Skip to content

Permissions Reference

This page mirrors the current Admin > Identity & Access > Permissions screen. Permissions are organized by application. Within each application, administrators choose an option for each permission group.

Permissions overview table with roles as rows and applications as columns
The Permissions screen starts with an application overview; select an application to review the detailed permission groups.

For an explanation of how roles, users, direct grants, and the admin flag interact, see the Permissions admin guide.

Core

Core permissions control account actions that are not tied to one app.

Permission GroupOptionsWhat It Controls
Change Own PasswordNo Access, AllowedAllows the user to change their own direct ZynoSuite password.
Manage Own FingerprintsNo Access, AllowedAllows the user to enroll and remove their own fingerprints for ZynoWorkstation sign-in.

ZynoCRM

ZynoCRM permissions control contact records and the tabs inside a contact profile.

Permission GroupOptionsWhat It Controls
Customers & ContactsRead Only; Read & Create; Read, Create & EditOpens contact records, creates new contacts, and edits contact details when edit access is granted.
NotesNo Access; Read Only; Read & Create; Read, Create & EditShows, creates, edits, and deletes notes on a contact record.
FilesNo Access; Read Only; Read & Create; Read, Create & EditShows, uploads, edits, and deletes files attached to a contact record.
Form SubmissionsNo Access; Read OnlyShows submitted forms linked to a contact record.
MembershipsNo Access; Read; Read & EditShows contact membership details and allows membership changes when edit access is granted.
Payment MethodsNo Access; Read Only; Read & Create; Read, Create & EditShows, adds, edits, and removes saved payment methods on a contact record.

Some ZynoCRM permissions depend on another application also being available for the organization. For example, contact form submissions require ZynoForms access, and memberships and payment methods depend on ZynoSales access.

ZynoSales

ZynoSales permissions control Salespoint, bookings, products, reporting, fulfillment, transactions, and related sales workflows.

Permission GroupOptionsWhat It Controls
SalespointNo Access; On Zyno Desktop installs; On any deviceOpens Salespoint. The On Zyno Desktop installs option requires a ZynoWorkstation install; any-device access also allows browser and mobile Salespoint use.
DiscountsUnrestricted Pre-defined Discounts Only; All Pre-defined Discounts; Pre-defined & Custom DiscountsControls which discounts the user can apply in Salespoint. This setting applies when the user also has Salespoint access.
Open Cash DrawerNo Access; AllowedAllows the user to open a configured cash drawer from Salespoint when using ZynoWorkstation and cash payments are enabled.
Gift CardsNo Access; Read OnlyOpens gift card records, balances, and history.
ProductsNo Access; Read Only; Read & EditOpens the product catalog and allows product creation or editing when edit access is granted.
ReportsNo Access; Read OnlyOpens ZynoSales Reports, Cash Sessions, and Daily Closeouts.
TransactionsNo Access; Read Only; Read & ModifyOpens transaction lists and details. Modify access allows transaction actions such as refunds, cancellations, and adjustments.
FulfillmentNo Access; Read Only; Read & ModifyOpens fulfillment queues and order details. Modify access allows shipment, pickup, batch, label, and fulfillment-status actions.
BookingsNo Access; View Own; View & Modify Own; View All; View All, Modify Own; View & Modify AllOpens ZynoSales Bookings and controls whether the user can see or modify only their assigned bookings or all bookings. Modify access can also open Salespoint for booking-focused work even without full ZynoSales access.

::: note E-commerce visibility depends on organization settings and feature access. The current Permissions screen does not expose a separate E-Commerce permission row. :::

ZynoTalk

ZynoTalk access is managed outside the global permission grid. In the Permissions screen, ZynoTalk points administrators to the ZynoTalk admin area because phone access is assigned per number and per extension.

Use Numbers & Access to control which users or roles can access each number or extension. The exact ZynoTalk actions available to a user depend on the number or extension access granted there.

ZynoInventory

ZynoInventory permissions control item maintenance and stock counts.

Permission GroupOptionsWhat It Controls
Edit InventoryNo Access; Update Quantities; Create, Edit & Delete ItemsAllows stock quantity updates, or full item maintenance including creating, editing, deleting items, and updating quantities.

Users with ZynoInventory application access but no edit option can open inventory and review item information without changing records.

ZynoForms

ZynoForms access controls opening the ZynoForms submissions workspace. The current Permissions screen does not expose individual form creation or editing rows.

Form definition changes are handled through your organization's form-management process. For day-to-day use, staff use ZynoForms to review submitted forms and exports that are available to their role.

ZynoDisplay

ZynoDisplay permissions control setup and configuration for registered display devices.

Permission GroupOptionsWhat It Controls
Register DeviceNo Access; AllowedAllows the user to register a new display device with the organization.
Configure DisplaysNo Access; AllowedAllows the user to rename display devices and assign None, ZynoForm, or Web View content.

MSP

MSP permissions apply only to managed service provider accounts that administer multiple ZynoSuite organizations.

Permission GroupOptionsWhat It Controls
Sign into Client TenantNo Access; AllowedAllows access to the MSP administration area for managed client organizations.
Impersonate Client UsersNo Access; AllowedAllows the MSP user to act as a user inside a managed client organization when impersonation is available.

Still need help?

Can’t find what you’re looking for? Our support team is happy to help.