Permissions
Overview
Permissions are fine-grained access controls that can be assigned directly to users or to roles. In most cases, access is controlled via roles rather than individual permissions — see Roles & Permissions for the role reference.
Navigate to Settings → Permissions to view and manage permissions.
Managing Permissions
Permissions can be created, assigned to roles, and revoked. When a permission is deleted, it is automatically removed from any users or roles it was assigned to.
Widget Permissions
Dashboard widget access is also controlled by permissions. Each widget has a corresponding widget:{key} permission (e.g. widget:orders-list-pending). These are automatically assigned to roles during initial setup.
To give a user access to a specific widget outside their normal role, assign them the relevant widget: permission directly. To remove a widget from all users in a role, revoke the permission from that role.