Admin Manual

Roles & Permissions

Kanso controls access with a set of quality-management roles plus fine-grained, per-user, per-module permissions layered on top. This page explains how the two work together and how to grant the right access to each person.

How access control works

Access in Kanso has two layers. The first is a set of quality-management roles that reflect the way an ISO 9001 quality system and a Lean Six Sigma program are actually run. The second is a fine-grained layer of per-user, per-module permissions that sits on top of those roles, letting you tune exactly what each individual can see and do.

Because permissions are resolved per user and per module, two people who share the same role can still end up with different access if you have refined their individual settings. The role gives you a sensible starting point; the per-module permissions give you the precision.

View and edit levels

Each module can be granted at one of two levels. Choose the level that matches what the person needs to do in that area of the platform.

ViewRead-only access. The person can open and read the module but cannot change anything in it.
EditFull access to the module, allowing the person to create and change records within it.

Granting access module by module means you can, for example, let someone edit documents while giving them view-only access to another area, all for the same person.

Enforced in the UI and on the server

Permissions are enforced in two places, not one. In the interface, a permission gate hides or disables anything a user is not allowed to access, so people simply do not see controls they cannot use.

Just as importantly, sensitive actions are also checked on the server. Operations such as approving or signing a record are verified server-side rather than merely hidden in the UI, so access cannot be bypassed by working around the interface.

Note:Because approvals and signatures are validated server-side, a user without the right permission cannot complete those actions even if a control were somehow reached.

Using role presets

To make setup quick, Kanso provides role presets. Applying a preset grants a sensible default set of permissions in one step, after which you can refine the access per person to match their real responsibilities.

  1. Assign a role preset

    Give the person a role preset to establish their baseline access across modules.
  2. Refine per module

    Adjust individual modules to view or edit as needed so the person has exactly the access their work requires.
  3. Confirm sensitive actions

    Review who can perform approvals and signatures, since these are enforced server-side.
Tip:Start from the closest preset, then tighten or loosen individual modules rather than building each person's access from scratch.