> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://support.robaws.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Setting up the permissions of your users

A [user](https://support.robaws.com/en/article/adding-a-new-user-frez0i/) is given a **user role** to determine which permissions that user receives.
The purpose of the user role is to make sure that users only have access to the functions they need to do their work properly.

**Example:**
*A project leader may only have access to his own projects, but he may not see the projects of his colleagues. He may not see the sales invoices and incoming invoices in his environment either. A specific role 'project leader' is created for this.*

*Jump straight to:*

* [creating a user role](#2-creating-a-user-role)
* [what you set on the role](#2-what-you-set-on-the-user-role)
* [permissions per module](#2-permissions)
* [sharing a project](#2-sharing-a-project)

| You cannot customise the menu on the left (change the order), but you can use the user roles to decide which modules are shown per user, and which ones therefore do not appear.


## Creating a user role

You create a user role via **your name (top right) > users > action button userroles**.
You then link a user role to a [user](https://support.robaws.com/en/article/adding-a-new-user-frez0i/) when you create or change that user.

If you work with **teams**, you create those via **your name (top right) > users > action button teams**. You can read more about this in [Creating teams for use with the dayplanning](https://support.robaws.com/en/article/creating-teams-for-use-in-the-dayplanning-uez1su/).

||| Changes to user roles or permissions only become active once the user **logs in again**. If you are testing a change, first ask the user concerned to log out and log back in.


## What you set on the user role

The user role consists of two parts.

**On the role itself** you fill in:

| Setting | Explanation |
| ---- | ---- |
| Name | The name of the role, for example 'project leader' or 'invoicing'. |
| Allowed IP's | Restrict logging in to specific IP addresses. If you leave this empty, the user can log in from anywhere. |
| Admin | Gives access to the settings of your environment. |
| Manage users | Gives access to the management of the users and the user roles. |
| Hide sale prices | **If you tick this,** Robaws **hides** the sales prices on the work orders for this user. |
| Hide financial info and analyses | **If you tick this,** Robaws **hides** the financial info of a project as well as the analysis action buttons in the overview screens. See below. |
| Restrict company access | Restrict the user to one or more [companies](https://support.robaws.com/en/article/adding-a-company-1w61tjm/) in your environment. If you leave this empty, the user sees all companies. |

|| Pay close attention to the two 'hide' settings: they take something **away** instead of granting something. A role for which they are switched off therefore sees everything.

**In the permissions matrix** you determine per module:

1. whether the user sees the module
2. the permissions to **read**
3. the permissions to **change**
4. the permissions to **delete**

### Hide financial info and analyses

This setting goes further than just the project. If you switch it on, the following disappear for that user:

* the financial info and the [recalculation](https://support.robaws.com/en/article/project-recalculation-1sitd2t/) on the project
* the action button **analysis** in the overview screens of, amongst others, quotations, projects, work orders, supply orders, orders, sales invoices, incoming invoices, items and time registration — see for example [Quotations | Analysis](https://support.robaws.com/en/article/quotations-analysis-18mg9ns/)
* the financial PDFs and Excel exports of a project

|| The data is genuinely refused by Robaws, not merely hidden on screen. A user therefore cannot get around it via an export or a PDF.


## Permissions

You can set the access to a module so that **all** documents, the documents of a **team**, or only the user's **own** documents are used. For the incoming invoices there is also the scope **all except confidential**.

Below is an explanation of the permissions per module.

||| These permissions are described for the permissions for 'own'. The permissions for 'team' are the same, with the difference that they apply to all members of your team.

| Module | Own |
| ---- | ---- |
| Customers | Documents on which you are the assignee. |
| Quotation & change orders | Documents on which you are the assignee OR on which you are the project leader or executor of the linked project. |
| Orders | Documents on which you are the assignee OR on which you are the project leader or executor of the linked project. |
| Projects | Documents on which you are the project leader or executor. |
| Work orders | Documents on which you are the assignee OR on which you are the project leader or executor of the linked project OR on which you have registered a number of hours worked as an employee. |
| Invoices | Documents on which you are the assignee OR on which you are the project leader or executor of one or more projects assigned to one or more invoice lines. |
| Supply orders | Documents on which you are the assignee OR on which you are the project leader or executor of one or more projects assigned to one or more supply order lines. |
| Progress claims | Documents on which you are the assignee OR on which you are the project leader or executor of the linked project. |
| Delivery notes | Documents on which you are the assignee OR on which you are the project leader or executor of the linked project. |
| Incoming invoices | Documents on which you are the assignee OR on which you are the project leader or executor of one or more projects assigned to one or more invoice lines. |
| Subscriptions | Documents on which you are the assignee OR on which you are the project leader or executor of one or more projects assigned to one or more subscription lines. |
| Rental tickets | Documents on which you are the assignee OR on which you are the project leader or executor of the linked project. |

| **Incoming invoices** have two particularities. An incoming invoice that is marked as **confidential** is not visible with 'own' and 'team' — for that you need the scope 'all'. And if you are part of the [approval flow](https://support.robaws.com/en/article/acceptance-flow-c1qga3/) of an incoming invoice, you always see it, regardless of your scope.

### Dayplanning, items and time registration

For these three modules the scopes 'team' and 'own' do not exist: there you choose between all or nothing. If you want to let someone only consult the **dayplanning**, set the permissions for read to 'all' and the permissions for change and delete to 'nothing'. That gives you a read-only dayplanning.


## Sharing a project

It is possible to share a project with a user, regardless of which user role he or she has.
When a project is shared with a user, that user can only see what applies within his user role.

*Example:*
*The user has the user role 'invoicing' and only has access to the modules invoices, work orders, orders and incoming invoices.*
*When a project is shared with this user, he or she will only be able to consult the invoices, work orders, orders and incoming invoices of this project.*

To share a project, click the action button **share object** at the top of the project. You can then select a user with whom you want to share the project.