SNB Production Workflow

SNB Production WorkflowTrainingRead a role's permissions

Read a role's permissions

Permissions are grouped by the part of SNB they govern. Seven groups work the same way. The eighth — the factory floor — works differently, and the difference is worth understanding.

You need an administrator account.

Stop

Do not open an existing role to look around in. Roles are shared, and a tick-box changed by accident changes what real people can do, immediately, with nothing to warn you and no undo.

This walkthrough opens a new role instead, reads the permission list, and leaves without saving. Nothing is created and nothing is changed.

1Open a blank role

Open Roles under System, then click New role.

You get an empty form in two parts. Role details is the name. Permissions — everything below it — is the role itself.

The line under the Permissions heading is worth reading. It says: “Toggle group access. Where a group has View, Create/Edit/Delete require it. The Kiosk group is one permission per button on the factory screen.” The rest of this walkthrough is that sentence, explained.

Open a blank role — Read a role's permissions

2Look at the eight groups

Permissions are gathered into eight groups, each covering one part of SNB:

Production, Inventory, Customers & Projects, Design, Workflow, Delivery, Kiosk (factory floor) and System.

A role is built by ticking boxes in these groups. Nothing else defines it.

Look at the eight groups — Read a role's permissions

3Read a normal group

Seven of the eight look like this one. Four boxes:

View may open this part of SNB and read it
Create may add new records
Edit may change existing ones
Delete may remove them

View is the foundation. The other three need it — being allowed to change something you are not allowed to see would be meaningless, so ticking any of them requires View as well.

Read a normal group — Read a role's permissions

4Read the Kiosk group

Now look at Kiosk (factory floor). It has six boxes, and they are not View, Create, Edit and Delete. They are named after buttons:

Start, Complete, Hold, Resume, Report and Split.

There is no View.

Why it works this way

Both differences come from the same fact: the kiosk is not like the rest of SNB.

The kiosk screens are the touch screens on the factory floor. Nobody signs in to them. A worker walks up to the screen for their department and it is already showing the jobs waiting there — no password, no account, nothing to open. They tap their PIN only at the moment they press a button, and the PIN says who did this, not who may look.

So there is nothing for a View permission to control. The board is visible to whoever is standing in front of it, which on a factory floor is the whole point — a screen you have to sign in to read is a screen nobody reads.

And because every action is a distinct thing a person may or may not be trusted with, the permissions are the buttons themselves. A delivery driver may be allowed to Start and Complete a job but not to Split one into pieces or to Hold it. That does not fit into “create, edit, delete” — those four words would have to be stretched to mean things they do not mean, and the tick-boxes would then lie about what they grant. Six buttons, six permissions, each one saying exactly what it does.

Note

What the worker actually sees. A button their role does not allow is not hidden — it is shown, dimmed, in the same place, the same size, and it explains itself when tapped.

That is deliberate. Buttons that appear and disappear depending on who last used the screen are worse than a refusal: an operator reaches for where a button was, finds nothing, and has no idea whether the system is broken, the job is different, or they have done something wrong. A dimmed button that says why is a screen that still makes sense.

Read the Kiosk group — Read a role's permissions

5Ticking a box

Ticking Start in this group would let anyone holding this role press Start on a kiosk. Nothing more.

Notice how narrow that is, and how readable. You can hand somebody the ability to begin a job without also handing them the ability to put one on hold or break it into pieces.

Ticking a box — Read a role's permissions

6Leave without saving

Click Cancel.

You are back at the list of roles, and it is exactly as it was — the role you were looking at was never created.

Note

Cancel is the safe way to explore this screen. Nothing is written until you press Create, so you can open a blank role, read every group, and back out having changed nothing.

Leave without saving — Read a role's permissions

What happens next

If you had saved, the new role would appear in the list with a Permissions count matching the boxes you ticked, ready to be given to somebody on their account.

Changes to a role take effect immediately for everyone holding it. There is no publish step and no delay.

If it goes wrong

What you see What it means
You ticked Create and View ticked itself Expected. The other three permissions require View, so it is added for you.
A person still cannot do something after you ticked its box Check which role they actually hold — see Change what someone is allowed to do. Ticking a box on the wrong role changes nothing for them and quietly changes something for somebody else.
A kiosk button is greyed out on the factory floor That role does not hold that button’s permission. The button is dimmed rather than hidden on purpose; the fix is on this screen, in the Kiosk (factory floor) group.
You are not sure whether you changed something If you left with Cancel, you did not. If you pressed Create or Save changes, you did, and it is already live.