Manage permissions
When you do this: you're setting up the tenant, adjusting access for an existing user, creating a new role with a new mix of permissions, or troubleshooting "why can't user X see Y?"
Outcome: permission profiles that match the roles your company actually has, and users assigned to the right profile.
Steps
- Understand the concept: every user gets exactly one permission profile; profiles are easier to manage than per-user grants. → Permissions
- Review the existing permission profiles. Are the five standard ones (Restricted, Employee, Team Manager, Resource Manager, Admin) close enough? Only create new profiles when there is a real gap. → Permission concept
- For each profile, walk through every permission and pick a scope: None, Own data, Team data, Resource group, Team & Resource group, or All data. Document the rationale in the profile description. → Permission concept
- Test by switching to a user with that profile and confirming what they can and cannot do. → Check Your Permissions
- For temporary access (e.g. when someone is on vacation), use delegations rather than re-assigning the permission profile. → Delegations
Common patterns
- A new consultant gets the default Employee profile.
- A team manager gets a profile with team-scoped read/write on profiles, projects, and resource plan.
- A resource manager gets broader read across all consultants plus write on bookings and resource requests.
- An administrator gets full access.
Related scenarios
- Set up decídalo for the first time: set up profiles before importing users.
- Onboard a new consultant: where profile assignment actually happens for each user.