Database-configurable access control, with granular permissions, scopes and per-role limits.
TALLERDESK uses a fully configurable roles-and-permissions system (RBAC). Permissions are granular with module.action notation (view, edit, close, issue invoice, correct, view cost...), and can be granted or denied directly per user, overriding the role.
Each permission can be limited to a scope ("only mine" or a site) and each role can have numeric limits (maximum discount per line, maximum refund amount...). Exceeding them requires a supervisor's authorisation. Preloaded roles (manager, workshop foreman, reception, mechanic, warehouse, office, accountant...) are editable and cloneable.