Skip to main content

Fix & Enhance User Permissions

Creating a user & testing permissions - gave myself ONLY read access, but was able to create a campaign. Wasn’t able to delete the campaign, however.

Read-only shouldn’t be able to create anything.

User permissions are very confusing. Any user can do whatever actions they have access to to any location.

To fix this:

1. Make named access permissions that make sense. Ex: Viewer, Responder, Manager, Admin, etc. Allow Agency to specify what access they have in plain English (i.e., can respond to reviews, create campaigns, edit settings)

  1. Make access flexible for locations: Give access to entire organization, or 1 or more locations (selectable)

This is a really basic requirement of most SaaS apps. You developed this feature around your CRUD API, but it doesn’t make sense to end-users! There are some unexpected behaviors around the permissions select boxes (described above).

Status: Completed7 comments

Log in to comment and vote

Comments7

  • mannie@embedmyreviews.com

    Team•

    Feb 16

    Pinned

    ✅ Completed.
    This required a full rebuild of our permissions system with role-based access, per-location controls, overrides, and API enforcement.
    It’s now live and fully supported across the platform.

    Read:

    https://roadmap.embedmyreviews.com/changelog/rocket-emr-platform-update-team-controls-smarter-plans-analytics-and

  • Patrick Brennan

    •

    Jul 17, 2025

    Found another area for improvement that could be revamped in the new user permissions logic:

    Administrators don’t have access to the entire organization & its settings/reports. I believe this is a common thing. Administrator has access to everything. That’s the idea behind the admin, is to administer the whole account. Currently, even admin privilege users can’t access everything the account owner does.

    During the revamp of user privileges, I would suggest it be designed in the most flexible way to future-proof the app:

    Essentially, there is a user-access matrix where columns are user types (including custom ones) and rows are permission levels. You could stock have account owner, admin, manager, user, but allow a user to create a new user type of a custom name with check-boxes for permissions.

    Again, permissions would need to be more semantic (i.e., respond to review, create & manage campaigns, manage report, view-only, etc) & less tied to software CRUD terminology.

  • Patrick Brennan

    •

    Jul 16, 2025

    To add to this - With the new agency dashboard, it would be very useful to have a centralized user management area, as well as be able to list + manage users in the company profile page in the agency dashboard.

  • Patrick

    •

    Jan 23, 2025

    Any updates on this? This is holding me back from making some pretty large deals. Bigger customers see this feature as a basic, must-have.

    User permission levels:
    Super Admin - agency users
    Admin - can’t see agency features of the account, but can manage customers, etc.
    Manager - Can manage organization & users in the org.
    Location Manager - Can manage one or multiple locations
    User - Can log in & read/respond to reviews

    Better yet - allow agencies to specify all of these types of permissions in a custom user-permissions table.

  • Patrick

    •

    Jul 30, 2024

    Another bug in permissions:

    Logged in as users and DID NOT check reviews: delete. Was able to delete a review! I’d say this is an URGENT bug. Clients expect this basic security behavior.

  • Patrick

    •

    Jul 23, 2024

    What would I need to do in order to get organization + location-specific access permissions implemented?

  • Patrick

    •

    Jul 23, 2024

    This is REALLY broken. I added a user with ONLY the permissions below, but was able to access settings screens, and go through & begin adding an SMS provider to this account: