Permissions in Novrex are layered. Every user has a workspace role (Owner / Admin / Editor / Viewer) plus optional per-module overrides and per-outlet scoping.
Building a custom role
Go to Settings → Roles → New Custom Role. Pick a starting template (closest existing role), then toggle individual permissions. Custom roles can be assigned to any number of users and edited in place — changes propagate immediately.
Per-module overrides
A user can have different roles per product. The most common pattern: marketing managers are Admins in Marketing, Viewers in ERP, no access to E-Commerce.
Outlet scoping
On any role assignment, restrict the user to specific outlets. Outlet managers typically have full access to their own outlet and read-only access elsewhere.
Audit log
Every permission change is logged with who, what, and when. Available under Settings → Security → Audit Log. Exportable for compliance reviews.