User Roles Guide
User Roles Guide
What are Roles?
In Janby Cloud, a Role defines what a user can see and do within the organization. Roles determine access to resources (products, programs, devices, reports, etc) and the actions that can be performed on them (view, edit, create or delete).
Janby Cloud defines six roles, organized in an incremental model: each role inherits all permissions from the previous role and adds new capabilities.
`
Operator → Manager → Executive → Corporate → Administrator → Owner
`
The Incremental Model
Each role is not an isolated set of permissions, but an extension of the previous one:
This means that, for example, anything a Manager can do can also be done by an Executive, a Corporate, an Administrator, and an Owner.
The Six Roles
1. Operator 👤
The base level. This role is designed for kitchen staff who operate directly on Janby equipment or mobile apps and usually do not need to access Janby Cloud (although they could to edit their user info).
Can:2. Manager 🧑🍳
Everything an Operator can do, plus editing capability (not creation) over their assigned resources.
Can (in addition to everything an Operator can do):3. Executive 👨💼
Everything a Manager can do, plus the ability to create and delete certain types of resources.
Can (in addition to everything a Manager can do):4. Corporate 🏢
Everything an Executive can do, plus the ability to manage the organizational structure (locations and workspaces).
Can (in addition to everything an Executive can do):5. Administrator 🔑
Full control over the organization. Can create, edit, and delete any resource, with no assignment restrictions.
Can (in addition to everything a Corporate can do):6. Owner 👑
Has exactly the same privileges as the Administrator. The difference is not one of permissions, but of origin: the Owner is the user who creates the organization at the time of registration, and this role is reserved to identify who founded it.
Can: Everything an Administrator can do. Distinctive trait: It is a unique role per organization, automatically assigned to the first user (the one who registers it), and is not granted to other users afterward.Permissions Summary Table
| Capability | Operator | Manager | Executive | Corporate | Administrator | Owner |
|---|:---:|:---:|:---:|:---:|:---:|:---:|
| Edit lower role users info | only their info | ✅ | ✅ | ✅ | ✅ | ✅ |
| View organization info | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
| Operate on equipment/mobile app | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
| View assigned resources | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
| Edit assigned resources | ❌ | ✅ | ✅ | ✅ | ✅ | ✅ |
| View production data and stock status | ❌ | ✅ | ✅ | ✅ | ✅ | ✅ |
| View cooking history data | ❌ | ✅ | ✅ | ✅ | ✅ | ✅ |
| Change batch status (consumed/cancelled/wasted) | ❌ | ✅ | ✅ | ✅ | ✅ | ✅ |
| Create products, programs, devices, batches, reports | ❌ | ❌ | ✅ | ✅ | ✅ | ✅ |
| Edit stock | ❌ | ❌ | ✅ | ✅ | ✅ | ✅ |
| Delete products, programs, devices, batches, reports, stock | ❌ | ❌ | ✅ | ✅ | ✅ | ✅ |
| Create/manage locations | ❌ | ❌ | ❌ | ✅ | ✅ | ✅ |
| Create/manage workspaces | ❌ | ❌ | ❌ | ✅ | ✅ | ✅ |
| Assign resources to workspaces | ❌ | ❌ | ❌ | ✅ | ✅ | ✅ |
| Change users' roles | ❌ | ❌ | ❌ | ❌ | ✅ | ✅ |
| Configure organization settings | ❌ | ❌ | ❌ | ❌ | ✅ | ✅ |
Assigning and Changing Roles
⚠️ Important Notice: Role Assignment Restrictions
When a user with Manager role or above edits another user, they can set that user's role to their own role level or lower. However, be aware that if you promote a user to your same role, you will no longer be able to edit them, since you can only edit users with lower roles than yours.
Example: If you are a Manager and you change another user's role from Operator to Manager, you will not be able to edit that user afterward. This is by design to prevent role elevation conflicts.If you need to continue editing a user, keep their role at least one level below your own role.
Frequently Asked Questions
Q: By default if I have no workspaces created, what do users see?A: If there are no workspaces created, users will be able to see the all resource types they have permission to see. If you want to compartmentalize/isolate resources by work units or other business logic, it is recommended to create workspaces.
Q: What's the difference between Administrator and Owner?A: In terms of permissions, none — both have full control. The difference is that the Owner is the user who founded the organization; it's a matter of origin, not an additional permission level.
Q: Can there be more than one Owner in an organization?A: Yes. Although Owner role is automatically assigned to the user who registers the organization, afterwards owners can add more Owner users.
Q: If I change a user's role, do they lose access to resources they had assigned?A: It depends on whether the new role requires resource assignment (Operator/Manager/Executive/Corporate) or not (Administrator and above). When moving to a role without assignment restrictions, the user automatically gains expanded access.
Best Practices
1. Assign the minimum necessary role
Give each user the lowest role that allows them to do their job. This reduces the risk of accidental changes to products or programs in production.
2. Use Operator for floor staff
Staff who only execute programs on kitchen equipment or app don't need more than the Operator role.
3. Reserve Executive and above for process designers
The ability to create and delete products/programs should be limited to those who define recipes and processes, to maintain traceability and avoid duplicates.
4. Limit Administrator and Owner
The fewer users who have full control over users and settings, the lower the risk of uncontrolled changes to the organization.
5. Review Operator and Manager assignments periodically
When an employee changes position or location, update which resources are assigned to them.