Skip to main content

User Roles

Tools – User Roles

Written by Zuzana Sýkorová

User Roles

Location in the application:
Nástroje → Uživatelské role

What are user roles

The User Roles form contains a list of all roles, i.e. the access rights, that can be assigned to individual users in the system.

Roles can be:

  • standard – pre-set by the system

  • custom – created according to your own needs

The main purpose of roles is to restrict access to the system based on a user's job position, for example for:

  • warehouse workers

  • salespeople

  • accountants

  • payroll accountants

  • administrators

Each user is assigned a specific user role. This determines what the user is allowed to do after logging into the system.

You can find the list of roles in the module:

Tools → User Roles

💡 Tip
It's a good idea to set up user roles right when implementing the system. Properly configured permissions significantly reduce the risk of unwanted changes to data.

Standard roles are set programmatically and cannot be changed. However, you can use them as a basis to create new custom roles, which you can then adjust according to your own needs.


Standard roles

Standard roles are marked with a checkmark in the Standard role column of the table view.

This means these roles are:

  • firmly defined by the system

  • unchangeable

  • cannot be deleted

If you haven't created your own role, the Change button won't even be available in the top toolbar.

You can use the Open button to view what a specific role allows or forbids.

How roles are displayed

On the left side of the form, the entire ABRA Flexi system is displayed as a tree structure – i.e. all modules and their options.

On the right side, you can see what kind of access a user with the given role has.

In the basic view, there are four options:

Full access

The user is allowed to do everything in the given option.

Read only

The user may only view records.

Not accessible

The user cannot see the marked records at all.

Access specification

If a user has full access, this access can be further restricted.

Depending on the specific module and specific option, you can allow or deny things such as:

  • editing

  • deleting

  • canceling/reversing

  • working with discounts

  • changing prices

How to identify the access type by font

You can identify the type of access just by looking at the left-hand side.

Looking at the left side of the form, you can tell the access type by the font style:

  • bold font → full access

  • regular font → read-only or specified access

  • italics → access denied

⚠️ Note
No user role automatically has the following enabled:

  • company administration

  • the right to lock documents

  • the right to lock accounting periods

These permissions are set individually for a specific user in their login credentials.


Overview of standard roles

Administrator

The administrator has all permissions within the application.

This permission is automatically granted to the user who first launched the application during installation and entered their username and password in the First Launch dialog.

Only this first user automatically has the following checked:

Allow company administration

The administrator can therefore:

  • create new companies

  • rename companies

  • disconnect companies

  • delete companies

  • restore companies from the list of disconnected companies

  • restore companies from backups

The administrator has all permissions within the application.

Super user

The super user has almost all permissions, with a few exceptions.

In particular, they do not have access to these areas:

This means they cannot:

  • add new users

  • change other users' access rights

On the other hand, they can:

  • add accounting periods

  • change company settings

  • work with code lists

  • perform standard user operations

  • back up data

Standard user

A standard user has fewer permissions than a super user.

They can work with the application normally, but access is denied to:

  • Company Setup Wizard

  • standalone Company Settings

Additionally:

  • cannot back up data

  • does not have access to the Employees module

  • cannot update the license

In the Tools menu, they have limited options. They can:

  • work with code lists

  • change their password

  • work with personal certificates

  • use the online store

Accountant

An accountant has fewer permissions than a standard user.

Their rights correspond to the role of an accounting employee. They can perform standard accounting operations, but have restrictions in other areas.

Restrictions:

  • limited access to the Goods module

  • cannot change product groups

  • cannot change price levels

  • no access to the sales module:

    • inquiries

    • orders

    • quotes

  • cannot issue payment orders

  • no access to the Employees module

  • cannot update the license

In the Tools menu, they can:

  • work with code lists

  • change their password

  • use personal certificates

Payroll accountant

A payroll accountant has the same permissions as an accountant, but also has access to the module:

  • Employees

Salesperson

A salesperson has permissions corresponding to sales activities.

They only have access to selected parts of the system, and even there access may be partially limited.

Company module

Access is denied to:

  • Company Setup Wizard

  • standalone Company Settings

They cannot:

  • back up data

Modules and options

They do not have access to accounting-related parts, for example:

  • Posting Rules

  • Item Overviews

Money module

They only have access to the section:

  • Cash Register

They do not have access to the section:

  • Bank

No access to the modules:

  • Assets

  • Employees

  • Accounting

  • Reports

In the Tools menu, they can:

  • work with code lists
    (except for sections related to accounting)

  • perform imports

  • change their password

  • use personal certificates

  • use the online store

They cannot update the license.

Warehouse worker

A warehouse worker has one of the lowest permission levels. This role is intended for warehouse management.

They only have access to the modules:

Even here, access is limited.

For example, they do not have access to:

In the Tools → Code Lists menu, they only have access to code lists related to warehouse management.

Warehouse worker with cash register

This role has the same permissions as a warehouse worker, but also has access to the module:

The Bank section remains restricted.

Read only

A user with this permission has access to all modules but cannot:

  • create new records

  • edit existing records

They can only:

  • view data

  • create filters

  • print reports

Inactive account

This permission is intended for a user who previously had access to the application but should now be prevented from logging in.

It is used in cases where a user cannot be deleted because documents they created are linked to their account.

By changing the role to Inactive account:

  • the user's record remains in the system

  • but they will not be able to log in

If they attempt to log in, the system will notify them of this fact.

📌 Example
If an employee's employment ends, but there are documents in the system created under their account, the account cannot be deleted. The correct approach is to change their permission to Inactive account.


Creating a custom user role

Predefined user roles in ABRA Flexi cannot be edited. If you need a role with a different scope of rights, create your own by copying one of the existing roles.

⚠️ Always copy a role that has higher rights than what you ultimately want to set, and then remove rights as needed. If you start from a role with lower rights and try to add rights, the system will not accept the change.

Procedure

  1. Go to the Tools → User Roles menu.

  2. From the list, select the role you want to base the new one on, for example Salesperson.

  3. Click the icon to create a copy.

  4. In the window that opens, name the new role — both the abbreviation and the name must be unique, otherwise the role cannot be saved.

  5. On the Basic tab, adjust access to individual modules.

  6. Save the role and assign it to the desired user in the Tools → Users in Company menu.

ℹ️ Roles determine which modules a user can enter. If you also need to restrict which specific records they see within a module, use the data visibility rights available in the Premium plan.

Available fields for a custom role

  • Abbreviation: The abbreviation of the original role is copied into the new role. It must be changed, since the abbreviation must be unique.

    If you don't change it, the system will notify you when saving that the same abbreviation is already used by another record.

  • Name: The name of the original role is also copied. It's a good idea to edit it so the new role is clearly distinguished.

  • Name in foreign languages: If you have foreign languages set up in the system, you can press the corresponding button to fill in the Name field in other languages as well.

    These language variants of the name are printed on documents when printing in a foreign language.

    You can use another button to close the fields for foreign-language names again.

  • Standard role: This field is inaccessible. The new role is not a standard role.

💡 Tip
When creating custom roles, it's worth naming them according to their specific function, for example:

  • Skladník bez cen

  • Obchodník bez mazání

  • Účetní jen čtení mezd

"Basic" tab

On the left side of the tab is a tree of all ABRA Flexi modules and options. You can tell the basic access level by the font type.

On the right side, access is then specified in more detail.

By selecting a module or specific option on the left and marking the corresponding permission on the right, you can adjust the permissions for the given role.

Types of access

  • Full access – bold font: The user can do everything in the given option.

  • Read only – regular font: The user may only view records.

  • Not accessible – italic font: The user cannot see the marked records at all

  • Access specification – regular font: If a user has full access, this access can be further restricted. Depending on the specific module and specific option, you can allow or deny things such as editing, deleting, etc.

Detailed access restrictions

Depending on the specific module or option, you can individually allow or deny, for example:

  • Add new – adding a new item or document

  • Edit existing – editing an existing item or document

  • Delete – deleting an existing item or document

  • Cancel/reverse – canceling an existing item or document

  • Allow discount and price changes – restricting work with discounts and prices

  • Summation – enabling the summation button

  • See purchase price – visibility of the purchase price during sales

  • Change posting – ability to change the configured posting

⚠️ Note
When setting permissions, always make sure you understand what a specific permission applies to:

  • the whole document

  • or its line items

The same permission can behave differently depending on where it is set.

⚠️ Important note
If a particular user role property is set both on the document and on the document's line items, the application only accepts the change if the setting is the same in both places.

📌 Example
If you want to prevent a user from changing the price on line items of an issued invoice, it's not enough to check the permission on the invoice itself. You also need to check the permission on the document's line items.

"Texts" tab

All code lists and lists contain a Texts tab.

There are two optional fields here where you can record your own internal information.

  • Description: You can add a more detailed description.

  • Note: The note serves to alert staff to a peculiarity of the record or to something other users should pay attention to when handling the record.

💡 Tip
It's a good idea to record in the note, for example:

  • why the role was created

  • who it's intended for

  • what restrictions it has compared to the standard role


Frequently Asked Questions (FAQ)

  1. Can a standard role be edited?

No. Standard roles are system roles and cannot be changed or deleted.

2. How do I create a custom role?

You create a copy of an existing role and then edit it as needed.

3. Does any role automatically have company administration enabled?

No. Company administration is set individually for a user. The exception is the first administrator when the application is first launched.

May also be useful

Did this answer your question?