Skip to content
Roles and Permissions

Roles and Permissions

Roles are reusable sets of Permissions for a company’s Users. An Admin can open Settings → Roles to review the Permission catalog, edit the protected User Role, or create a custom Role. Assigning a Role to a User changes what that User may view or change across AndonPulse.

Each resource offers Read and Write levels. Write includes Read, and the editor saves only the highest selected level. A resource with no selected level is unavailable. Some levels are fixed by the product and appear locked in the editor; a Role cannot override them.

Every company has two protected Roles:

  • Admin always has the highest current level for every resource. It cannot be renamed, edited, or deleted.
  • User is assigned to invitations by default. It cannot be renamed or deleted, but an Admin can change its editable Permissions. Initially it can read Analytics, Settings, and Billing, but it cannot save Charts or Dashboards, change settings or billing, view financial data, or administer Users and Roles.

Custom Roles start with the catalog defaults and can be renamed or edited. Access control cannot be granted to a custom Role in the first version. A custom Role can be deleted only when no Users are assigned to it; if it is assigned, AndonPulse reports the number of assignments to resolve first.

Use custom Roles to combine the access a job needs. For example, a finance-style Role can add Financial data → Write to view Labor Cost metrics and maintain the Labor Cost worksheet, and add Billing → Write only when that User should also change the Subscription. There is no fixed Finance Role.

Read grants viewing while Write also grants Read and allows changes. A User with Analytics Read but without Analytics Write can open saved Dashboards but cannot open Explore or save, duplicate, rearrange, resize, or delete Charts and Dashboards. Settings and Billing pages remain visible when their Read level is present; their mutation controls are disabled without the matching Write level.

A saved Chart that requests financial data remains in its original Dashboard position for a User without Financial data Read. Its title and dimensions remain visible, but its body says You don’t have access to this metric and shows no number, series, table, tooltip, drill, or export action.

Permission checks are enforced by the server. If another Admin changes a Role while someone is signed in, their next unauthorized request is refused even if an older page still shows the action.

Last updated on