ACCESS MANAGEMENT

How to Create Users and Assign Roles in Smart Business 360

Step-by-step administrator guide to provisioning users, assigning job roles and permission groups, setting role scopes, and enforcing account offboarding procedures.

The Access Model in Brief

System access is determined sequentially by evaluating 4 distinct parameters in strict order:

  1. Company Entitlement: Is the target module enabled for this company tenant?
  2. Role Permission Key: Does the user's role contain the necessary Module.Resource.Action key?
  3. Record Scope: What level of access (Own, Department, Company) does the user hold?
  4. Department & Team: Which team assignment determines record visibility for a manager?
Diagnostic Tip: If a user cannot reach a screen at all, failure is usually at Step 1 or 2. If the screen opens but data does not appear, failure is at Step 3 or 4.

Creating a User (7 Steps)

1
Navigate to User ManagementClick on System → User management in the main navigation.
2
Click Create UserSelect the Create User action button.
3
Enter Contact DetailsEnter contact information, full name, and primary email address.
4
Assign Active CompanyAssign the user to their target company tenant.
5
Assign RoleSelect and assign the appropriate job role.
6
Designate DepartmentIf the company uses departments, assign the user to their designated department.
7
Save AccountClick Save. The user receives account activation details at their provided email address.

Required Permissions: System.UserManagement.Create plus System.UserManagement.Assign to attach roles.

Roles & Creating a Role

A role is a collection of permission keys grouped by job title. Rather than assigning individual permission keys per person, assign a role and update the role when job duties change.

Steps to Create a Custom Role:
  1. Go to System → Permissions.
  2. Select Create role.
  3. Enter a job title name (e.g. Sales Officer, not an individual person's name like Ali's Access).
  4. Select one or more prebuilt permission groups as a starting point.
  5. Make fine-grained adjustments to specific permission keys as necessary.
  6. Save the role definition.

Recommended Baseline Roles Catalog

Role NameBuilt From (Permission Groups & Scopes)Typical Holder
Tenant Administrator Full Access + TenantAdmin scope Company owner or IT lead
Sales Officer CRM Sales Rep Sales agents working leads
Sales Manager CRM Full Access + Sales Management Full + TeamManager Closes bookings, oversees sales team
Accountant Finance Full Access Enters and posts financial vouchers
Finance Reviewer Finance View Only Internal auditor and reviewer
HR Officer HRM Full Access + HrManager Payroll administrator and leave approver
Employee HRM Employee Self-Service All general staff members
Support Agent Support Agent Support desk staff
Marketing Officer Marketing Manager Campaign and digital channel manager

Role Scopes Definition

Role scopes decide whose records a user can see. Assigned via System.RoleScope permission:

Scope KeyGrants Allowed
PlatformSuperAdminPlatform-wide access across all company tenants
TenantAdminFull administration within one company tenant
TeamManagerVisibility of their team members' records
HrManagerHR authority including salary visibility and leave approval
TaskAssignerAuthority to assign tasks to other users

A scope is not a substitute for permissions. A manager with TeamManager still requires module read permission (CRM.Lead.Read) to view team lead records.

Departments Setup

Departments structure team-based visibility and HR reporting:

  1. Click on HRM → Departments.
  2. Establish the department and designate the job title of its department head.
  3. Assign users to the department. Records created by department members are visible to managers with TeamManager scope.

Managing Account Status

ActionOperational Effect
DeactivateBlocks user sign-in while preserving 100% of historical records, audit logs, and transaction history.
ReactivateRestores user sign-in access.
Reset passwordIssues a password reset; requires System.UserManagement.ResetPassword.
Audit Preservation Rule: Always Deactivate rather than delete accounts when employees depart. Deleting a user breaks historical record attribution and audit trails.

Offboarding Checklist (6 Steps)

When an employee leaves the company, execute this strict 6-step offboarding checklist:

1
Deactivate AccountDeactivate the user account immediately.
2
Reassign Sales RecordsReassign open leads, opportunities, and follow-up tasks to active agents.
3
Transfer Tasks & Support TicketsTransfer open support tickets and administrative tasks to active team members.
4
Revoke Integration CredentialsRemove any personal integration credentials or channel tokens set up by the user.
5
Reassign Approval AuthorityEnsure an alternate approval authority is designated before deactivation to prevent approval queues from stalling.
6
Document Audit LogDocument the offboarding changes in your internal compliance log.

Troubleshooting Access Issues

A module isn't appearing in a user's sidebar.

Before checking role permissions, verify company module entitlement. Entitlement is evaluated before permissions.

User logs on but no records are presented on screen.

The user either holds a too-limited position scope or is assigned to the wrong department.

Users cannot approve document transactions.

Approve is a separate action permission. Read and Update permissions do not grant approval authority.

New user did not receive activation email.

Verify user email address spelling and ensure company outbound SMTP email settings are configured correctly.

Changes in permission are not yet taking effect.

Ask the user to log off and log back in to force token re-calculation.

Frequently Asked Questions

If more than one permission is granted, they are additive. However, it is best practice to define a clear-cut job position role rather than assigning confusing multiple roles.

Yes! Create a variant quickly using the Copy, rename and adjust option in the Permissions screen.

Permissions govern present and future access actions. Existing historical records created prior to permission changes remain preserved in the system.

Filter by specific permission key in the Permissions screen and export the list of assigned users.