Skip to main content

Roles & Permissions

Every user has exactly one role. The role decides the sidebar, the landing dashboard, and which actions the server will accept โ€” the backend enforces permissions independently of what the UI shows.

๐Ÿ“ท Screenshot spot โ€” capture this screen and save it as static/img/screenshots/guide-roles-permissions.png, then replace this whole box with the single line:
![Roles & Permissions](/img/screenshots/guide-roles-permissions.png)

The rolesโ€‹

RoleFocusLands on
Company AdminEverything in their company โ€” settings, users, billing, all modulesCompany Dashboard
Sales ExecutiveCRM, customers, quotations, orders, Quote Studio, Follow-upsSales Dashboard
Estimation EngineerBOMs, drawings, costing, panel templates, quotation draftsEstimation Dashboard
Purchase ManagerVendors, requisitions, RFQs, POs, GRNs, supplier invoices, price OCR, procurement AIPurchase Dashboard
Production EngineerJobs, work orders, shop floor, kanban, QC, dispatch, planner AIProduction Dashboard
AccountantInvoices, payments, receivables, collections, financial & GST reports, GST agentAccounts Dashboard
ViewerRead-only dashboards โ€” quotations, jobs, inventory, reports; no editing anywhereViewer Dashboard
Super AdminThe platform operator (ZAPTIZ itself) โ€” cross-company administrationโ€”

What each role can reachโ€‹

A few access rules worth knowing beyond each role's own module:

  • Shared pages โ€” the Drawing Manager is shared with Sales and Purchase; the BOM Generator with Purchase; the Template Center with most staff roles; Panel Studio with most staff roles.
  • Reading vs writing โ€” several modules let more roles read than write. For example, Sales Executives and Viewers can read invoices but not create them; Production Engineers can update sales-order statuses (for shipping) but not create orders.
  • AI pages follow their module: Quote Studio and Follow-ups belong to Sales; Smart Procurement and Invoice Reader to Purchase; the Planner to Production; Collections and Zaptiz GST to Accounts; the Daily Briefing and Security Center to Company Admins.
  • Viewer really is read-only โ€” a Viewer can't confirm, send, approve or edit anything, and even AI action proposals are denied at the confirmation step.

Changing someone's roleโ€‹

Company Admins manage roles in Users, Roles & Invitations โ€” the change applies at the user's next page load. There are no per-user permission tweaks beyond the role; pick the role that matches the job.

Which role should I giveโ€ฆ?
  • The owner/director โ†’ Company Admin (and read the Daily Briefing).
  • Anyone quoting customers โ†’ Sales Executive.
  • The person doing BOMs and pricing โ†’ Estimation Engineer.
  • The buyer โ†’ Purchase Manager.
  • The factory supervisor โ†’ Production Engineer.
  • The person doing bills and GST โ†’ Accountant.
  • An auditor, investor or consultant who should only look โ†’ Viewer.