ACL & Permissions
اے سی ایل اور اجازتیں
ACL & Permissions
ACL (Access Control List) lets you precisely define what each staff member can see and do in RentOyee. Apply the principle of least privilege — give each user only the permissions their job function requires, nothing more.
Permission Structure
Every permission is a combination of a Module and an Action:
- Modules: customers, vehicles, bookings, payments, drivers, reports, settings, users, documents, sessions, logs, blacklist, fleet, intelligence
- Actions: view, create, edit, delete, export, verify
Example: A staff member with customers.view but without customers.edit can see customer profiles but cannot change any customer data.
Pre-Built Roles
| Role | Access Level |
|---|---|
| Owner / Super Admin | Full access to everything including settings, users, and billing |
| Manager | All operational modules; excludes system settings and user management |
| Receptionist | Create and view bookings and customers; no access to reports, payments, or settings |
| Accountant | View and record payments; view reports; read-only access to bookings and customers |
| Driver | View only their own assigned bookings; no access to customers, payments, or reports |
Creating a Custom Role
Navigate to Admin → ACL → Roles from the sidebar.
Click "Add Role". Give it a clear, descriptive name such as "Senior Receptionist" or "Fleet Supervisor".
Check the permission checkboxes for each module/action combination this role should have. You can enable entire modules or granular individual actions.
Save the role. Go to Users, edit the relevant staff member, and select this new role from the dropdown.
Review all user roles at least once every quarter. Remove permissions that are no longer needed. When a staff member changes job function, update their role immediately rather than accumulating unnecessary access.
اے سی ایل اور اجازتیں
ACL آپ کو یہ کنٹرول کرنے دیتا ہے کہ ہر عملے کا رکن RentOyee میں کیا دیکھ اور کر سکتا ہے۔ کم سے کم اجازت کا اصول اپنائیں۔
اجازت کی ساخت
- ماڈیولز: گاہک، گاڑیاں، بکنگز، ادائیگیاں، رپورٹس، ترتیبات، صارفین
- اعمال: دیکھنا، بنانا، ترمیم، حذف، ایکسپورٹ
پہلے سے بنے کردار
- مالک — سب تک مکمل رسائی
- مینیجر — سسٹم ترتیبات اور صارف انتظام کے علاوہ سب
- ریسپشنسٹ — بکنگز اور گاہک بنانا/دیکھنا
- اکاؤنٹنٹ — ادائیگیاں اور رپورٹس
- ڈرائیور — صرف تفویض شدہ بکنگز دیکھنا
کسٹم کردار بنانے کا طریقہ
واضح نام دیں، مثلاً "سینئر ریسپشنسٹ"۔
ہر ماڈیول/عمل کے لیے چیک باکس منتخب کریں۔
Users → صارف → اس کردار کو منتخب کریں۔
ہر 3 ماہ بعد تمام صارفین کے کردار کا جائزہ لیں اور غیر ضروری اجازتیں ہٹائیں۔