Dealerships have a responsibility to safeguard sensitive customer and business information. To better protect your customers and your business, we offer user Roles. User Roles allow you to dictate what individual users can or cannot access in DeskManager Online.
User Roles are a small part of managing user accounts and settings. For more information about User Accounts, read our article here: User Accounts
Questions this answers
- "How do I create a role and control what each user can access?"
- "How do I assign a role to one of my users?"
"Someone can't see or do something" — find the symptom, then the permission
Most access problems reported as bugs are a Role permission working exactly as configured. Find the symptom below, then open Setup > Organization > Roles, open that user's role, and check the permission named.
| What the person sees | Permission that controls it |
|---|---|
| Customer record opens fine, but the Sensitive tab says access denied and the SSN section is hidden | The permission for sensitive contact fields — SSN, driver's license |
| Can open regular customers, but not the GAP provider, insurance company, warranty company or vendor records | The permission for third-party contact records |
| The Email button is there on a deal but missing on inventory or accounting screens | Email-from-letter permissions are granted per module — deal, inventory, contact and accounting are four separate permissions |
| Can see what you paid for a car, but not the total cost with pack | Vehicle cost and pack are two different permissions |
| Cannot correct a vehicle expense after the car has sold | The permission for modifying cost on a sold vehicle |
| A negative expense on a vehicle is rejected | The permission allowing negative expense entry |
| Cannot unlock or unwind a finalized deal | The deal-unlock permission. Also check Prevent Editing Closed Deal — that one removes access when checked |
| Can print and e-sign, but cannot add or reorder forms inside a form pack | The form-pack editing permission |
| Gets Access Denied opening the credit bureau (Metro 2) report history | The Metro 2 credit-reporting permission |
| Needs to locate a vehicle through your GPS provider, without full inventory access | The GPS access permission — separate from inventory access |
| Only sees contacts for the lot they are working in | Access only to Current Lots Contacts — this one restricts when checked |
| Cannot see other people's tasks | The task view-others permission |
| Commissions tab or Attachments tab is missing on a deal | Hide Commissions Tab / Hide Attachments Tab — both remove access when checked |
| Can look at the warranty plans list but can't create a new plan | Warranty plan access is a level, not a checkbox: View lists plans, Add is required to create one |
| Can't see the Attachments tab on a customer or contact record | The attachment permission — View to see attachments, Edit to add or change them. This is the same permission that governs vehicle photos, and is separate from the deal's Hide Attachments Tab flag |
| Can order a new credit report but gets access denied opening previously run reports | Ordering and viewing are two different permissions: one governs running a new report, the other governs the stored report list |
| Can print deal paperwork but can't print or export a customer's payment schedule | The payment schedule belongs to Accounting, not to deal printing. Printing or exporting it needs Accounting at View or higher — deal print access on its own is not enough |
| Title and purchase details are greyed out on a car that has already been sold, though other panels still work | Once a vehicle is marked sold, its title and purchase/cost panels become read-only unless the role carries the separate Inventory right to change cost information on a sold vehicle. It is not a title-specific permission — there isn't one |
| Can open a deal but can't submit it to a lender, or the lender screen won't open at all | There is no separate permission for sending an application. The whole lender area — opening it, submitting, viewing decisions, resending — is governed by Deal Finance at Full. If someone can't send, they don't have it |
Navigate to the Roles Setup Page
To manage User Roles, first, click the Settings cogwheel located at the bottom of the leftmost sidebar. From the Settings pop-up menu, click Organization and select Roles.
Edit Access Rights
On the Roles setup page, you can see a list of predefined roles. You can customize the existing access rights for each role, or you can add your own.
Click on a default role to look at the default access rights.
There are multiple categories of access rights, each organized by different functions within DeskManager Online.
Each category contains options to allow or block specific features for users in this role. Checking a box will allow users to access that feature. An unchecked box will restrict that access.
Some categories contain drop-down boxes that allow you to give a user limited access to a specific function.
Create, Copy, or Delete a Role
While you can edit default roles, it is also possible to create new roles.
To create a new role from scratch, click on Add New in the top-left of the main Roles setup page.
You can also create a new role by clicking the Copy button on a pre-existing role. You may want to copy a role if you need to create a new one with similar access rights.
You may only delete roles that you have created. To delete a role you have created, navigate to the Roles setup page and click the trash can icon to the right of the role.
This will show a page asking you to confirm. When deleting a role, the users assigned to this role will lose all the access rights that they had through membership to this role.
Click OK to confirm.
Assign a Role
By assigning a role to a DeskManager Online user, you grant that user the access rights associated with that role.
To assign users to a role, navigate to the Roles setup page and click the Members button to the right of the role you would like to add users to.
If your dealership has multiple lots, you will be shown a list of the lots for your dealership.
Remember that a user could have a different Role in different lots.
Click Add Users in the top-left.
Click the name of the lot to show the users that are associated with that lot.
Then click the checkbox for each user you would like added to this role.
Once complete, click Save & Close.
You can also add members to each Role from the Users setup page.
Roles are assigned per lot with no inheritance and no "apply to all lots" shortcut — a role that should apply everywhere has to be checked under each lot. See Who Can See What: Permission Exceptions and Multi-Lot Access.
Two things worth knowing before you go hunting:
- A few permissions work backwards. Anything worded "Prevent…" or "Hide…" removes access when checked. See Who Can See What: Permission Exceptions and Multi-Lot Access.
- Permissions are per lot. A role granted at one lot does not carry to another, and access is evaluated against whichever lot the user is currently working in.
Three permission behaviours that surprise people
Setup access is all or nothing. Every screen under Setup is gated by the same single Settings permission at Full access for the lot you are currently working in. There is no way to let someone manage Taxes & Fees without also letting them manage Users, Roles, Providers and Billing.
Copying a role is a snapshot, not a link. Creating a role with the Copy button takes a one-time copy of the source role's access levels. Later changes to the original never flow through to the copy, so every copied role has to be maintained separately.
Not every sensitive-looking field is protected. The sensitive-data permission covers SSN and driver's licence. Bank account and routing details on a contact's Banks tab are ordinary fields — anyone who can view or edit that contact can see and change them.
The credit bureau (Metro 2) reporting permission is also its own separate activity: granting general Accounting access does not include it.
Comments
0 comments
Please sign in to leave a comment.