Every person who logs into posflect is a user — with a username, email, and profile details, and optionally a phone number, job title, and monthly salary if they're on payroll. A user never holds permissions directly; instead they belong to one or more groups, and each group holds a specific list of permissions such as viewing reports, managing printers, or approving discounts. Access is managed at the role level — give a group the right permissions once, and every user in it inherits them; moving someone into a different group instantly changes what they can do.
Because handing out group-editing power could otherwise let someone grant themselves permissions they don't actually have, the system enforces a simple rule: you can only add a permission to a group if you already hold that permission yourself. Users also each set their own short PINs, separate from their login password, used specifically for in-person approvals and clocking in and out at a shared terminal.
Key capabilities
- Users are assigned to one or more permission groups rather than holding permissions individually
- Groups bundle permissions by module (printers, reports, approvals, and more)
- Self-escalation guard: you can only grant a permission you already hold when editing a group
- Personal approval PIN and attendance PIN, separate from the login password
- Account lockout after repeated failed login attempts