Skip to content

Authorization & User Management

The right person, the right data, the right permission.

The Authorization & Users module unifies users, roles, permissions and session security on one data model. It governs access to every module centrally, making each action traceable and auditable.

Illustrative screenYetki & KullanıcıRol MatrisiROLGörüntüleDüzenleSilYöneticiMuhasebeDepo PersoneliMisafir14 rol · 142 kullanıcıRBAC aktif

Role-based authorization and access.

Overview

What it does

Central control instead of access settings scattered module by module. The Authorization & Users module gathers users, roles and permissions on the same data, answering “who can access what” from one place, traceably.

Scope

Sub-categories of Roles & Users

Each sub-category manages a part of this process — all on the same data.

User Management

Manage user accounts, groups and statuses from one place.

Account managementUser groupsStatus & suspension

Role & Permission Management

Define roles, map permissions to roles and restrict access at screen/action level.

Role definitionScreen / action permissionData restriction

Session & Security

Manage session policies, two-factor authentication and the audit log.

Session policyTwo-factor authAudit log

Roles

Who is it for?

The same data, a different view for each role.

System Administrator

Manage users, roles and permissions centrally; set access policies.

Security Officer

Manage session and authentication policies; monitor suspicious access.

Auditor

Verify who did what and when from the audit log; report compliance.

Connection

How access is governed

Authorization is not an isolated setting; it stands at the gate of the whole ERP. A user links to a role, a role to permissions, and every action to the audit log.

User

An account is created.

Role & Permission

Access is mapped to a role.

Session

Protected by policy.

Audit

Every action is logged.

Capabilities

Key features

Central user and role management
Screen- and action-level permissions
Data-level access restriction
Two-factor authentication
Session policies
Full audit trail

Compliance

Compliant with local regulation

Erişim Kontrolüİki Adımlı DoğrulamaDenetim İziKVKK

Architecture supporting the control required by KVKK and corporate information-security policies through role-based access, two-factor authentication and audit trails.

Roles & Users with Sonia AI

Describe it, Sonia prepares it.

Describe your authorization tasks in natural language; Sonia analyzes current access, prepares the suggestion or report and brings it for your approval — assignment and the final decision are always yours.

List users with access to finance data, by role
Surface accounts with no login in 90 days
Report users whose permissions changed this month

Frequently Asked Questions

How granular can permissions get?

Permissions can be granted at module, screen and action level; a user can also be limited to a data set such as their own branch/department.

What does the audit trail record?

Logins, permission changes and critical actions are recorded with user, time and content; they are traceable retrospectively for audit and compliance.

Can two-factor authentication be enforced?

Yes. Two-factor can be enforced by role or user group; session duration and re-authentication policies can be defined.

See AinosERP on your own processes

Let’s schedule a short demo and walk through the screens and Sonia AI using your flows.