Vinitor uses a combined system of roles and permissions . Each user has exactly one role that determines their hierarchy level. In addition, permissions are assigned individually per user — they do not automatically derive from the role.
Modules and permissions work together
The effective permissions of a user are the intersection of the permissions assigned to them and the modules that your business has booked. A permission remains ineffective as long as the associated module is not active — for example, the PLANT_PROTECTION_WRITE permission only takes effect when the Plant protection module is booked.
Role Internal name Description Owner OWNERHighest hierarchy level. Full access to all functions including business settings and billing. Administrator ADMINManagement of employees, vineyards, tasks and all business functions. Lead LEADERTeam management with access to operational functions such as tasks, plant protection and reports. Employee WORKERStandard role for field workers. Access to assigned tasks, GPS tracking and reports.
Roles are hierarchically ordered: Owner > Administrator > Lead > Employee .
The hierarchy answers two separate questions . Both must be satisfied for a role change:
Am I allowed to edit this record at all? — Your own account, always. Other people’s accounts only if that person does not outrank you . You may edit colleagues of equal rank.
Am I allowed to assign this role? — Only roles at or below your own level. And never to yourself.
Own role Editable accounts Owner Everyone — Owner, Administrator, Lead, Employee Administrator Administrator, Lead, Employee (not: Owner) Lead Lead, Employee (not: Owner, Administrator) Employee Employee
Your own account is exempt from this — you may edit your own profile regardless of your role.
Own role Can assign Owner Owner, Administrator, Lead, Employee Administrator Administrator, Lead, Employee Lead Lead, Employee Employee Employee
Your own role is locked
Nobody can change their own role — neither up nor down. Even an Owner cannot demote themselves.
For handing over a business, that means: the new owner is set to Owner by the existing owner (people of equal rank may edit each other). The new owner can then demote the old one.
Both rules apply together
An example: a Lead with the USER_WRITE permission wants to make another Lead an Administrator. Rule 1 is satisfied — both are of equal rank, so she may edit the record. Rule 2 is not — Administrator is above her own level. The change is rejected.
The check runs on the server and applies to every route by which an account can be changed:
Operation What is checked Create user The role assigned must be at or below your level Edit user Record access and — if the role is changed — the new role Bulk editing As above, for every entry. If a single entry is not permitted, the entire change is discarded Archive user Record access. You cannot archive your own account Change permissions Record access. You cannot change your own permissions, and you cannot grant permissions that go beyond your own role Change profile picture Record access
If one of these rules applies, Vinitor rejects the change with the message Access denied — This operation is not allowed .
Tip
In the role selection fields, the dashboard offers you only the roles you are allowed to assign in the first place. The server check is the authoritative instance — it also applies where the interface shows more, for example in the table editing of the employee list.
Vinitor has 32 individual permissions that are assigned individually per user. The permissions are divided into the following categories:
Permission Description VINEYARD_READView vineyards and their details VINEYARD_WRITECreate and edit vineyards VINEYARD_DELETEDelete vineyards
Permission Description TASK_READView tasks TASK_WRITECreate and edit tasks TASK_DELETEDelete tasks TASK_TABLE_READView task table (matrix view)
Permission Description USER_READView employee list and detail view USER_WRITECreate and edit employees USER_DELETEArchive/delete employees USER_WRITE_SELFEdit own profile (name, contact details, profile picture)
Permission Description EQUIPMENT_READView machinery and equipment EQUIPMENT_WRITECreate and edit machinery and equipment EQUIPMENT_DELETEDelete machinery and equipment
Permission Description PLANT_PROTECTION_READView spray plans, active substances and tank mixes PLANT_PROTECTION_WRITECreate and edit spray plans, manage active substances and tank mixes
Permission Description REPORT_READView reports REPORT_WRITECreate and edit reports
Permission Description STATISTICS_READView analyses and statistics
Permission Description GPS_TRACKING_READView GPS tracking data GPS_TRACKING_WRITEManage GPS tracking settings MAP_READView map view
Permission Description TIME_TRACKING_READView time tracking overview TIME_TRACKING_EXPORTExport time tracking data as PDF or CSV TIME_TRACKING_EDIT_OWNEdit own working hours TIME_TRACKING_EDIT_ALLEdit working hours of all employees
Permission Description LEAVE_REQUESTRequest leave and absence LEAVE_APPROVEApprove or reject absence requests
Permission Description SALARY_READView salary entries SALARY_WRITECreate and edit salary entries
Permission Description COMPANY_MANAGEManage business settings BILLING_MANAGEManage billing and invoices