Manage Roles and Access
Yepsta separates a person’s job title, assigned role and location access. This lets the owner create access profiles around real responsibilities instead of giving every manager or staff member the same permissions.
Understand the access model
Section titled “Understand the access model”- A staff profile under Team stores operational information such as job title, work location, services and availability.
- A role under Settings → Permissions → Roles & Access is an access profile that defines workspace, allowed actions and supported record scopes.
- A dashboard user under Administration → User Management receives one role plus assigned locations.
The final result is the intersection of the role’s permissions and scopes, the user’s permitted locations, record assignments, subscription and feature availability. A job title does not grant access, and a role does not automatically grant every record at a location.
Set up default roles
Section titled “Set up default roles”If the business has no role profiles yet, open Settings → Permissions → Roles & Access and select Set up default roles. Yepsta creates the default Manager and Staff profiles. Review their permissions before assignment; the profile name alone is not an assurance that it matches a person’s work.
Default and system profiles are protected. They cannot be archived, and their required workspace cannot be changed. To create a substantially different access pattern, duplicate a profile or create a custom role.
Create a custom role
Section titled “Create a custom role”- Open Settings → Permissions → Roles & Access and select Create role.
- Enter a clear role name and optional description.
- Choose Business workspace for broader operational administration, or Staff workspace for a person linked to a Staff profile.
- Use Find permissions to locate the relevant module and function.
- Select the individual actions the role needs. Use Select all View, Select all Read/Write or Clear module only as review shortcuts.
- For each supported action, choose the narrowest suitable Access scope.
- Select Save changes, review the confirmation summary, then select Confirm changes.
The View and Read/Write shortcuts are additive selections, not fixed permission levels. Sensitive actions—such as deletion, export, payment or override actions—remain separate and should be granted individually.
Choose the correct scope
Section titled “Choose the correct scope”An action may support one or more of these scopes:
- Default access: use the action’s normal record boundary.
- Their own records: records created by or belonging to the user where supported.
- Assigned records: work explicitly assigned to the user.
- Their team: records for the user’s supported team relationship.
- Assigned locations: records at locations assigned to the user.
- Across permitted business locations: eligible records across the locations the user is allowed to use.
The choices shown depend on the action. A broad action scope never overrides the locations saved on the user or an owner-only rule.
Review, edit or archive a role
Section titled “Review, edit or archive a role”Open a role to see its workspace, permissions, scopes and assigned-user count. Use Duplicate to create a starting point for a related role.
When editing, Confirm role changes identifies access being allowed or removed and how many users are affected. Permission changes apply to every assigned user, and users whose current access changed must sign in again. If someone else changed the role while it was open, reopen the latest version and review again.
A custom role can be archived only when no user is assigned to it. Reassign its users first. Assigned, default and system roles cannot be archived, and archived roles are retained rather than deleted.
Assign a role and locations to a user
Section titled “Assign a role and locations to a user”- Open Administration → User Management.
- Find the person and select Manage access.
- Choose the Assigned role and confirm whether User active should be on.
- Choose Access all business locations, including future locations, or select only the required Assigned locations.
- For a Staff workspace role, confirm the login is linked to the correct Staff profile.
- Select Preview saved current access when you need to compare the existing setup.
- Select Review changes, inspect the workspace, role, status and locations, then select Save user access.
An explicit all-locations selection takes precedence over individual locations and includes future locations. Without it, keep the user to the branches they work in. Access changes require the user to sign in again.
Example role profiles
Section titled “Example role profiles”Use these as review prompts, not automatic permission bundles:
- Academy Instructor: Staff workspace, linked Staff profile, assigned locations, assigned Classes, attendance and the learner details needed for delivery; no fee adjustments or role management.
- Academy Operations Manager: Business workspace, permitted Academy locations, Programmes, Batches, enrolments, timetable and operational reports; add fee actions only if this person owns that process.
- Service Front Desk: Business workspace, assigned locations, customers, appointments and permitted invoice actions; no payroll, accounting exports or access administration.
- Graphic Designer: Business workspace, assigned Projects and their tasks or documents; add website actions only when publishing is part of the job, with sensitive publish or deletion actions reviewed separately.
Troubleshoot missing or excessive access
Section titled “Troubleshoot missing or excessive access”Check these layers in order:
- Correct dashboard user and active status.
- Correct assigned role and workspace.
- Exact action permission and supported scope.
- Assigned locations and record location.
- Required Staff-profile or work assignment.
- Subscription and feature availability.
Navigation may hide work a user cannot perform, but Yepsta also checks access when the page or action is requested. A bookmark cannot bypass the rule.
Last reviewed:
