Overview
Roles determine which areas of Affinity a user can access and the actions they can perform.
Affinity includes several predefined roles. Organisations can also create custom roles tailored to the responsibilities of different teams and users.
Access to role management is itself permission-controlled. Only users whose role includes access to Admin → User Roles can view and manage roles.
Affinity roles and custom roles
On the Roles page, each role is identified as one of the following:
- Affinity — a predefined system role supplied with Affinity.
- Custom — a role created by your organisation.
Affinity roles can be viewed but cannot be edited or deleted. They can, however, be duplicated to provide a starting point for a new custom role.
The standard roles are:
- Manager — full access to Affinity’s features.
- Admin — broad administrative and operational access, with restrictions around banking, certain financial information, user administration and some deletion actions.
- System — primarily read-only access, with limited creation or update permissions in selected areas.
The precise permissions assigned to a role can be reviewed by opening it from the Roles page.
Understanding permissions
Permissions are grouped by areas such as Property, Tenant, Supplier, Work Orders, Banking, Reports and Admin.
Depending on the feature, a role may have the following permissions:
- Access — view or open the feature.
- Create — add new records.
- Update — edit existing records.
- Delete — delete records.
A green tick indicates that permission is granted. A red cross indicates that it is denied. A grey symbol means that the action is not applicable to that feature.
Some permissions depend on a parent permission. When configuring a role, ensure the user has access to the main area as well as the required sub-features.
Viewing existing roles
- Open Admin.
- Select Settings.
- Under User Management, select Roles.
- Select a role name to view its description and permissions.
The Roles page also shows whether each role is an Affinity or Custom role and how many users are currently assigned to it. Select the number of users to view the corresponding user list.
Creating a custom role
- Go to Admin → Settings → Roles.
- Select Add Role.
- Enter a unique Role Name.
- Optionally enter a description explaining who should use the role.
- Expand each permission section and select the required Access, Create, Update and Delete permissions.
- Select Add Role.
Use clear role names and descriptions, such as “Property Officer” or “Finance Read Only”, so that administrators can assign them consistently.
Duplicating a role
Duplicating an existing role is often the quickest way to create a custom role with similar permissions.
- Go to Admin → Settings → Roles.
- Open the role you want to use as a starting point.
- Select Options → Duplicate Role.
- Enter a suitable name and description for the new role.
- Review and adjust its permissions.
- Select Add Role.
Manager, Admin, System and existing custom roles can be duplicated. The Account Owner role cannot be duplicated.
Always review all permissions before saving a duplicated role. The new role initially inherits the permissions of its source role.
Editing a custom role
- Go to Admin → Settings → Roles.
- Open the custom role.
- Select Options → Edit Role.
- Update the name, description or permissions.
- Select Update Role.
Changes apply to users assigned to that role. Before removing important permissions, check how many users are assigned and consider how the change may affect their work.
Affinity’s predefined roles cannot be edited.
Assigning a role to a user
For an existing user:
- Go to Admin → Settings → Users.
- Open the user’s record.
- Select the option to edit the user.
- Choose the required role from the Role list.
- Review the user’s associated branches.
- Select Update User.
A role is also selected when creating a new user.
Role permissions determine what the user can do, while associated branches determine which organisational branches and related records the user can work with. Both settings should be reviewed when configuring access.
The Account Owner role is managed separately and cannot be assigned through the normal Role list.
Deleting a custom role
A custom role can be deleted only when no active users are assigned to it.
- Reassign any active users to another suitable role.
- Open the custom role.
- Select Options → Delete Role.
- Confirm the deletion.
Affinity’s predefined roles cannot be deleted.
Recommended practice
- Follow the principle of least privilege: grant only the access required for the user’s duties.
- Prefer custom roles over assigning Manager access solely to unlock one feature.
- Use read-only access where users need visibility but should not change records.
- Restrict financial, banking, deletion and user-management permissions carefully.
- Review role membership and permissions regularly.
- Give roles descriptive names and document their intended audience.
- Test a new role with a suitable user account before assigning it widely.
Comments
0 comments
Please sign in to leave a comment.