← All training

👥 Roles & Permissions

Who can edit what. The roles, role defaults, and per-user overrides.

10 sections · ~7 min read

Nine roles, clear lanes

Admin · R&D (npd) · QA · Factory · OPS · Purchasing · Finance · IT · Viewer. Each role edits a specific set of pages. Outside those pages, the role still sees data, just read-only.

Admin

Full access. Edits library, manages users, fixes anything. Currently the only admin is Caterina.

R&D / npd — recipe authors

Owns: Recipes, Recipe Detail, Ingredients, Builds, Factory SOP (full edit), Branch SOP, QAS, Brands, Library, Safety Icons, Substitutions, Ingredient Requests. Drives the recipe lifecycle from Draft → In Review → Factory Trial. Hands off to QA + Factory at the gates.

QA — gatekeeper, also a SOP author

Owns: QA, Builds, Branch SOP, Recipe Detail (QA fields), Substitutions, Ingredient Requests. Approves recipes for trial, sets shelf life (temporary + validated), captures lab results, signs the COA. Full Factory SOP edit access (same as R&D): generate SOPs, edit steps + method, manage hazards, and edit the Standard Blocks Library + Safety Icons catalog. Can't create recipes or schedule runs.

Factory — production owner

Owns: Production. Schedules runs, captures yields, marks complete. Assigns the Recipe ID at the Factory-Trial-Passed gate — the chokepoint between trial and prod-trial.

IT — support without recipe exposure

IT reads the portal for support and audit, but Recipes / Factory SOP / Branch SOP are hidden — formulations stay confidential. Otherwise behaves like Viewer (read-only, no edits).
Role-specific notes
ADMIN: Omar holds this role today. Use it for anyone on the IT team who needs to troubleshoot the portal without seeing recipe IP.

OPS, Purchasing, Viewer

OPS — branches-only (Branch SOP). Never sees factory pages.
Purchasing — Ingredients + Communications. Manages prices and supplier specs.
Viewer — read-only across the portal. Useful for execs, auditors, new hires.

Finance, costing and queries

Read-only across the portal, with two extra powers: it can edit ingredient and supplier pricing, and raise or clear flags on Recipes and Product Builds to query a cost or a spec. Finance cannot create or edit recipes, builds, QA results, or SOPs, and does not flag Factory SOPs. Mohd Rehan is the first Finance user.
Role-specific notes
FINANCE: sign in with your @dailyfoodsa.com Workspace account. Costing shows everywhere; the flag button sits on recipes and builds.

Adding a user

Admin opens Users & Access from the sidebar and clicks + Add User on the Active Team card. Name, email, and role are set at creation — there's no approval queue.
Role-specific notes
ADMIN: Only you can add users. The button on the Active Team card opens the form.
NPD: You can't add users. Ask Caterina if someone new needs access.
VIEWER: You're read-only by design. To change role or add people, contact Admin.

Per-user access overrides role defaults

Every user has an Access column on the Active Team table with toggles for Recipes / Builds / Prices / Cost / Branch SOP / Factory SOP. These per-user toggles override the role-level defaults — useful when one Factory user needs to see Cost while the rest don't.

Role defaults — Access Control matrix

The Access Control matrix at the bottom of the Users & Access page is collapsed by default. Open it to set what each role can see and do out of the box. Per-user toggles still override this when needed.
Role-specific notes
ADMIN: Click the navy "Access Control" header to expand. Save Changes appears once it's open.