Legasum Help Open Legasum

Help / People and access

Roles and permissions

Create a role that says who can view, create, edit, delete and export in each module, and limit it to certain branches.

A role is a named set of permissions, such as "Cashier" or "Accountant". You give each employee one role. The page is called Roles & Access; open it from Company > Roles or go to Roles. You need the Roles view permission to see it.

How permissions work

For every module the role has five tick boxes:

PermissionMeaning
ViewSee the module's pages and records
CreateAdd new records
EditChange records. In Approvals, this is also what lets someone approve or reject
DeleteRemove records
ExportDownload the module's data

If a role cannot view a module, that menu disappears from the left menu for that person.

Who is restricted and who is not

  • The company owner always has full access.
  • An employee with no role is not restricted: they can do everything.
  • A role that has never been saved with permissions is also unrestricted.
  • Once you save a role with permissions, only the ticked boxes are allowed. A module with nothing ticked is denied, including modules that Legasum adds later. Open the role, tick what is needed and save again.

Create a role

  1. Open Roles and select Add Role.
  2. Enter a Role Name. It is required ("Please enter role name.").
  3. Optionally add a Description.
  4. In Module Permissions, tick the boxes for each module.
  5. If your company has branches, Branch Access appears. Leave every branch unticked for access to all branches, or tick the branches this role may use.
  6. Select Add Role.

Limit a role to some branches

Tick specific branches under Branch Access to restrict the role. People with that role start in their own branch and cannot create documents or payments, or view reports, for a branch outside the list. They also cannot manage branches themselves.

Edit or delete a role

  • Select the pencil icon, change the role, and select Update Role.
  • Select the bin icon to delete it. Legasum asks "Delete this role and all its permissions?"

A role that is still assigned to anyone cannot be deleted: Legasum tells you how many people hold it. Move them to another role in Employees first. Changes to roles are recorded in the Audit log.

Assign a role to a person

Choose the role when you invite an employee, or later in the employee's edit page. You cannot change your own role.

Common questions

Why can an employee still see everything? They probably have no role, or their role was never saved with permissions.

Where do Departments fit in? Departments group people. They use the Staff permission, not a separate one. See Departments.