# Roles & permissions

# Roles &amp; permissions

Access is controlled per staff member. The catalogue and orders remain visible for read-only users; write actions are hidden when you do not have write access.

 <table id="bkmrk-leveltypical-access-"> <thead><tr><th>Level</th><th>Typical access</th></tr></thead> <tbody> <tr><td>**Reader**</td><td>View Items, Orders, Vendors, Receive lists. Cannot change quantities, create orders, receive, or save stock take.</td></tr> <tr><td>**Write**</td><td>Update items, run the ordering session, create orders, receive stock, save stock take.</td></tr> <tr><td>**Administrator**</td><td>Everything above, plus Settings (users, MFA/SMTP, hospital coding, lookups, audit). Administrators always have write access.</td></tr> </tbody> </table>

Module grants are configured under **Settings → Security**.