RevenuePilot CRMDocumentation
v1.0.0 Changelog

Roles And Permissions

RevenuePilot uses Spatie permissions to protect modules, actions, and high-risk operations. Assign capabilities by job role, not by copying administrator access.

RoleTypical Scope
AdministratorSettings, roles, System Health, packaging, platform controls, and all CRM data.
ManagerDashboards, leads, deals, quotes, reports, teams, approvals, and customer success.
AgentAssigned leads, deals, follow-ups, tasks, tickets, and customer communications.
FinanceInvoices, payments, statements, gateway events, reconciliation, and dunning.
SupportSupport inbox, tickets, canned replies, SLA operations, and knowledge base.

Permission Design

Use view/manage permission pairs where possible, then isolate critical permissions such as settings, system health, payment gateway management, refunds, live activation, and marketplace packaging.

Role Review Procedure

  1. Start from the user's job responsibilities and workspace, not an existing administrator role.
  2. Grant view access before manage access; isolate export, delete, refund, settings, and live-provider permissions.
  3. Sign in as a test user and verify direct URLs as well as sidebar visibility.
  4. Confirm portal roles cannot cross company or workspace boundaries.
  5. Review role changes in the activity log and repeat the test after adding a module.
RevenuePilot permission glossary
Use the permission glossary during least-privilege review.