Permission Model Reference: Modules, Resources & Actions
This is the definitive reference document on access control in Smart Business 360. Targeted at administrators configuring job roles and auditors auditing system access control.
How a Permission is Expressed
All permissions in the system are expressed as a three-part structured key:
Module . Resource . Action
| Part | Meaning | Example |
| Module | A top-level navigation module | Accounts |
| Resource | An entity or screen inside that module | Voucher |
| Action | The operation being permitted | Post |
Combined Example: Accounts.Voucher.Post grants permission to post a financial voucher to the ledger.
Wildcards & The (Any) Resource
An asterisk (*) matches everything at that position in the key hierarchy:
| Pattern | Grants Allowed |
Accounts.Voucher.Read | Read vouchers only |
Accounts.*.Read | Read every resource in Accounts module |
*.*.Read | Read everything, everywhere across the system |
*.*.Delete | Delete everything, everywhere across the system |
Wildcard Group Maintenance: Built-in permission groups are maintained with wildcards (e.g. CRM.*.Read). This ensures newly shipped CRM resources are automatically accessible without manually updating group definitions.
The (Any) Resource: Some modules have default (Any) stored as .*, granting action access throughout the module.
Standard Action Sets
Most resources use a common CRUD action set, extended with specialized operational actions when necessary:
Standard CRUD Actions:
Create · Read · Update · Delete
Extended Actions:
Export · Import · Print · BulkEdit · Assign · Approve · Reject
Business-Specific Actions:
Unique business actions (e.g. Accounts.Voucher.Post, CRM.Lead.Convert, HRM.Salary.RunPayroll).
Segregation of Duties Note: Action distinctions like Accounts.Voucher.Create vs Accounts.Voucher.Post ensure that the person entering a voucher is not forced to be the same person who posts it to the ledger.
Role Scopes
The System.RoleScope resource defines a user's structural visibility and authority across records:
| Role Scope | Meaning & Authority |
PlatformSuperAdmin | Platform-wide administrator across all companies |
TenantAdmin | Full tenant administrator within one company |
TeamManager | Manages a team; sees team members' records |
HrManager | HR authority, including salary visibility and leave approval |
TaskAssigner | May assign tasks to other users |
Role scopes are additive to normal permissions. A TeamManager still requires module permissions; the scope determines whose records are visible, not which screens are reachable.
Prebuilt Permission Groups
A permission group is a reusable template of permission patterns applied to a role. System groups cannot be deleted; to customize, copy and edit the copy.
| Group | Description |
| Full Access | Full CRUD plus Export, Import and Print across all modules |
| Read Only | *.*.Read — read-only everywhere |
| CRM Full Access | Full CRM including leads, customers, opportunities |
| CRM Sales Rep | Create/read/update in CRM, plus lead convert, score and follow-up. No delete, no import |
| HRM Full Access | Full HR including salary, leave approvals, performance and payroll runs |
| HRM Employee Self-Service | Own data only: read employee record, apply for leave, view attendance and performance |
| Finance Full Access | Full Finance and Accounts including posting, approval and bank reconciliation |
| Finance View Only | Finance.*.Read and Accounts.*.Read |
| Sales Management Full | Bookings, receipts, collections, with approval and print |
| Marketing Manager | Full Marketing Hub including publish, plus Marketing Analytics read and export |
| Project Manager | Full Projects including assignment and status changes |
| Reports Viewer | Read and export all reports |
| Support Agent | Support tickets: create, update, assign, resolve, close |
Choosing a Starting Group
| If the user is a... | Start from System Group |
| Sales agent working leads | CRM Sales Rep |
| Sales manager closing bookings | Sales Management Full |
| Accountant entering vouchers | Finance Full Access |
| Auditor or reviewer | Finance View Only or Read Only |
| HR officer | HRM Full Access |
| Ordinary employee | HRM Employee Self-Service |
| Support desk staff | Support Agent |
| Marketing staff | Marketing Manager |
Full Permission Catalog (22 Navigation Modules)
Actions listed below are in addition to standard CRUD (Create, Read, Update, Delete) unless otherwise stated.
1. Dashboard
2. System
| Resource | Actions |
Company | CRUD, Export |
Permissions | Read, Update |
UserManagement | CRUD, Export, Import, Assign, ResetPassword |
SystemSettings | Read, Update |
RoleScope | PlatformSuperAdmin, TenantAdmin, TeamManager, HrManager, TaskAssigner |
3. CRM
| Resource | Actions |
Customer | CRUD, Export, Import, BulkEdit, Assign, Merge |
Lead | CRUD, Export, Import, BulkEdit, Assign, Convert, ChangeOwner, Score |
Opportunity | CRUD, Export, Assign, ChangeStage, ChangeOwner |
Pipeline | CRUD, Customize |
FollowUp | CRUD, Assign, Complete |
AutomationRule | CRUD |
LeadScoring | Read, Update, Configure |
Contacts | CRUD, Export, Import |
CRMInbox | Read, Update |
4. Leads Inbox
| Resource | Actions |
Dashboard | Read |
Inbox | Read, Update |
Lead | CRUD, Export, Import, BulkEdit, Assign, Convert, ChangeOwner, Score |
Settings | Read, Update |
5. HRM
| Resource | Actions |
Employee | CRUD, Export, Import, ViewSalary, ViewAll, Terminate, ViewPersonal |
Leave | CRUD, Approve, Reject, ViewAll, Export |
Attendance | CRUD, Export, Import, MarkAll, ViewAll |
Department | CRUD |
Performance | CRUD, Approve, ViewAll, Export |
Salary | CRUD, View, ViewAll, Approve, Export, RunPayroll |
Training | CRUD, Assign, Complete, Export |
Employee.ViewSalary and Salary.ViewAll expose compensation data. Grant them deliberately.
6. Approvals
| Resource | Actions |
LeaveApproval, ExpenseApproval, PurchaseApproval, GeneralApproval | Read, Approve, Reject |
7. Projects
| Resource | Actions |
Project | CRUD, Export, Assign, ChangeStatus, ViewAll |
ProjectIdea | CRUD, Approve, Reject |
Task | CRUD, Assign, ChangeStatus, Export |
TimeEntry | CRUD, Approve, Export |
8. Sales Management
| Resource | Actions |
Registration | CRUD, Export, Print |
Member | CRUD, Export, Import |
PaymentPlan | CRUD, Export, Print |
Allocation | CRUD |
Booking | CRUD, Export, Print, Cancel, Reactivate |
Receipt | CRUD, Export, Print, Approve |
Transfer | CRUD, Approve |
Merge | CRUD, Approve |
Adjustment | CRUD, Approve |
Refund | CRUD, Approve, Export |
ReSale | CRUD |
Collections | CRUD, Export |
Commission | CRUD, Export, Approve |
9. Property & Sales
| Resource | Actions |
LandParcel | CRUD, Export |
LandOwner | CRUD, Export |
LandPayment | CRUD, Export, Approve |
LandDocument | CRUD, Export, Print |
Plot | CRUD, Export, Import |
Dealer | CRUD, Export |
10. Admin Tasks
| Resource | Actions |
AdminTask | CRUD, Assign, ChangeStatus, Export |
11. Marketing Hub
| Resource | Actions |
MarketingCampaign | CRUD, Export, Approve, Publish, Schedule |
MarketingQuotation | CRUD, Export, Print, Approve |
FieldVisit | CRUD, Export, Assign |
DigitalCampaign | CRUD, Export, Publish |
DigitalIntegrations | CRUD, Configure |
12. Marketing Analytics
| Resource | Actions |
CampaignAnalytics, LeadAnalytics, ROIAnalytics | Read, Export |
13. Research / Planning
| Resource | Actions |
FeasibilityStudy | CRUD, Export, Approve |
DesignDocument | CRUD, Export, Print, Approve |
ResearchReport | CRUD, Export |
14. Execution Control
| Resource | Actions |
ExecutionProject | CRUD, Export, ChangeStatus |
Milestone | CRUD, ChangeStatus, Approve |
NocRequest | CRUD, Approve |
ProgressUpdate | CRUD |
15. Finance
| Resource | Actions |
Income | CRUD, Export, Approve |
Expense | CRUD, Export, Approve |
FinanceDashboard | Read |
16. Accounts
| Resource | Actions |
ChartOfAccount | CRUD, Export, Import |
FinancialYear | CRUD, Close |
VoucherType | CRUD |
Voucher | CRUD, Export, Print, Post, Approve |
PartyAccount | CRUD, Export |
BankAccount | CRUD, Export, Reconcile |
Cheque | CRUD, Export, Print |
PettyCash | CRUD, Export, Approve |
CashAccount | CRUD, Export, Approve |
17. Communication
| Resource | Actions |
WhatsApp | Read, Create, BulkSend |
SMS | Read, Create, BulkSend |
Call | Read, Create, Export |
Chat | Read, Create |
AddressBook | CRUD, Export, Import |
Notification | Read, Create |
BulkSend permits mass messaging. Restrict it — carries cost and regulatory exposure.
18. Inventory
| Resource | Actions |
Inventory | CRUD, Export, Import, Adjust |
Vendor | CRUD, Export |
VendorRating | CRUD |
Procurement | CRUD, Export, Approve |
19. AI Analytics
| Resource | Actions |
AIDashboard | Read, Export |
Predictions | Read |
Insights | Read, Export |
20. AI Assistant
| Resource | Actions |
(Any) | Read |
21. Reports
| Resource | Actions |
SalesReports, FinanceReports, HRReports, CRMReports, MarketingReports | Read, Export, Schedule |
CustomReports | Read, Create, Export, Schedule |
22. Support Tickets
| Resource | Actions |
SupportTicket | CRUD, Assign, Resolve, Close, Export |
SLABreach | Read, Export |
Segregation of Duties Checklist
For a controlled finance environment, ensure no single user role holds both permission keys in any of these pairs:
| Should Be Separated Pair | Reason / Business Risk |
Accounts.Voucher.Create + Accounts.Voucher.Post | Entry vs commitment to financial ledger |
SalesManagement.Receipt.Create + SalesManagement.Receipt.Approve | Collection vs payment authorization |
SalesManagement.Refund.Create + SalesManagement.Refund.Approve | Refund initiation vs disbursement release |
HRM.Salary.Create + HRM.Salary.RunPayroll | Payroll preparation vs funds disbursement |
Inventory.Procurement.Create + Inventory.Procurement.Approve | Requisition vs purchase commitment authority |
System.UserManagement.Create + System.Permissions.Update | User account creation vs privilege escalation grant |
Frequently Asked Questions
Grants are additive. A user with CRM.*.Read and CRM.Lead.Update can read all CRM resources and also update leads as well.
Yes. The same module catalog is used for navigation menu rendering.
Yes. Permission checks are done in the context of the currently active company tenant using assigned user roles and role scopes.
In the Admin Console, navigate to the Permissions screen, filter for specific permission keys, and export the resulting user list.