Roles & action permissions
Design permissions around job responsibilities, not broad module access.
Environment-aware guidance
Exact buttons and available actions can vary with company plan, role permissions and enabled capabilities. Stoneware workflow rules and server-side checks remain authoritative.
Sales
Sales should not automatically adjust inventory, approve POs, view landed cost, approve stocktakes or issue credits.
Warehouse
Warehouse should not automatically accept/decline commercial quotes or perform financial adjustments.
API
Operational API authority is token scope ∩ employee current permission, with company/package/module checks on every request.
Was this useful?