Features · Roles and permissions

Decide who in your team can see and do what

A role is a list of switches, one for each part of Gem Logic. Create a role for each job in your shop, assign it to a person, and that is all there is to it. Sales staff sell, the workshop repairs, and only the people you choose see costs and profits.

One role per person Costs and profits is its own switch Changes apply immediately
Team and access
6 people · 3 roles
3 with full access
PersonRole
YKYou
Full access
KVKatrien Vos
Full access
AJAnna Janssens
Store Manager21/25
MLMarie Lefèvre
Accountant17/25
LMLore Maes
Sales Associate11/25
SPSofie Peeters
Full access
Saturdays only. No role.
Sofie can see everything, including costs, because nobody assigned her a role.
Assign a role
How it works

Simple by design

There are no access levels, no hierarchies and no roles inheriting from other roles. Three ideas cover the whole system.

One list covers the whole app

25 permissions in 6 groups, one for each part of Gem Logic: sales, repairs, catalog, customers, finance and more. Two of them are marked sensitive so granting them is always a conscious decision.

A role describes a job

Workshop, Saturday sales, bookkeeping. Turn on the switches that job needs and give it a name. Because roles never inherit from each other, most shops only need four or five.

One role per person

Roles do not stack. Each person holds exactly one, so the role name alone tells you what somebody can open. People without a role get full access, which is reserved for owners.

Inside a role

Switch on what the job needs

Open a role and toggle permissions on or off. The counter at the top follows along, and every change is saved the moment you make it. Two permissions carry a sensitive label: delete, and view costs and profits.

Role
Accountant
17 of 25 permissions enabled
All changes saved
Sales
3/5Enable all
Sales
View and manage sales
Quotes
View and manage quotes
Repairs
View and manage repairs
Memos
View and manage memos
Creations
View and manage creations
Data and insights
2/4Enable all
View graphs
Access charts and analytics
Export data
Export and download files
DeleteSENSITIVE
Delete and archive records
View costs and profitsSENSITIVE
Access product cost and profit information
Four more groups below: Operations 2/6 · Catalog 5/5 · Customers 2/2 · Finance 3/3
Two permissions carry a warning label

Delete and view costs and profits are marked sensitive in the interface. Nothing blocks you from granting them, but the label makes sure it is always a deliberate choice.

Creating a role takes about a minute

Enable a whole group at once and switch off the few that do not apply, or duplicate an existing role and adjust it. Changes save automatically and apply immediately.

The same rules apply to Gembot

Permissions are not a way around your setup, not even for the AI. Gembot respects the same roles as your team, so an action reserved for admins stays reserved no matter who or what asks.

The whole list

25 permissions in 6 groups

These are the exact names you will see in the app. Most mean view and manage together. The four in Data and insights reach across the whole app at once, which is why two of them are marked sensitive.

Sales
5
SalesQuotesRepairsMemosCreations
Operations
6
ShipmentsTasksWorksheetsAgendaAutomationsAutopilot
Catalog
5
Product and stockStock inSuppliersCertificatesFiles
Customers
2
ContactsEmails
Finance
3
AccountingTransactionsBilling
Data and insights
4
View graphsExport data Delete SENSITIVE View costs and profits SENSITIVE
A role decides which parts of the app somebody can open. It does not limit them to specific customers or price lists inside those parts.
Worth checking twice a year

How many people can see what your stock cost you?

In most shops this number only grows, through reasonable decisions made on busy days: a promotion, a temporary login that became permanent, a new hire given full access to save time. The team list makes the answer visible, so you can fix it in a minute instead of finding out by accident.

Costs and profits · today
5of 6 people can see it
3have full access, so no role limits them
2hold a role that includes it on purpose
1holds a role without it, and does not need it
Check this number after every promotion, and every time somebody leaves.

Set up the right access for your team

Book a demo, bring your team list and the jobs those people actually do, and we will create the roles together on the call. It takes less time than you think.

image_overlay