estimation Dashboard |
| Purchase Manager | Vendors, requisitions, RFQs, POs, GRNs, supplier invoices, price OCR, procurement AI | Purchase Dashboard |
| Production Engineer | Jobs, work orders, shop floor, kanban, QC, dispatch, planner AI | Production Dashboard |
| Accountant | Invoices, payments, receivables, collections, financial & GST reports, GST agent | Accounts Dashboard |
| Viewer | Read-only dashboards โ quotations, jobs, inventory, reports; no editing anywhere | Viewer Dashboard |
| Super Admin | The platform operator (ZAPTIZ itself) โ cross-company administration | โ |
What each role can reachโ
A few access rules worth knowing beyond each role's own module:
- Shared pages โ the Drawing Manager is shared with Sales and Purchase; the BOM Generator with Purchase; the Template Center with most staff roles; Panel Studio with most staff roles.
- Reading vs writing โ several modules let more roles read than write. For example, Sales Executives and Viewers can read invoices but not create them; Production Engineers can update sales-order statuses (for shipping) but not create orders.
- AI pages follow their module: Quote Studio and Follow-ups belong to Sales; Smart Procurement and Invoice Reader to Purchase; the Planner to Production; Collections and Zaptiz GST to Accounts; the Daily Briefing and Security Center to Company Admins.
- Viewer really is read-only โ a Viewer can't confirm, send, approve or edit anything, and even AI action proposals are denied at the confirmation step.
Changing someone's roleโ
Company Admins manage roles in Users, Roles & Invitations โ the change applies at the user's next page load. There are no per-user permission tweaks beyond the role; pick the role that matches the job.
Which role should I giveโฆ?
- The owner/director โ Company Admin (and read the Daily Briefing).
- Anyone quoting customers โ Sales Executive.
- The person doing BOMs and pricing โ Estimation Engineer.
- The buyer โ Purchase Manager.
- The factory supervisor โ Production Engineer.
- The person doing bills and GST โ Accountant.
- An auditor, investor or consultant who should only look โ Viewer.