๐งโ๐ผ Managing User Roles & Access Control
The User Roles & Access Control Page allows administrators to define which users can access certain features and data. This is crucial for ensuring security, accountability, and streamlined workflows in multi-user environments.
๐ฏ What Can You Do Here?
- ๐ Create and edit user roles
- ๐ฅ Assign roles to users
- ๐ช Restrict access to specific stores or departments
- ๐ Control permissions for each feature (view, edit, delete)
๐ Default Roles in the System
The system comes with preconfigured roles that can be customized:
- Administrator: Full access to all features and stores
- Inventory Officer: Manages stock but cannot change system settings
- Cashier: Limited to POS operations and viewing sales
- Pharmacist: Dispensing permissions and access to expiry alerts
- Auditor: Read-only access to inventory and transaction records
๐ Store-Level Access
Each role can be restricted to specific stores:
- โ Example: A cashier may only access the โRetail Storeโ
- โ Example: A ward nurse sees only the inventory for โWard Supplies Storeโ
This ensures users only see and work with data relevant to their responsibilities.
๐ ๏ธ Configurable Permissions
For each role, you can set granular permissions like:
- โ๏ธ View Only: Allows viewing data but no edits
- โ๏ธ Create/Edit: Enables adding and modifying records
- โ๏ธ Delete: Allows removing records (use with caution)
- โ๏ธ Export/Print: Controls ability to generate reports
๐งฐ Real-Life Workflow: Adding a Role for Nurses
- Go to User Roles & Access Control Page
- Click Add New Role
- Name: โWard Nurseโ
- Set permissions: View inventory, Borrow items, Dispense items
- Restrict to stores: Ward 1, Ward 2
- Save and assign this role to staff accounts
โ Nurses now have appropriate access without seeing unrelated data.
๐ง Best Practices
- Review user permissions quarterly to ensure compliance
- Apply the principle of least privilege (grant only needed access)
- Use separate roles for admins and finance teams to prevent conflicts
- Restrict Delete permissions to trusted users only

