In EQLEM, authorization is more than showing or hiding screens. Module access and action permissions work together: a user may see inventory but not delete vouchers, or open finance lists without editing payment documents. In setups with many teams, many branches and sensitive operations, that difference matters.
Authorization intersects with modular licensing. Licensing opens the capability on the account; authorization decides who uses it and how. Without both, security is incomplete.
Who is it for?
System admins and IT build role templates. Managers in finance, e-documents, and HR need action separation. Branch managers run teams in their scope; central users see wider. Firms with audit needs want a foundation for “who did what?”; the permission model is that groundwork.
How it works
Users receive roles; roles carry module and action permissions. Typical permissions cover read, create, update, delete, and approval/special actions. The same user may work with different rights across company or branch scopes; configured with multi-company, branch, warehouse.
Company and system management screens administer users, roles, and permissions. New hires start from templates (warehouse operator, sales rep, accounting); exceptions are narrowed or widened per user. Sensitive actions (invoice cancel, bank movement, e-document send) are protected with separate permission rows.
Mobile and web share the same authorization backbone: one model avoids over-granting in the field and over-locking in the office. B2B buyer accounts stay in their portal scope and do not mix with platform user permissions.
Benefits
Error and misuse risk drops. Task-based access replaces “everyone is admin.” Training load shrinks because users only see menus they need. In privacy-sensitive CRM communication and opt-out flows, access boundaries become clear.
Authorization also speeds operations. The right person runs the right action on their own screen; approval queues are intentional. Branch separation keeps central data from spreading unnecessarily.
Relation to modules and products
Authorization applies to every licensed module; from stock vouchers to CRM activities, POS shifts to finance collections. Company management is central for definitions. Permissions are managed in Platform Web; Mobile applies the same permissions to field actions. Integration agent accounts and service identities must also be controlled; write rights on existing system / ERP sync are especially critical.
FAQ
If a license is open, can everyone use it? No. Licensing opens the capability on the account; users still need roles and action permissions.
Are role templates required? Templates accelerate setup; custom roles are allowed. Starting with a few standard roles is practical.
Can a branch manager see another branch? Only according to scope and permission definitions. Multi-company/branch scope is set with authorization.
Is there a separate mobile permission model? No. Same backbone; channel license and device experience may differ, permission logic is shared.
Next step
Draft four to six role templates (read-heavy, operator, approver, admin). Mark sensitive actions separately. Try Free to build the matrix in your account, then connect multi-company scope.
