Permissions
Permissions define what operations a role can perform on which resource groups. They are the primary mechanism for controlling day-to-day access, determining whether a user can view, create, edit, or delete records in a given business area. The permission system distinguishes between ALL_RECORDS scope (access to every record in the tenant) and OWN_RECORDS scope (access only to records the user owns or that have been shared with them).
Permission definitions
Each permission has the following key attributes:
| Field | Description |
|---|---|
| target_resource_group | A three-letter business area code (e.g. CRM, HRM, FAR, BIL) |
| target_resource_name | The specific resource within the business area |
| operation | The operation this permission governs (e.g. SELECT, INSERT, UPDATE) |
| permission_name | A human-readable name for the permission |
| permission_code | A unique machine-readable code, unique per tenant |
| permission_description | A free-text explanation of what the permission allows |
Permissions are data-driven — they are stored as configurable records, not hard-coded. This allows tenants to define custom permissions for new business areas or adjust existing ones without code changes.