Source Badges (Where access comes from)
In the "Active Authorizations" list, every user has a badge indicating the origin of their access. Understanding these helps you know if you can edit the record or if it is controlled elsewhere.
| Badge | Meaning | Actionable? |
|---|---|---|
| MANUAL | Manual Grant: Access was explicitly given by an admin using the "New Auth" button. | Yes. Can be edited or revoked. |
| PROFILE | Profile Inherited: Access comes from a Job Profile (e.g., "Store Manager"). | No. You must remove the Profile from the user to revoke this. |
| PACKAGE | Package Inherited: Access is part of a subscribed system package or billing plan. | No. Controlled by system billing settings. |
| FOUNDER | Founder / God Mode: The user is a system owner and has permanent full access. | No. Cannot be revoked. |
| AUTO | Automatic Rule: Access granted by a dynamic system rule (e.g., "All Heads of Unit"). | No. Access ends automatically when the user no longer meets the criteria. Can be overwritten by manual permissions |
Status Indicators (State of the access)
- ALIGNED (Coincident): The user has a Manual grant that matches their Profile exactly. The manual record is redundant and can be removed.
- PENDING (Future): The "Valid From" date is in the future. The user cannot access the feature yet.
- Expired (Past): The "Valid Until" date has passed. Access is blocked.
-
MANUAL OVERRIDE(Conflict): The user has a Profile, but a Manual setting is forcing a different access level (e.g., restricting a Manager to "Read Only").