> ## Documentation Index
> Fetch the complete documentation index at: https://docs.jadenet.id/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles and access

> Understand role-based access, data scope, user responsibilities, and access reviews in JADE-ELS.

JADE-ELS uses role-based access control. What you can see and do depends on your assigned roles, office or branch scope, enabled modules, and the state of each record.

## Typical responsibilities

| Role               | Typical work                                                         |
| ------------------ | -------------------------------------------------------------------- |
| Operations         | Orders, shipping documents, milestones, charges, and job status      |
| Expense user       | Advance requests, settlements, and supporting evidence               |
| Cashier            | Payments, receipts, allocations, cash registers, and bank monitoring |
| Accounting         | AP, AR, journals, tax, reports, and period management                |
| Manager / approver | Approval queues, exceptions, profitability, and controls             |
| Administrator      | Users, roles, permissions, offices, and master data                  |

<Info>These are examples, not fixed system roles. Your organization can define roles that match its segregation-of-duties policy.</Info>

## Access rules users should expect

* A menu not assigned to your role does not appear.
* List views are filtered to the data scope permitted for your user.
* Create, edit, delete, approve, post, export, and report rights can be granted separately.
* Directly entering a restricted URL does not bypass authorization.
* Posted or period-locked records may remain visible but read-only.

## Account security

* Use an individual account and never share credentials.
* Use a strong, unique password.
* Change the initial password when **Change Password on First Logon** is enabled.
* Sign out on shared devices.
* Protect exported data and downloaded reports.
* Report unexpected access immediately.

## Administrator access review

<Steps>
  <Step title="Review active users">Confirm every active account belongs to a current staff member or approved service identity.</Step>
  <Step title="Review roles and scope">Confirm each user has only the modules, actions, offices, and data required for current duties.</Step>
  <Step title="Check privileged accounts">Limit administrator, approval, posting, and export permissions to authorized users.</Step>
  <Step title="Correct changes promptly">Deactivate leavers and update access when a person changes role, office, or responsibility.</Step>
  <Step title="Retain review evidence">Record who reviewed access, when it was reviewed, and which changes were approved.</Step>
</Steps>

For account creation, see [Register a user](/workflow/user-registration-23.2). For security controls, see [Data security](/security/data-security).
