Create or identify the user
A user belongs to the relevant tenant and operating context.
SimplyOS evaluates access through subscription entitlement, tenant module access, role permissions and user data scope.
A user belongs to the relevant tenant and operating context.
Roles are editable sets of granular permission codes rather than one fixed hardcoded permission level.
A role cannot open a module that the tenant subscription itself does not include.
Company, branch or customer restrictions can narrow what a user sees even when the role is otherwise broad.
Active sessions can be managed independently of the password, and revoked sessions are designed to stop working immediately.
All access layers are evaluated together.
Durat cannot bypass the user's permission and data scope.
Give each role the access needed for the job rather than broad access by default.