How do roles, permissions and the audit trail work?
The roles, permissions and audit trail module is the core layer that answers, on every panel screen, “can this user see this” and “who made this change.” Every other module — customers, accounting, trips, the assistant — borrows its access checks from here; no module invents its own permission logic.
Users and roles
The Users and permissions screen has two tabs. The Users tab is your team list; every user carries a role, a rank and a status (active/suspended). The Roles tab is a master-detail layout: a searchable role list on the left, the selected role’s detail on the right — even a company with fifty roles and a hundred users keeps this as a vertical, searchable list rather than a table that scrolls sideways. A role’s detail splits into three tabs: Permissions (grouped module by module), Members (users holding this role) and Appearance (the role’s name and colour).
Permission scope: all and own
A permission can be granted company-wide (all) or limited to a user’s own records (own). A driver’s “I can see my own trips” permission, for instance, is own-scoped — they cannot see a trip they were not assigned to; an operations manager holding the same permission as all sees every trip in the company. This split repeats in every module and is filtered by the same rule all the way down to dashboard widgets, lists and search results — an amount hidden on one screen never leaks out through a report or an export either.
The rank gate
Separate from role, there is also rank, and the two answer different questions: role decides “what actions can be taken”, rank decides “who can act on whom, and who can grant which rank.” A user can act on someone with a lower rank but never on someone equal or higher — this is how a company always keeps at least one owner, with no extra check needed. Ownership itself (the owner rank) cannot be handed off; an owner can only assign a lower rank, never their own.
The audit trail
The Staff tracking screen holds two things together: who currently has a session open (with the option to close that session remotely) and the company’s entire audit record. Every mutation — a user invited, a role’s permissions changed, an invoice issued — leaves a row here, carrying who did it, when, and what changed. Audit events are drawn from a closed dictionary — a row cannot be written under an event name that is not in it, which keeps the audit record from filling up with arbitrary text.
Full authority and readable audit rows
A “full authority” flag on a role can only be granted by the company owner (rank 10) — it means that role automatically holds every permission in the company, and it is deliberately kept narrow. Every audit row does not just say “what happened” — it also carries which record, which parent record (a passenger row on a trip, say) and which fields were touched, so reading one row answers “who changed what, inside which record” without needing a second screen.
Example
Picture a company where someone on the accounting team has a “Accounting” role scoped own, seeing only their own branch’s invoices. When they try to look up another branch’s invoice, the result comes back empty — they are not told they are blocked, the record simply behaves as if it does not exist. Later that day, a manager widens their role to all; that change shows up permanently on the Staff tracking screen as a “role permission changed” row, with which manager did it and when.
How it works in Rotenta
- From the Users and permissions screen’s Users tab, a new person is invited; their role and, if relevant, their rank are chosen at that step.
- From the Roles tab, a role is selected and its Permissions sub-tab is used to check permissions module by module; scoped permissions get an
own/allchoice. - The Members sub-tab shows who holds this role, and a new member can be added there.
- To temporarily stop a user, they are suspended from the Users tab; if their session is open, it can be closed instantly from Staff tracking.
- Closing every open session company-wide — say, after a suspected access issue — can be done in a single bulk action.
- Every change lands automatically in the Staff tracking audit list, which is searchable and filterable.
You can read about the consent side of this permission system in consent management, how it applies to sensitive fields on a customer card in customer management, and how the assistant inherits this exact permission set in AI assistant. The full picture of how this core layer relates to the rest is in our module guide; for a role template that fits your team structure, get in touch.
Frequently asked questions
If I change a user’s role, does it rewrite their past actions?
No; the audit record keeps exactly what was done under which permission at the time — a role change only affects access from that point forward.
Where does the own/all scope apply?
Everywhere a permission check runs — lists, dashboard cards, search results and exports all apply the same scope rule.
Can an owner hand their rank to someone else?
No; ownership cannot be transferred — an owner can only assign a rank lower than their own, which is how a company always keeps at least one owner.
Can an event name outside the audit dictionary be written to the log?
No; audit events come from a closed dictionary, and an attempt to write a row under a name that is not defined there is rejected.
If we notice suspicious access, can we close every session at once?
Yes; from Staff tracking, every open session company-wide (except your own) can be closed in a single action.
More in this category
- How does vehicle and driver document tracking work?
Warns on an expired or upcoming vehicle/driver document, and blocks trip assignment when a required one has lapsed.
- How does the vehicle and driver (fleet) module work?
One ledger for your vehicles and drivers that trips assign from and that answers who is available, when.
- How does recurring shuttle planning work?
A route and weekly plan are defined once; public holidays are skipped, one-off exceptions post as billing deductions, and off-plan extra trips enter the statement as their own line.
- How is e-invoicing (e-Fatura/e-Arşiv) integrated?
Tax ID and scenario data carried on the invoice record flow straight through; send status and the tax authority's reference show on the panel in real time.
- How does the Excel data import module work?
A module that validates and previews your existing spreadsheets, isolates the bad rows, and can undo an import if needed.
- How is workflow automation set up?
Trigger + condition + action rules ship as ready templates, every run is recorded as evidence, and a rule bound to a closed module shows as visibly inactive, never silent.
- How does the consent management module work?
Records customer consent per channel, ties sensitive fields to explicit consent, and exports to Turkey's İYS registry.
- How does the customer management (CRM) module work?
One card for people and companies, encrypted sensitive fields, tagging and notes — how Rotenta's CRM module is laid out on screen.
- How does the accounting module: accounts, invoices, cash work?
Current account, invoice, cash and instalment tracking brought together in one accounting module, from proforma to day-close.
- How do PDF outputs and letterhead documents work?
One core engine that puts your letterhead on invoices, statements, receipts and passenger lists, and logs every document it produces.
- How are staff shifts and timesheets managed?
Timesheets are produced from realised trips, deductions carry evidence and a dispute path, staff on leave cannot be reassigned, and period close freezes the past.
- How do reports and profitability analysis work?
Every list you own exports at full fidelity, aging buckets of 0-30/30-60/60-90/90+ days sit on one screen, and period profitability drills all the way down to the source trip.
- How does booking and capacity management work?
A resource x time-slot booking engine that blocks double-selling, tracks option deadlines and converts a confirmed request straight into a trip or service record.
- How does the trip and transfer operations module work?
One record that follows a trip from planning to completion, carrying its passengers, driver, vehicle and price lines together.
- How do contracts and progress billing work?
The contract is the single price source; progress billing is calculated automatically from trip records, penalty clauses apply on their own, and an approved statement becomes an invoice in one click.
- How do quotes and proposals work?
Quote lines read from the published rate list, margin is visible to authorised users, a five-state lifecycle is tracked, and an accepted quote converts to an invoice in one click.
- How does bulk messaging and consent compliance work?
Consent is checked at send time against İYS, the national record; every commercial message carries an opt-out link, and delivery state is kept as evidence.
- How is U-ETDS reporting done?
Every trip already carries the fields U-ETDS reporting needs; send status shows on the trip card and never shows an optimistic 'sent' before it is confirmed.
- How does the AI assistant module work inside the panel?
An in-panel assistant that works within your own permissions, masks personal data, and asks approval before every write.