Skip to content
Roles, permissions and audit

Access control that follows your org chart

1flux is a role-based access control ERP: roles built from more than 100 permissions, reporting lines and entity limits decide who sees and does what, down to the database.

In short

1flux gives every person exactly the access their job needs. Custom roles combine more than 100 permissions in 15 module groups. A reporting hierarchy with solid and dotted lines decides whose records each person sees. Members can be limited to specific legal entities when you invite them, and buyers, storekeepers and accountants work in separate permission lanes. Underneath, each customer's data is isolated inside the database with PostgreSQL row-level security.

Live view

Restricted, the default: each person sees their own records and their team’s. Dotted lines add view-only or full access.
View as text
  1. Open: every member can see all companies, contacts, deals and tasks. Tariq Mahmoud, head of sales, sees everyone’s records.
  2. Restricted, the default for new workspaces: Tariq sees his own records and those of Imran Raza and Maria Santos, who report to him. Fahad Al Otaibi reports to Khalid Al Shehri on a solid line and to Tariq on a dotted line set to View only, so Tariq can view Fahad’s records but not change them. Yousef’s and Khalid’s records are not visible to him.
Sound familiar?

The problem: access that doesn’t match the job

In most growing companies, access is all or nothing.

  • “Our field salespeople can browse, and export, the whole customer list.”

  • “Storekeepers see purchase and selling prices on the pick list.”

  • “The person who raises a purchase can also approve it and post the invoice.”

  • “A salesperson left, and their customers, deals and tasks sat orphaned under their name.”

  • “Nobody can say who changed a customer’s credit terms, or when.”

Four layers

How does a role-based access control ERP decide who sees what?

1flux decides who sees what in four layers: roles, record visibility, entity access and database isolation. Role-based access control means people get permissions through the roles they hold, not one by one. The other three layers answer the questions roles can’t.

  • Roles and permissions answer “What can this person do?” with custom roles built from more than 100 permissions.
  • Record visibility answers “Whose records can they see?”: Open or Restricted, following solid and dotted reporting lines.
  • Entity access answers “Which companies in the group can they work in?”: all entities, or selected entities only, set when you invite them.
  • Database isolation answers “Can another customer’s data ever reach them?” with PostgreSQL row-level security.
  1. What can this person do?

    • Roles and permissionsCustom roles from more than 100 permissions
  2. Whose records can they see?

    • Record visibilityOpen or Restricted, along reporting lines
  3. Which companies can they work in?

    • Entity accessAll entities, or selected entities only
  4. Can another customer’s data reach them?

    • Row-level securityEach customer isolated inside PostgreSQL
Four layers decide what each person can do and see. The last one sits inside the database.
Roles

Roles built from more than 100 permissions

Every workspace starts with three roles: Admin, which always has every enabled permission, Employee, the default for new members, and Submittal coordinator. From there you create your own, such as “Storekeeper”, “Buyer” or “Accounts”, and give a person more than one role. Permissions from every selected role are combined.

The permissions, 101 of them assignable, sit in 15 module groups: Access Control, CRM, Customers, Daily Updates, Items & Catalog, Tasks, Workflows, Calendar, Quotations, Inventory, Knowledge, Document Studio, Procurement, Sales orders and Accounting.

  • A non-admin can’t grant a permission they don’t hold themselves.
  • If two admins edit the same role at once, the second save is refused rather than silently overwriting the first.
  • Every change to roles and role assignments is recorded.
Build roles such as Storekeeper from more than 100 permissions in 15 module groups. A person can hold several roles.
Record visibility

Managers see their team’s records; dotted lines add more

1flux lets you choose whether everyone sees everything, or each person sees their own records and their team’s.

  • Open: every member can see all CRM records, such as companies, contacts, deals and tasks.
  • Restricted: each person sees the records they own plus those of the people who report to them. New workspaces start Restricted.

The reporting hierarchy decides who “the team” is:

  • Solid lines form the management tree, with one manager per person and as many levels as you need.
  • Dotted lines add access across the tree: View only, or Full (edit and reassign).
  • View all records and Manage all records are permissions you can give to named roles, such as a sales director, to see or manage everything.

CRM reports follow the same lines, so a manager’s reports cover their own team automatically. On each company and contact record, the Access tab shows exactly who can see it and why.

  1. Solid line: one manager per person.
  2. Dotted line: View only, or Full.
Each person has one manager on a solid line. A dotted line adds view-only or full access across teams.
Lookup-only

Lookup-only access for field sales

Salespeople need to link their deals, projects and quotations to the right customer. They don’t need to browse the whole customer list to do it. 1flux separates the two:

  • Open Companies module shows the Companies tab and lets people browse company records.
  • Find companies to link records to lets people pick their assigned companies from dropdowns, without opening the Companies module.

Each company has one primary salesperson plus additional salespeople, up to 20 in all. Tagging someone on a company’s sales team gives them access to that company and its deals and quotations, with no separate sharing step.

  1. No browsing the customer list.
  2. Still links their own deals and quotations.
Sales reps can link deals and quotations to their assigned companies without opening the Companies tab.
Segregation of duties

Separate lanes for buyers, stores and accounts

Segregation of duties is built into how 1flux splits its permissions: each step of procure to pay sits in its own lane.

Live view

Each step of procure to pay needs its own permission, so no one person raises, approves, receives and books the same purchase.
View as text
  1. Requester: raises a requisition and submits it.
  2. Approver: approves the requisition. Approval is its own permission.
  3. Buyer: compares supplier offers and awards each line, with a reason.
  4. Buyer: issues purchase order PO-2026-0012. Award, issue and add prices are separate permissions.
  5. Storekeeper: checks the delivery in on a goods received note (GRN), here Checked with comments. Nothing posts.
  6. GRN approver: approves the note checked with comments. Recording a GRN and approving one are separate permissions.
  7. Receiving: posts goods receipt report GRR-2026-0074. Stock and the journal post: Dr Inventory, Cr GRNI.
  8. Accounts: records purchase invoice PI-2026-0033, which posts Dr GRNI and input VAT, Cr accounts payable.
  9. Pick and dispatch screens never receive prices or credit terms.
  • Purchasing and receiving: requester, approver, award, issue, add prices, record a goods received note, approve a goods received note checked with comments, post the goods receipt report, and record or void a purchase invoice are separate permissions. See 1flux Purchasing.
  • Price-free warehouse: pick and dispatch screens never receive prices or credit terms from the server. Storekeepers can’t see what they were never sent.
  • Accounting: preparing a journal and posting it are separate permissions.
  • Credit terms: a maximum credit-days cap per customer is enforced on sales orders, and only people with the override permission can go past it.
People changes

Offboard a leaver in one step

When someone leaves, Reassign and deactivate does the whole handover in one step. It moves their companies, deals and tasks to a colleague, moves their direct reports to a new manager and marks them inactive.

Disable user ends a person’s sessions immediately and stops them signing in. Invitations to new members expire after 7 days if they’re not accepted.

Disable user ends a person’s sessions at once. Reassign and deactivate hands over their records and reports in one step.
Isolation

Isolation inside the database, not just the app

1flux isolates each customer's data inside the database itself with PostgreSQL row-level security, not only in application code. If the context that identifies your workspace is missing, the database returns nothing rather than everything.

  • No silent overwrites

    If two people edit the same record, the second save is refused with a “refresh and try again” message.

  • Field-level security

    Hiding a field, or making it read-only, per role or per person on companies, contacts and items is available, configured with our team.

  • Files

    Download links are signed and expire after 5 minutes, and uploads are checked by file signature.

  • In transit

    HTTPS everywhere.

Audit trail

A readable record of who did what

1flux keeps an audit trail where people actually look for it, on the record:

  • an Activity tab on companies, contacts, items and suppliers;
  • plain-sentence activity on every procurement document;
  • a per-entry audit trail on manual journals;
  • stage history on deals, tasks and sales orders;
  • a record of access changes: roles, member roles, reporting lines, visibility mode, and disabled or offboarded members.
Stage history on a deal: moves, send-backs and approvals with who, when and why.
Set-up

How do you set up access in 1flux?

Five steps, all in Settings. No code, and no separate admin tool.

  1. Invite people

    From Settings → Members & access, with their email, roles and legal-entity access.

  2. Set their manager

    With Set manager…, and add dotted lines where people work across teams.

  3. Choose record visibility

    Open or Restricted, under Settings → General.

  4. Create custom roles

    Under Settings → Roles & permissions, where the defaults don’t fit.

  5. Offboard cleanly

    With Reassign and deactivate when someone leaves.

One flow

Connected to the rest of 1flux

Access control is shared by every 1flux app, so one set of roles and reporting lines applies wherever your teams sell, buy, stock and account.

  1. Access controlApprovers are members
  2. Workflows and approvalsEntity access
  3. Multi-entitySales teams
  4. 1flux CRMPermission lanes
  5. Purchasing

Approvers in workflows and approvals are chosen members, entity access is part of multi-entity, and the CRM’s sales-team model drives who sees which customers in 1flux CRM.

Who it’s for

Who is 1flux access control for?

Anyone who needs the right people to see the right records, without writing code.

  • IT and workspace admins

    Who need precise access without writing code.

  • Owners

    Who want customer lists, prices and the books seen only by the right people.

  • Finance controllers

    Who need preparation and posting, and requesting and approving, kept apart.

FAQ

Questions, answered

Still deciding? Talk to sales

Can salespeople see only their own customers?

Yes. With record visibility set to Restricted, each person in 1flux sees the companies, contacts, deals and tasks they own, plus those of the people who report to them. Dotted reporting lines add view-only or full access across teams. Roles you trust, such as a sales director, can hold View all records or Manage all records. New workspaces start Restricted.

Can I hide prices from warehouse staff?

Yes. 1flux's pick and dispatch screens never receive prices or credit terms from the server, so storekeepers work from quantities, items and delivery details only. Because the data is never sent to their screen, it can't be revealed by a setting or a browser tool. Purchasing and receiving also split pricing, receiving and posting into separate permissions.

Can I create my own roles?

Yes. Admins create custom roles in 1flux from more than 100 permissions in 15 module groups, and a person can hold several roles, with their permissions combined. Three roles are set up for you: Admin, Employee and Submittal coordinator. A non-admin can't grant a permission they don't hold, and every change to a role is recorded.

What happens to a leaver's records?

1flux hands them over in one step. Reassign and deactivate moves the leaver's companies, deals and tasks to a colleague, moves their direct reports to a new manager and marks them inactive. Disable user on its own ends their sessions immediately and stops them signing in, if you need to cut access before the handover.

Does 1flux keep an audit log?

Yes. 1flux keeps it on the records themselves: an Activity tab on companies, contacts, items and suppliers, plain-sentence activity on procurement documents, a per-entry audit trail on manual journals and stage history on deals, tasks and sales orders. Access changes are recorded too, including edits to roles, member roles, reporting lines and record visibility.

Can I control access to individual fields?

Yes. Field-level security in 1flux is available, configured with our team: a field can be hidden or made read-only for a role or a person, on companies, contacts and items. Hidden fields are left out of screens and exports. It works alongside roles and record visibility, so each person sees the right records and the right fields on them.

How is our data kept separate from other customers' data?

1flux isolates each customer's data inside the database with PostgreSQL row-level security, not just in application code. Every request runs with your workspace's context, and if that context is missing, the database returns nothing. Files are served through signed links that expire after 5 minutes. See security at 1flux for backups and the rest of the picture.

Book a demo

Set up access the way your company is actually organised

Bring your org chart to a demo and we'll show you the roles, reporting lines and visibility it maps to.

Last updated