What you can see and do in Pyron comes down to the role or roles you hold. A role is a bundle of permissions that an administrator assigns to a person, and it decides which actions and screens are open to you. Specific parts of the directory and pages can also be shared with you one at a time, which access and sharing covers separately.
Roles bundle permissions
A role is a named set of permissions — a shorthand for everything a particular kind of person needs to do their job. Rather than granting abilities one at a time, an administrator gives someone a role, and that person receives every permission the role carries at once.
Your organisation defines its own roles to match how it works. A common setup has an administrator role with full access to everything, alongside narrower roles — a field role, say, that can view the directory and create entries but little else. The exact roles, and what each one allows, are up to your organisation.
A person can hold more than one role. When they do, their permissions add together: they can do anything any of their roles allows. Roles only grant abilities — holding one never takes an ability away.
Administrators create roles, adjust what each one allows, and assign them to people from the policy area. See Roles for how roles are built and Members for assigning them to people.
Permissions cover actions and screens
Permissions work at two levels, and together they shape what appears on screen.
The first level is actions — the things you can do to the information in Pyron. Creating an entry, editing part of the directory, deleting something, or running a report are each a separate action, and each one is governed by its own permission. Hold the permission and the button is there to use; lack it and the button is not shown at all.
The second level is screens — whole areas of the product, such as the reports area or the administration pages. Access to a screen decides whether its link appears in your navigation. If a screen is not open to you, you see no way to reach it.
Because Pyron hides what you cannot use rather than greying it out, two people with different roles can open the same app and see different menus and buttons. Nothing is broken — each person sees the set that matches their permissions.
What this means day to day
Most of the time, permissions stay out of your way: you see the screens, buttons and information your role allows, and the rest is hidden. A few things are worth knowing.
When a colleague can reach a page or use a button that you cannot, the usual reason is a difference in roles, or in what has been shared with you — not a fault. An administrator can grant the missing access.
Your access is not fixed. It changes when an administrator gives you a new role or removes one, and when someone shares a specific part of the directory or a page with you. A change takes effect the next time the affected screen loads.
If you are an administrator, roles and their permissions are managed in the policy area — see Roles to set up roles and Sharing to give people access to particular parts of the directory and pages. For the full list of the actions and screens each permission covers, see the roles and permissions catalogue.