What are user permissions?

What are user permissions?
User permissions are the rules that define what each person can see and what they can do inside Kardex Tauro. Instead of assigning closed roles such as "cashier" or "warehouse clerk", the software works with granular permissions: every capability is granted independently, user by user. That is why a newly created user starts with an empty assigned list and cannot perform any operation until an administrator sets the permissions.
Only an administrator can manage permissions. From the Configuration window, he or she opens the user list, selects the person and enters the permission selection screen, which shows two parallel lists: available permissions on the left and assigned permissions on the right. With a double click or the arrow buttons, capabilities move from one list to the other, and the changes take effect only after pressing Save permissions; closing the window without saving discards everything.
The See vs. Do duality
The core concept is separating consultation from operation. A See permission opens the module window and lets the user look at its information, but not create, edit or delete anything. A Do permission enables the operation: creating documents, processing movements or recording changes. Since a Do permission is useless without access to the module, the golden rule is that the user needs both: See plus Do equals full functionality.
A daily example: a seller with the See Kardex permission can check the movement history of a product, but without the Kardex plus and Kardex minus permissions cannot make positive or negative stock adjustments. That keeps an unauthorized person from changing inventory with a single click.
| Module | See permission (view) | Do permission (operate) |
|---|---|---|
| Sales | See sales | Do sales |
| Cash register | See cash register | Do cash register (opening, closing, counting) |
| Kardex | See Kardex | Kardex plus and Kardex minus (adjustments) |
| Inventory | See inventory | Create inventory |
| Purchases | See purchases | Do purchases, receive purchases and approve purchases |
| Shrinkage | See shrinkage | Do shrinkage |
| Third parties | See third parties | Do third parties |
| Consignments | See consignments | Do consignment |
| Customer quotation | See customer quotation | Do customer quotation |
| Accounts receivable | See accounts receivable | Do accounts receivable (payments and adjustments) |
| Transfers | See transfers | Do transfers |
| Returns | See returns | Do returns |
| Production | See production | Do production |
The catalog does not end there: internal consumption, supplier quotations, accounts payable, returns of goods, groups and subgroups, warehouse entries and other modules repeat the same pattern of one view permission plus one or several operation capabilities. The Available Permissions list always shows the complete catalog, and there the administrator decides, one by one, what each person receives.
Printing is a special case: there is a single Print permission, transversal to every module. A user may have See sales and Do sales, but without this permission cannot print invoices, tickets or reports; with it, printing works in any window the user can access.
The permission is single and cannot be limited to one kind of document: with it, any receipt or report from the authorized modules can be printed, and without it nothing is printed.
The permission assignment flow, step by step
Assigning or correcting permissions takes little time when the right order is followed. The administrator can do it at any moment, and saved changes apply to the user immediately.
- Log in with administrator credentials and confirm that the Configuration window is available, since it only appears for this user type.
- Open Configuration, go to the Users section and select the person to configure from the list.
- Open the User Permissions window for that person and check the top area: the name must be correct and the cost center must match the branch where they work; if it needs to be changed, do it before moving on to the permissions.
- Define what the person will do on the job: which modules they need to open, whether they only view or also operate, whether they print documents, whether they must approve other users' operations or work in more than one branch.
- In the left list, Available Permissions, find the first capability needed and double-click it to move it to Assigned Permissions; repeat for every permission, or use the arrow buttons between the two lists if you prefer the traditional method.
- Review the right list: every needed capability must be there, nothing extra should remain, and the See and Do permissions should stay balanced for the position.
- Press the Save permissions button. That click is mandatory: the software does not apply changes by itself and does not ask whether to save when closing; if the window closes without saving, the work is lost.
- Test the result: log out of the administrator session, log in with the configured user and verify that they open the expected modules, cannot enter unauthorized ones and print, or not, according to what was assigned.
The same route fixes a mistake: open the user's window, return the leftover permissions to the left list with a double click or the backward arrow, and save again. Since changes are immediate, the correction takes effect the moment the button is pressed.
User types
Three figures coexist in Kardex Tauro. The administrator holds every permission implicitly: the system does not even allow individual permissions to be assigned to an administrator, and only administrators reach the Configuration window to manage other users. The standard user (User) is born without permissions and depends on what the administrator grants. The super-administrator (super-admin) exists since installation, cannot be deleted or modified, and guarantees access to the system even if every other credential is lost.
| Type | Permissions | Recommended use |
|---|---|---|
| Administrator | All of them, implicit | Owners, managers and IT support; keep the smallest number possible |
| Standard user (User) | Only those granted by the administrator | Sellers, cashiers, warehouse staff and operational employees |
| Super-administrator | All of them, permanent and immutable | Backup and emergency access recovery |
The number of administrators should be as small as possible and limited to people of absolute trust, because each one can change prices, delete invoices and alter the global configuration. Their credentials should not be shared nor used for daily operations; the super-admin, for its part, is not meant for routine work: it exists as a backup to recover access when every other account fails.
Recommended profiles
Although there are no predefined roles, practice suggests typical combinations. The point-of-sale seller needs See sales, Do sales, the print permission, See inventory only to check stock, See and Do customer quotation, and See third parties; the seller should not have Create inventory, See Kardex, Do purchases or Do returns. The warehouse clerk needs See inventory, See and Do warehouse entries, See and Do transfers, See Kardex for consultation, See purchases and Receive purchases; on the other hand, the clerk should not make sales, buy or approve purchases, make Kardex plus or minus adjustments, or see accounts receivable or payable.
| Profile | Typical permissions | Permissions to avoid |
|---|---|---|
| Point-of-sale seller | See sales, Do sales, print permission, See inventory, See and Do customer quotation, See third parties | Create inventory, See Kardex, Do purchases, Do returns |
| Warehouse clerk | See inventory, See and Do warehouse entries, See and Do transfers, See Kardex, See purchases, Receive purchases | Do sales, Do or approve purchases, Kardex plus and minus, see accounts receivable or payable |
Behind every profile there is a control logic. The seller does not need to see the full Kardex to serve a customer, and should not process returns because that authorization belongs to supervisors; the warehouse clerk receives goods and moves them between warehouses, but does not adjust stock or approve purchases, so that the person who receives is not the one who corrects or authorizes the expense. Each process is thus split among different hands, and a mistake or abuse requires, by design, several people.
Before and after: a shrinkage case
A concrete example shows how the software behaves with an employee who lacks permissions. A warehouse assistant finds a batch of damaged products and needs to record the shrinkage to remove them from inventory, but the user only has permissions for the inventory module: the shrinkage module was never enabled for them.
| Moment | User permissions | What happens in the system |
|---|---|---|
| Before the change | See shrinkage and Do shrinkage not assigned | The assistant does not see the shrinkage option and cannot record the damaged batch; the inventory keeps showing products that are no longer usable |
| After the change | The administrator adds See shrinkage and Do shrinkage with a double click and presses Save permissions | The assistant enters the module, records the shrinkage and the stock is adjusted right away |
Notice that two permissions were needed: the See one, so the window exists for the assistant, and the Do one, so the recording can be executed. If only the Do had been enabled, the operation would still fail, because without the See there is no module to enter.
The user and their cost center
Every standard user is tied to a single cost center, that is, the warehouse or branch where they work: when the account is created in Kardex Tauro, the administrator must define which center it belongs to. At log-in, the system loads the information of that location, and the person cannot see or operate the data of other branches. The exception is the navigation permission Change cost center, granted cautiously to supervisors who must cover several branches.
The separation is strict from the very first log-in: when the user signs in, the system automatically loads the data of the assigned warehouse. A seller at North Branch cannot see the inventory, the sales or the third parties of South Branch or of the Central Warehouse, even though all the information lives in the same program. Permissions are therefore global for the user, but the reach of the data is limited by the cost center.
The cost center is defined when the user is created and can be changed later with the Edit user option; when that happens, the person stops seeing the previous warehouse and only works with the new one, so it is wise to confirm the change before applying it. The user screen also shows how many times each account has logged in: a user with zero log-ins or with access at strange hours may reveal a shared account or improper use, and deserves a review.
Why it matters in a small business
Well-configured permissions protect inventory from mistakes, internal theft and bad practices. Following the least privilege principle, every employee has only what the position requires and nothing more; with segregation of duties, no single person controls a whole process: the one who registers an entry does not approve a purchase, and the one at the cash register does not adjust stock. The software adds defense layers: authentication with personal credentials, user type, granular permissions, cost center restriction, print permission and a backup super-administrator. Every operation is also linked to the user who performed it, which eases auditing: when somebody leaves the company, it is better to remove their permissions than to delete their user, so the history of their movements is preserved.
Permissions are also protected by strong passwords: at least eight characters, a combination of uppercase letters, lowercase letters, numbers and symbols, no dates or personal names, and periodic changes, for example every ninety days. Every employee should have their own user and never share the password with a coworker, because a shared account breaks traceability: when two people operate with the same one, nobody knows who made each movement. On shared computers, it is wise to log out when the shift ends and to keep the automatic inactivity lock enabled. And if the credentials of every administrator are ever lost, the super-admin still exists as the last key: with it, a new administrator can be created or accounts reset, the incident documented and the policies reinforced.
Frequently asked questions
Can I assign permissions to an administrator user? No. The program does not allow individual permissions to be assigned to an administrator because they hold all of them implicitly; the assignment option is only available for standard (User) accounts.
What is the difference between See sales and Do sales? See sales lets the user open the window and view the information; Do sales lets the user create and process new sales. Selling requires both: the first grants access to the module and the second enables the operation.
Can a user work in several cost centers? Not by default: every standard user is assigned to a single cost center. To operate in several branches they need the special Change cost center permission, granted cautiously to supervisory staff.
Why do I need the print permission if I already have Do sales? They are independent permissions. Do sales processes the sale; the print permission controls printing across the whole system. Without it, invoices, tickets and reports cannot be printed from any module.
What happens if I create a user and assign no permissions? The person can log in, but sees no module, cannot create documents and cannot print anything. That is why, when creating a standard user, it is wise to enter Select permissions right away and enable the account.
Common situations and how to solve them
- A user forgot the password: if they remember the current one, they can change it themselves through the button with their name in the side panel; otherwise, the administrator resets it from Configuration and the user changes it again on the next log-in.
- Temporary permission: for example, processing returns while the supervisor is on vacation. The permission is granted, the start and end dates are documented, a reminder is scheduled and the permission is removed when the period ends.
- Access to several branches: the user asks the administrator for the Change cost center permission, intended for supervisory staff.
- "I cannot do something": usually one specific permission is missing. The administrator reviews the user's list and checks whether the See, the Do or the print permission is missing.
Setting permissions correctly from day one prevents headaches later. Define by position what each person must see and do, document the assignments, review the lists every few months and react immediately when someone changes roles. Security is not a product: it is a continuous process.