Fix & Enhance User Permissions
Creating a user & testing permissions - gave myself ONLY read access, but was able to create a campaign. Wasn’t able to delete the campaign, however.
Read-only shouldn’t be able to create anything.
User permissions are very confusing. Any user can do whatever actions they have access to to any location.
To fix this:
1. Make named access permissions that make sense. Ex: Viewer, Responder, Manager, Admin, etc. Allow Agency to specify what access they have in plain English (i.e., can respond to reviews, create campaigns, edit settings)
Make access flexible for locations: Give access to entire organization, or 1 or more locations (selectable)
This is a really basic requirement of most SaaS apps. You developed this feature around your CRUD API, but it doesn’t make sense to end-users! There are some unexpected behaviors around the permissions select boxes (described above).
Log in to comment and vote
Comments7
mannie@embedmyreviews.com
Feb 16
Pinned✅ Completed.
This required a full rebuild of our permissions system with role-based access, per-location controls, overrides, and API enforcement.
It’s now live and fully supported across the platform.
Read:
https://roadmap.embedmyreviews.com/changelog/rocket-emr-platform-update-team-controls-smarter-plans-analytics-and
Patrick Brennan
Jul 17, 2025
Found another area for improvement that could be revamped in the new user permissions logic:
Administrators don’t have access to the entire organization & its settings/reports. I believe this is a common thing. Administrator has access to everything. That’s the idea behind the admin, is to administer the whole account. Currently, even admin privilege users can’t access everything the account owner does.
During the revamp of user privileges, I would suggest it be designed in the most flexible way to future-proof the app:
Essentially, there is a user-access matrix where columns are user types (including custom ones) and rows are permission levels. You could stock have account owner, admin, manager, user, but allow a user to create a new user type of a custom name with check-boxes for permissions.
Again, permissions would need to be more semantic (i.e., respond to review, create & manage campaigns, manage report, view-only, etc) & less tied to software CRUD terminology.
Patrick Brennan
Jul 16, 2025
To add to this - With the new agency dashboard, it would be very useful to have a centralized user management area, as well as be able to list + manage users in the company profile page in the agency dashboard.
Patrick
Jan 23, 2025
Any updates on this? This is holding me back from making some pretty large deals. Bigger customers see this feature as a basic, must-have.
User permission levels:
Super Admin - agency users
Admin - can’t see agency features of the account, but can manage customers, etc.
Manager - Can manage organization & users in the org.
Location Manager - Can manage one or multiple locations
User - Can log in & read/respond to reviews
Better yet - allow agencies to specify all of these types of permissions in a custom user-permissions table.
Patrick
Jul 30, 2024
Another bug in permissions:
Logged in as users and DID NOT check reviews: delete. Was able to delete a review! I’d say this is an URGENT bug. Clients expect this basic security behavior.
Patrick
Jul 23, 2024
What would I need to do in order to get organization + location-specific access permissions implemented?
Patrick
Jul 23, 2024
This is REALLY broken. I added a user with ONLY the permissions below, but was able to access settings screens, and go through & begin adding an SMS provider to this account: