User Roles
Location in the application:
Nástroje → Uživatelské role
What are user roles
The User Roles form contains a list of all roles, i.e. the access rights, that can be assigned to individual users in the system.
Roles can be:
standard – pre-set by the system
custom – created according to your own needs
The main purpose of roles is to restrict access to the system based on a user's job position, for example for:
warehouse workers
salespeople
accountants
payroll accountants
administrators
Each user is assigned a specific user role. This determines what the user is allowed to do after logging into the system.
You can find the list of roles in the module:
Tools → User Roles
💡 Tip
It's a good idea to set up user roles right when implementing the system. Properly configured permissions significantly reduce the risk of unwanted changes to data.
Standard roles are set programmatically and cannot be changed. However, you can use them as a basis to create new custom roles, which you can then adjust according to your own needs.
Standard roles
Standard roles are marked with a checkmark in the Standard role column of the table view.
This means these roles are:
firmly defined by the system
unchangeable
cannot be deleted
If you haven't created your own role, the Change button won't even be available in the top toolbar.
You can use the Open button to view what a specific role allows or forbids.
How roles are displayed
On the left side of the form, the entire ABRA Flexi system is displayed as a tree structure – i.e. all modules and their options.
On the right side, you can see what kind of access a user with the given role has.
In the basic view, there are four options:
Full access
The user is allowed to do everything in the given option.
Read only
The user may only view records.
Not accessible
The user cannot see the marked records at all.
Access specification
If a user has full access, this access can be further restricted.
Depending on the specific module and specific option, you can allow or deny things such as:
editing
deleting
canceling/reversing
working with discounts
changing prices
How to identify the access type by font
You can identify the type of access just by looking at the left-hand side.
Looking at the left side of the form, you can tell the access type by the font style:
bold font → full access
regular font → read-only or specified access
italics → access denied
⚠️ Note
No user role automatically has the following enabled:
company administration
the right to lock documents
the right to lock accounting periods
These permissions are set individually for a specific user in their login credentials.
Overview of standard roles
Administrator
The administrator has all permissions within the application.
This permission is automatically granted to the user who first launched the application during installation and entered their username and password in the First Launch dialog.
Only this first user automatically has the following checked:
Allow company administration
The administrator can therefore:
create new companies
rename companies
disconnect companies
delete companies
restore companies from the list of disconnected companies
restore companies from backups
The administrator has all permissions within the application.
Super user
The super user has almost all permissions, with a few exceptions.
In particular, they do not have access to these areas:
This means they cannot:
add new users
change other users' access rights
On the other hand, they can:
add accounting periods
change company settings
work with code lists
perform standard user operations
back up data
Standard user
A standard user has fewer permissions than a super user.
They can work with the application normally, but access is denied to:
Company Setup Wizard
standalone Company Settings
Additionally:
cannot back up data
does not have access to the Employees module
cannot update the license
In the Tools menu, they have limited options. They can:
work with code lists
change their password
work with personal certificates
use the online store
Accountant
An accountant has fewer permissions than a standard user.
Their rights correspond to the role of an accounting employee. They can perform standard accounting operations, but have restrictions in other areas.
Restrictions:
limited access to the Goods module
cannot change product groups
cannot change price levels
no access to the sales module:
inquiries
orders
quotes
cannot issue payment orders
no access to the Employees module
cannot update the license
In the Tools menu, they can:
work with code lists
change their password
use personal certificates
Payroll accountant
A payroll accountant has the same permissions as an accountant, but also has access to the module:
Employees
Salesperson
A salesperson has permissions corresponding to sales activities.
They only have access to selected parts of the system, and even there access may be partially limited.
Company module
Access is denied to:
Company Setup Wizard
standalone Company Settings
They cannot:
back up data
Modules and options
They do not have access to accounting-related parts, for example:
Posting Rules
Item Overviews
Money module
They only have access to the section:
Cash Register
They do not have access to the section:
Bank
No access to the modules:
Assets
Employees
Accounting
Reports
In the Tools menu, they can:
work with code lists
(except for sections related to accounting)perform imports
change their password
use personal certificates
use the online store
They cannot update the license.
Warehouse worker
A warehouse worker has one of the lowest permission levels. This role is intended for warehouse management.
They only have access to the modules:
Even here, access is limited.
For example, they do not have access to:
In the Tools → Code Lists menu, they only have access to code lists related to warehouse management.
Warehouse worker with cash register
This role has the same permissions as a warehouse worker, but also has access to the module:
Money → Cash Register
The Bank section remains restricted.
Read only
A user with this permission has access to all modules but cannot:
create new records
edit existing records
They can only:
view data
create filters
print reports
Inactive account
This permission is intended for a user who previously had access to the application but should now be prevented from logging in.
It is used in cases where a user cannot be deleted because documents they created are linked to their account.
By changing the role to Inactive account:
the user's record remains in the system
but they will not be able to log in
If they attempt to log in, the system will notify them of this fact.
📌 Example
If an employee's employment ends, but there are documents in the system created under their account, the account cannot be deleted. The correct approach is to change their permission to Inactive account.
Creating a custom user role
Predefined user roles in ABRA Flexi cannot be edited. If you need a role with a different scope of rights, create your own by copying one of the existing roles.
⚠️ Always copy a role that has higher rights than what you ultimately want to set, and then remove rights as needed. If you start from a role with lower rights and try to add rights, the system will not accept the change.
Procedure
Go to the Tools → User Roles menu.
From the list, select the role you want to base the new one on, for example Salesperson.
Click the icon to create a copy.
In the window that opens, name the new role — both the abbreviation and the name must be unique, otherwise the role cannot be saved.
On the Basic tab, adjust access to individual modules.
Save the role and assign it to the desired user in the Tools → Users in Company menu.
ℹ️ Roles determine which modules a user can enter. If you also need to restrict which specific records they see within a module, use the data visibility rights available in the Premium plan.
Available fields for a custom role
Abbreviation: The abbreviation of the original role is copied into the new role. It must be changed, since the abbreviation must be unique.
If you don't change it, the system will notify you when saving that the same abbreviation is already used by another record.
Name: The name of the original role is also copied. It's a good idea to edit it so the new role is clearly distinguished.
Name in foreign languages: If you have foreign languages set up in the system, you can press the corresponding button to fill in the Name field in other languages as well.
These language variants of the name are printed on documents when printing in a foreign language.
You can use another button to close the fields for foreign-language names again.
Standard role: This field is inaccessible. The new role is not a standard role.
💡 Tip
When creating custom roles, it's worth naming them according to their specific function, for example:
Skladník bez cenObchodník bez mazáníÚčetní jen čtení mezd
"Basic" tab
On the left side of the tab is a tree of all ABRA Flexi modules and options. You can tell the basic access level by the font type.
On the right side, access is then specified in more detail.
By selecting a module or specific option on the left and marking the corresponding permission on the right, you can adjust the permissions for the given role.
Types of access
Full access – bold font: The user can do everything in the given option.
Read only – regular font: The user may only view records.
Not accessible – italic font: The user cannot see the marked records at all
Access specification – regular font: If a user has full access, this access can be further restricted. Depending on the specific module and specific option, you can allow or deny things such as editing, deleting, etc.
Detailed access restrictions
Depending on the specific module or option, you can individually allow or deny, for example:
Add new – adding a new item or document
Edit existing – editing an existing item or document
Delete – deleting an existing item or document
Cancel/reverse – canceling an existing item or document
Allow discount and price changes – restricting work with discounts and prices
Summation – enabling the summation button
See purchase price – visibility of the purchase price during sales
Change posting – ability to change the configured posting
⚠️ Note
When setting permissions, always make sure you understand what a specific permission applies to:
the whole document
or its line items
The same permission can behave differently depending on where it is set.
⚠️ Important note
If a particular user role property is set both on the document and on the document's line items, the application only accepts the change if the setting is the same in both places.
📌 Example
If you want to prevent a user from changing the price on line items of an issued invoice, it's not enough to check the permission on the invoice itself. You also need to check the permission on the document's line items.
"Texts" tab
All code lists and lists contain a Texts tab.
There are two optional fields here where you can record your own internal information.
Description: You can add a more detailed description.
Note: The note serves to alert staff to a peculiarity of the record or to something other users should pay attention to when handling the record.
💡 Tip
It's a good idea to record in the note, for example:
why the role was created
who it's intended for
what restrictions it has compared to the standard role
Frequently Asked Questions (FAQ)
Can a standard role be edited?
No. Standard roles are system roles and cannot be changed or deleted.
2. How do I create a custom role?
You create a copy of an existing role and then edit it as needed.
3. Does any role automatically have company administration enabled?
No. Company administration is set individually for a user. The exception is the first administrator when the application is first launched.








