Manage roles and permissions
To manage roles and permissions, start with settings access and verified Business Account, branch, user, or configuration details. In Admin, list roles, create role, edit role, and select capabilities. Settings can affect every user or branch in scope, so review the selected Business Account and branch before saving.
Before you start
- Settings access and verified Business Account, branch, user, or configuration details
- Confirm whether the change is personal, Business Account-wide, or branch-specific before saving
Steps
- Open the Roles section in Settings and review existing roles before creating a new one.
- Enter a distinct role name, then select only the capabilities required for the documented job.
- Review read, write, administration, and branch scope separately before saving.
- Assign the saved role from the team-member workflow; verify the affected user’s effective access rather than assuming the role name grants it.
Expected result
The role reopens with its saved name and selected capabilities. Assignment occurs through the intended user record, and effective access remains constrained by the user’s Business Account and branch assignments.
Permissions
- Role management requires rbac.admin for the redirected RBAC routes; role writes and assignments remain restricted to authorized administrators.
Troubleshooting
A role cannot be saved.
Correct the displayed name or capability validation and ensure the role has only the required permissions. Submit once; do not broaden access merely to make the save succeed.
A user’s effective access differs from the role.
Check the saved role, the user assignment, and Business Account and branch scope separately. Do not infer access from the role name; report the role, user reference, expected capability, branch, and observed route.
Related articles
Update verified Business Account identity, regional, or tax settings and confirm the saved values.Manage branches
Create or maintain a branch, review its tabs separately, and assess operational impact before deactivation.Manage team members and invitations
Invite or maintain a team member using the correct email, role, and allowed branch scope.
Open in TajerGo
Sign in with the appropriate role and confirm your Business Account and branch before continuing.
Read as Markdown · Guidance for support agents
Last reviewed 2026-09-06 · Send documentation feedback