ACL & Permissions

اے سی ایل اور اجازتیں

ACL & Permissions

ACL (Access Control List) lets you precisely define what each staff member can see and do in RentOyee. Apply the principle of least privilege — give each user only the permissions their job function requires, nothing more.

Permission Structure

Every permission is a combination of a Module and an Action:

  • Modules: customers, vehicles, bookings, payments, drivers, reports, settings, users, documents, sessions, logs, blacklist, fleet, intelligence
  • Actions: view, create, edit, delete, export, verify

Example: A staff member with customers.view but without customers.edit can see customer profiles but cannot change any customer data.

Pre-Built Roles

RoleAccess Level
Owner / Super AdminFull access to everything including settings, users, and billing
ManagerAll operational modules; excludes system settings and user management
ReceptionistCreate and view bookings and customers; no access to reports, payments, or settings
AccountantView and record payments; view reports; read-only access to bookings and customers
DriverView only their own assigned bookings; no access to customers, payments, or reports

Creating a Custom Role

1Go to ACL → Roles

Navigate to Admin → ACL → Roles from the sidebar.

2Create New Role

Click "Add Role". Give it a clear, descriptive name such as "Senior Receptionist" or "Fleet Supervisor".

3Assign Permissions

Check the permission checkboxes for each module/action combination this role should have. You can enable entire modules or granular individual actions.

4Save & Assign

Save the role. Go to Users, edit the relevant staff member, and select this new role from the dropdown.

Security Best Practice:

Review all user roles at least once every quarter. Remove permissions that are no longer needed. When a staff member changes job function, update their role immediately rather than accumulating unnecessary access.

اے سی ایل اور اجازتیں

ACL آپ کو یہ کنٹرول کرنے دیتا ہے کہ ہر عملے کا رکن RentOyee میں کیا دیکھ اور کر سکتا ہے۔ کم سے کم اجازت کا اصول اپنائیں۔

اجازت کی ساخت

  • ماڈیولز: گاہک، گاڑیاں، بکنگز، ادائیگیاں، رپورٹس، ترتیبات، صارفین
  • اعمال: دیکھنا، بنانا، ترمیم، حذف، ایکسپورٹ

پہلے سے بنے کردار

  • مالک — سب تک مکمل رسائی
  • مینیجر — سسٹم ترتیبات اور صارف انتظام کے علاوہ سب
  • ریسپشنسٹ — بکنگز اور گاہک بنانا/دیکھنا
  • اکاؤنٹنٹ — ادائیگیاں اور رپورٹس
  • ڈرائیور — صرف تفویض شدہ بکنگز دیکھنا

کسٹم کردار بنانے کا طریقہ

1Admin → ACL → Roles
2نیا کردار بنائیں

واضح نام دیں، مثلاً "سینئر ریسپشنسٹ"۔

3اجازتیں مقرر کریں

ہر ماڈیول/عمل کے لیے چیک باکس منتخب کریں۔

4محفوظ کریں اور تفویض کریں

Users → صارف → اس کردار کو منتخب کریں۔

بہترین عمل:

ہر 3 ماہ بعد تمام صارفین کے کردار کا جائزہ لیں اور غیر ضروری اجازتیں ہٹائیں۔