👥 Roles & Permissions
Who can edit what. The roles, role defaults, and per-user overrides.
10 sections · ~7 min read
Nine roles, clear lanes
Admin · R&D (npd) · QA · Factory · OPS · Purchasing · Finance · IT · Viewer. Each role edits a specific set of pages. Outside those pages, the role still sees data, just read-only.
Admin
Full access. Edits library, manages users, fixes anything. Currently the only admin is Caterina.
R&D / npd — recipe authors
Owns: Recipes, Recipe Detail, Ingredients, Builds, Factory SOP (full edit), Branch SOP, QAS, Brands, Library, Safety Icons, Substitutions, Ingredient Requests. Drives the recipe lifecycle from Draft → In Review → Factory Trial. Hands off to QA + Factory at the gates.
QA — gatekeeper, also a SOP author
Owns: QA, Builds, Branch SOP, Recipe Detail (QA fields), Substitutions, Ingredient Requests. Approves recipes for trial, sets shelf life (temporary + validated), captures lab results, signs the COA. Full Factory SOP edit access (same as R&D): generate SOPs, edit steps + method, manage hazards, and edit the Standard Blocks Library + Safety Icons catalog. Can't create recipes or schedule runs.
Factory — production owner
Owns: Production. Schedules runs, captures yields, marks complete. Assigns the Recipe ID at the Factory-Trial-Passed gate — the chokepoint between trial and prod-trial.
IT — support without recipe exposure
IT reads the portal for support and audit, but Recipes / Factory SOP / Branch SOP are hidden — formulations stay confidential. Otherwise behaves like Viewer (read-only, no edits).
Role-specific notes
ADMIN: Omar holds this role today. Use it for anyone on the IT team who needs to troubleshoot the portal without seeing recipe IP.
OPS, Purchasing, Viewer
OPS — branches-only (Branch SOP). Never sees factory pages.
Purchasing — Ingredients + Communications. Manages prices and supplier specs.
Viewer — read-only across the portal. Useful for execs, auditors, new hires.
Finance, costing and queries
Read-only across the portal, with two extra powers: it can edit ingredient and supplier pricing, and raise or clear flags on Recipes and Product Builds to query a cost or a spec. Finance cannot create or edit recipes, builds, QA results, or SOPs, and does not flag Factory SOPs. Mohd Rehan is the first Finance user.
Role-specific notes
FINANCE: sign in with your @dailyfoodsa.com Workspace account. Costing shows everywhere; the flag button sits on recipes and builds.
Adding a user
Admin opens Users & Access from the sidebar and clicks + Add User on the Active Team card. Name, email, and role are set at creation — there's no approval queue.
Role-specific notes
ADMIN: Only you can add users. The button on the Active Team card opens the form.
NPD: You can't add users. Ask Caterina if someone new needs access.
VIEWER: You're read-only by design. To change role or add people, contact Admin.
Per-user access overrides role defaults
Every user has an Access column on the Active Team table with toggles for Recipes / Builds / Prices / Cost / Branch SOP / Factory SOP. These per-user toggles override the role-level defaults — useful when one Factory user needs to see Cost while the rest don't.
Role defaults — Access Control matrix
The Access Control matrix at the bottom of the Users & Access page is collapsed by default. Open it to set what each role can see and do out of the box. Per-user toggles still override this when needed.
Role-specific notes
ADMIN: Click the navy "Access Control" header to expand. Save Changes appears once it's open.