FireAI ERP
Users and roles
Admin guide to inviting users and configuring roles with View, Edit, and Delete on pages and collections so each person only sees the FireAI ERP screens they need.
Updated August 1, 2026
Access problems are the most common “ERP is broken” report during onboarding. Almost always the role is incomplete. Configure roles before inviting the whole team.
Who can manage access
- Users with admin rights / Settings manage permission
- Do not share one admin login across the accounts team
A. Plan roles on paper first
Suggested starter roles:
| Role | Typical access |
|---|---|
| Admin | Settings, all collections, users |
| Accounts | Sales + Purchases documents, customers, vendors, receipts, payments |
| Store | Inventory, warehouses, stocks, transfers, products (view/edit as needed) |
| Sales executive | Customers, orders, draft invoices (confirm optional) |
| Viewer | Home + view-only invoices/stock |
B. Configure a role
- Open Settings → Roles.
- Select an existing role or create a custom role (name + slug).
- You will see permission grids for:
Pages
Examples from the product:
| Page key | Controls access to |
|---|---|
| Home | Home |
| Collections | Collections browser |
| Inventory (Stock) | Inventory |
| Trips | Trips |
| Reports | Dashboard / reports |
| Orders | Staff orders |
| Settings | Settings |
For each page set View, and Edit / Delete only where justified.
Collections
Grant View/Edit/Delete on collections the role must use, for example:
- customers, vendors
- products, raw_materials, warehouses, stocks
- sales_invoices, receipts, credit_notes
- purchase_orders, purchase_invoices, payments
- price_lists, price_list_items
- Save the role.
- Have a test user log in and confirm menus.
Least privilege
Start with View + Edit on the daily registers only. Add Settings or Delete later when trust is established.
C. Invite users
- Open Settings → Users.
- Click Invite.
- Enter the email they will actually sign in with and assign the role you prepared.
- Send them the ERP URL and ask them to sign in the same day.
- On first login, confirm: correct organisation, expected left-rail modules, can open one create form.
Pending invites show as Invite pending until they register.
Checklist per user
- Email correct
- Role assigned
- Can open Home
- Sees only intended modules
- Cannot open Settings (unless admin)
D. Changing access later
- Prefer changing the role once over editing every user.
- If one person needs a special right, create a named role (for example Accounts+Confirm) instead of making everyone admin.
- After role changes, ask the user to refresh or re-login.
E. Common access issues
| Symptom | Fix |
|---|---|
| Empty left rail | Grant page View (Home at minimum) |
| Sees Sales but not Invoices tab | Grant sales_invoices collection View |
| Can open invoice but cannot save | Grant Edit on that collection |
| Settings missing | Expected for non-admins |
| Wrong company data | Organisation switcher — not roles |
F. Onboarding sequence with users
- Admin finishes Company and settings.
- Admin creates roles (this page).
- Admin creates warehouses/products personally or with store lead (Masters).
- Admin invites Accounts and Store users.
- Accounts creates first draft invoice while admin watches once.
- Only then invite the wider sales team.