Roles And Permissions
RevenuePilot uses Spatie permissions to protect modules, actions, and high-risk operations. Assign capabilities by job role, not by copying administrator access.
Recommended Roles
| Role | Typical Scope |
|---|---|
| Administrator | Settings, roles, System Health, packaging, platform controls, and all CRM data. |
| Manager | Dashboards, leads, deals, quotes, reports, teams, approvals, and customer success. |
| Agent | Assigned leads, deals, follow-ups, tasks, tickets, and customer communications. |
| Finance | Invoices, payments, statements, gateway events, reconciliation, and dunning. |
| Support | Support inbox, tickets, canned replies, SLA operations, and knowledge base. |
Permission Design
Use view/manage permission pairs where possible, then isolate critical permissions such as settings, system health, payment gateway management, refunds, live activation, and marketplace packaging.
Role Review Procedure
- Start from the user's job responsibilities and workspace, not an existing administrator role.
- Grant view access before manage access; isolate export, delete, refund, settings, and live-provider permissions.
- Sign in as a test user and verify direct URLs as well as sidebar visibility.
- Confirm portal roles cannot cross company or workspace boundaries.
- Review role changes in the activity log and repeat the test after adding a module.
