ODShared Setup DocsRoles
Shared access model

Roles And Permissions

All current Ovion apps use role-based access patterns. Keep this shared setup light, then use each app's module pages for product-specific permission names and workflows.

Leastprivilege by default
01

Admin

Full setup, settings, billing, import/export, user, and integration control.

02

Manager

Operational oversight, approvals, assigned records, reports, and team workflow control.

03

Staff

Daily work surfaces with restricted settings and record visibility.

04

Portal

Client, employee, patient, or customer access depending on the product.

Safe Rollout

  1. Create the first admin during installation.
  2. Review the generated permission catalog before adding real staff.
  3. Clone roles for managers and staff instead of editing admin permissions directly.
  4. Test portal/client access with a seeded demo user before inviting real users.
  5. Limit integration, webhook, payment, payroll, and export permissions to trusted administrators.

App-Specific Permission Areas

AppHigh-risk permissions
OvionDesk AIAI settings, knowledge training, billing, workspace/license operations, Envato verification, webhooks, inbox exports, and widget domain control.
AttendProPayroll, attendance corrections, device/API capture, reports, employee data export.
SupportDeskSLA changes, automations, public support, AI actions, organization contracts.
OperixEMR, billing, pharmacy, patient data, clinic tenancy, AI review.
BookFlowTenant settings, wallet/payment changes, no-show controls, staff calendar, program credits.
RevenuePilot CRMAPI clients, webhooks, invoices, payment gateways, portal files, AI operator actions.
Metrivo AIAccounting periods, journals, tax controls, stock corrections, import/export, POS overrides, payment settings, and permissions catalog changes.
SupportHubAutomation playbooks, public support, organization contracts, AI copilot actions, reports, API clients, delivery diagnostics, and case file exports.
Previous: SMTPBack to shared docs