Overview
Permissions (Kennel, Store, Office, Operations, Advertisement, applet scopes) are assigned per user in admin. API keys for tablets receive a subset via applet catalog. Superadmin-tier permissions are not assignable by kennel admins.
Steps
- Map job roles to permission bundles before hiring season.
- Test a “kennel tech” login with only Kennel + Operations tasks.
- Review API keys quarterly on API Settings.
Practical note
Over-permissioned interns become over-powered ex-interns.
Admin setup
All user management in Users—no self-serve superadmin.
Advanced options
API keys for tablets separate from user JWT sessions.
Troubleshooting
User sees module in API but not sidebar: navigation assignment hidden it.