VauPrime DocsOrganizationRole & Permissions
OrganizationCurrent app behaviorDart-source backed

Role & Permissions

Current role and permission management in VauPrime is handled through Users Management. Invite a user by email, choose the user’s role, target organization/branch, optional access dates and screen-wise permissions, then manage the connection from Existing Users.

Main tabs

2 tabs

Add User and Existing Users

Default role

Manager

Changing role refreshes its default permission set

Access scope

Organization / Branch

A target workspace is required before invitation

Permission model

Screen-wise

View, Create, Update and Delete where supported

Current source of truth: Users Management

The old access-key / Add Role documentation is no longer the correct user workflow for this page. Role & Permissions now follows the current Users Management screen with Add User and Existing Users tabs, organization/branch targeting and screen-level permissions.

What is Role & Permissions?

Purpose and current VauPrime behavior.

Role & Permissions is the user-access layer for an organization. The current implementation is not a separate access-key creator; it is the Users Management workflow used to invite and manage organization members.

Each new user is connected by email, role and Target Organization / Branch. Optional access start/end dates can restrict when the connection is active.

Permissions are role-aware and can be refined screen by screen. Some screens expose all four actions — View, Create, Update and Delete — while read-only/report screens expose only the permissions that make sense for that screen.

Existing Users combines outgoing user connections and received requests. Actions change according to connection status, so an invited user can be revoked, an active user can be disabled, a disabled/suspended connection can be enabled, and received invitations can be accepted or rejected.

Mobile UI structure

What the user sees and what each action does on the compact layout.

Top layoutThe current Android implementation uses the compact layout without the Windows sidebar, with the organization Global Header above the content in normal management mode.
Two tabsAdd User is the invitation/access form. Existing Users is the list of current connections and received requests.
Add User — Member EmailEnter the user’s email address. The invitation cannot continue when this field is empty.
RoleRead-only field that opens the role picker. The default selection is Manager.
Target Organization / BranchTap to select one of the available owned organization/branch workspaces. The selected target is required before the user can be invited.
PharmacyShown only when the Pharmacy Manager role is selected. The role has an additional pharmacy-target requirement in its specialized flow.
Access Start DateOptional date picker for when access begins.
Access End DateOptional date picker for when access ends. If both dates are set, end date cannot be before start date.
PermissionsOpen the permissions manager to review role defaults and choose screen-wise access. Permission actions are View, Create, Update and Delete where supported by each screen.
Existing Users — SearchSearch by role, user ID, status or email. Pull/refresh reloads the latest connections.
Existing user cardCards use the centralized expandable mobile list. Tap expands the available row actions for that connection.
EditOpens the member edit sheet so role, target branch, access dates, status and permissions can be updated.
RevokeAvailable for an outgoing invitation that is still Invited.
Disable / EnableActive connections can be disabled. Non-active connections that are eligible can be enabled again.
Accept / RejectShown for received invitations so the user can accept or reject the incoming organization request.

Windows UI structure

Desktop layout, lists, tables and actions.

Desktop shellNormal Windows management uses the Window Global Sidebar plus Global Header and the same two-tab Users Management content.
Add User tabThe same Member Email, Role, Target Organization / Branch and access-date controls are arranged with more horizontal space.
Role & branch selectionRole and Target Organization / Branch remain required access decisions. Branch selection shows the organization/branch name and its code in the picker.
PermissionsScreen permission management uses the same permission model as mobile. Role defaults are the starting point and can be refined for individual screens.
Existing Users tableDesktop uses the centralized existing-data table rather than expandable mobile cards.
SearchSearch by role, user ID, status or email and refresh to reload the latest connections.
Conditional row actionsWindows actions are status-aware: Edit is available for outgoing connections; Invited can expose Revoke; Active can expose Disable; eligible inactive states can expose Enable; received Invited requests expose Accept/Reject.
Edit member sheetThe edit flow includes Role, Target Organization / Branch, Access Start Date, Access End Date, Status and permission controls.

Add User fields and permission controls

Current fields sourced from the Users Management screen rather than the retired access-key role form.

Member EmailEmail address of the person being connected to the organization.
RoleAvailable current roles: Owner, Admin, Manager, Accountant, Viewer, Sales Person, Pharmacy Manager and Booking Receptionist.
Target Organization / BranchRequired target workspace. This is also where a newly created branch becomes usable for user access assignment.
PharmacyConditional field for Pharmacy Manager.
Access Start DateOptional start of the member’s allowed access period.
Access End DateOptional end of the access period; cannot be earlier than the selected start date.
Role default permissionsChanging the role loads the default permission set for that role.
Screen permissionsPermissions are stored per screen. Supported actions are View, Create, Update and Delete; read-only screens may expose only View or a smaller allowed set.
StatusesCurrent connection states include Active, Invited, Suspended and Revoked, plus received/outgoing connection context.

Invite a user and assign permissions

Current user flow from start to completion.

01

Open Add User

Open Role & Permissions / Users Management and stay on the Add User tab.

02

Enter Member Email

Enter the email address for the person who needs organization access.

03

Choose Role

Select the role that best describes the user. VauPrime refreshes the default permission set when the role changes.

04

Choose Target Organization / Branch

Select the exact organization or branch the person should access. This selection is required.

05

Set optional access dates

Use Access Start Date and Access End Date when the user should only have access for a defined period.

06

Review screen permissions

Open the permission manager and adjust View/Create/Update/Delete by screen where those actions are supported.

07

Send invitation

VauPrime checks the plan’s user capacity, then creates the connection and reports Invitation sent successfully when completed.

08

Manage Existing Users

Open the Existing Users tab to search, edit, revoke, disable, enable, accept or reject connections according to their current status.

Subscription and plan checks

Plan-aware checks that can affect this workflow.

LiteCurrent Users Management logic allows up to 1 organization member before showing the upgrade flow.
EliteCurrent Users Management logic allows up to 3 organization members before showing the upgrade flow.
Prime and higher plansThe current Users Management screen does not apply the Lite/Elite fixed user cap to these plans in this check.
User Limit ReachedWhen the applicable limit is reached, VauPrime shows an Upgrade Plan prompt instead of adding another user.

Validation and common checks

Conditions checked before completing an action.

Member Email is required before a new organization member can be invited.
The current organization must be resolved correctly before user access can be created.
Target Organization / Branch is required.
When both access dates are set, Access End Date must not be before Access Start Date.
The active subscription user limit is checked before a new member is added.
Pharmacy Manager has an additional account/pharmacy-specific creation path when the required manager account or pharmacy target is not ready.

Important behavior and notes

Current product behavior worth knowing.

The old Add Role / Existing Roles access-key documentation has been removed from this guide because it does not match the current Users Management workflow.
The default role is Manager, but users can be assigned Owner, Admin, Accountant, Viewer, Sales Person, Pharmacy Manager or Booking Receptionist as appropriate.
Permissions are not one global on/off switch. VauPrime supports screen-level access, and each screen defines which of View/Create/Update/Delete are meaningful for it.
Examples of read-only permission surfaces include Account Ledger, Balance Sheet and analytics/report screens, while transaction/master screens can expose create/update/delete controls.
A branch must exist before it can be selected as Target Organization / Branch. Use Branches Management → Create New Branch when another workspace is needed first.
Received requests and outgoing invitations live in the same Existing Users experience but expose different actions based on connection type and status.