Operations

Who sees what: roles, permissions and MFA

Every user has a role, and the role decides which modules they open, whether they see prices and costs, whether they can export, and how much they can quote or spend before an approver is needed.

01

Sales can see the cost of everything

Before

Your margin is your business.

With Zigaflow

Create a role in Team Settings, tick the option to hide prices and costs, and assign it. Users with that role cannot see costs or prices and cannot add one-off items.

02

Everyone sees everything or nothing

Before

The old system had two settings: admin and not. So production staff could see invoices, or could not see the job.

With Zigaflow

Roles set control for a whole module or for specific functions within it, and users are given access to modules individually with Assign Modules. Reporting access and delete rights are part of the role.

03

The leaver who can still log in

Before

A user left on Friday.

With Zigaflow

Archive the user to free their license and stop new logins, then click Revoke to log them out on their next page load.

What you get

  • Roles control access to whole modules or to specific functions within them
  • Hide prices and/or costs from a role, and stop it adding one-off items
  • Untick Export per module so a role cannot export data
  • Restrict internal attachments so a role cannot open documents such as costed quotes
  • Give non-admin roles only the bulk actions their job needs
  • Quotation and purchase order approval limits set per role
  • Multi-factor authentication on login; an admin can temporarily disable it for a locked-out user
  • Archive leavers to free the license, and revoke a live session immediately

How it works

  1. Create a roleCog, Team Settings, Create New Role.
  2. Set what the role can see and doTick hide prices and costs, untick Export on the modules to protect, restrict internal attachments, choose the bulk actions, and set the quotation and PO approval limits created under Internal Approvals.
  3. Assign users and modulesEdit each team member and set their role, then use Assign Modules to give them the modules they work in.
  4. Manage mfaIf a user cannot get their code, an admin opens their profile in Manage Team Members, chooses Disable Two Factor Authentication and confirms with the admin's own password.
  5. Handle leaversArchive the account to free the license, tick to keep the leaver in reporting dropdowns if needed, and click Revoke against their name to end any live session.
How do roles and permissions work in Zigaflow?

Access in Zigaflow is decided by two things: the modules a user has been assigned, and the role they hold. Assign Modules, in Team Settings, gives a user the quotations, jobs, purchase orders, invoices, stock or other modules they work in. Their role then controls what they can do inside each one. A role can grant a whole module or only specific functions within it, decide whether the user sees prices and costs and can add one-off items, whether they can export data from each module, whether they can view internal attachments such as costed quotes, which bulk actions they can run, and which quotation and purchase order approval limits apply to them. The two system roles, Admin and User, cannot be edited; you create the roles your business needs, assign them, and users pick up changes when they next log in.

Authentication uses multi-factor authentication. Users set it up at first login and again after an admin changes their login email. If someone is locked out, an admin can temporarily disable two-factor authentication from the user's profile, confirming with the admin's own password, and the user re-enrols on their next login. Only admins can do this.

When someone leaves, archive their account to free the license and stop new logins, keeping them in reporting dropdowns if you want historical reports to still name them, and click Revoke to end any session that is still open. Archived users can be restored later and will need modules assigned again. Combined with approvals, which hold quotes and purchase orders over a role's limits until an approver signs them off, and final statuses only an admin can undo, roles let you widen who uses the system without widening who can see your margin or change a completed record.

Frequently asked

Ready to get started? Try it free.

14-day free trial on all plans. No credit card required.

Start free trialBook a demo