USER AND PERMISSION MANAGEMENT

GENERAL DESCRIPTION

The window of User Permissions is the security center of Kardex Tauro. Unlike other systems, there are no predefined "roles" here (such as Salesperson or Warehouse Keeper). The system uses a model of granular permissions, which allows you to grant exactly the capabilities that each person needs, no more, no less.

KEY CONCEPTS

1. The "VIEW" and "DO" Rule

For a user to be able to perform a complete task, they generally need two different permissions:

  • VIEW (Query): It allows them to open the window and look at the information.
  • DO (Operation): It allows them to create, edit or execute actions in that window.
  • Example: To process a sale, the user needs to have both "View Sales" and "Do Sales" assigned.

2. User Types

  • Administrator (Admin): It has all permissions by default. It can access the Configuration window and manage the other users. It is not necessary (nor possible) to assign it individual permissions.
  • Standard User (User): When creating it, has no permissions. The administrator must manually assign what they can and cannot do.
  • Super-Administrator: A master backup user that comes with the system, cannot be deleted and guarantees total access in case of emergency.

3. Restriction by Cost Center

Each user is tied to a single warehouse or branch (Cost Center). A salesperson from "North Branch" will not be able to see or operate in "South Branch", guaranteeing the security and segregation of information between locations.

4. Print Permission

It is a unique and independent permission (cross-cutting). A user may have permissions to create invoices, but if they do not have the "Print permission", they will not be able to generate any physical document, ticket or PDF in the entire system.

HOW TO ASSIGN PERMISSIONS

The window is divided into two lists:

  1. Available Permissions (Left): The full catalog of system options.
  2. Assigned Permissions (Right): What the user currently has enabled.

Procedure:

  1. Select the user in the main list.
  2. Search for the permission in the left list.
  3. Move the permission to the right list by double-click onto it (or using the central arrow buttons).
  4. Critical Step: Click the button "Save permissions" at the bottom. If you close the window without saving, the changes will be lost.

SPECIAL PERMISSIONS

  • Change cost center: By default, users are locked to their assigned warehouse. If a supervisor or manager needs to move between branches, you must assign them this special permission.

SECURITY RECOMMENDATIONS

  • Principle of Least Privilege: Assign only what is strictly necessary for the employee to perform their daily work.
  • Do not share users: Each employee must have their own user. The Kardex records who made each movement, so sharing users invalidates traceability.
  • Segregation of duties: Avoid the same person having crossed critical permissions (for example, that the same user can "Do purchases" and "Approve purchases").

Created with HelpNDoc's Personal Edition: Achieve professional documentation results with a help authoring tool