- Home
- Getting Started
- Account & Settings
- Roles & Add-On Access
- Settings
- Agentic
- White Label
- Agents & Engines
- Engines
-
Agents
- Overview
- Core Agents
- Core Agents
- Matrix Agent
- Audit Agent
- Industry Agents
- Patent Agent
- Add-On Modules
-
Manufacturing
- Manufacturing
- Overview
- Work Orders
- Production Scheduling
- Shop Floor Monitor
- OEE Dashboard
- Production Counters
- Plant & Process Setup
- Work Centers
- Bill of Materials
- Manufactured Products
- Work Instructions
- Quality Operations
- Overview
- Inspection Plans
- Quality Checklist
- Non-Conformance (NCR)
- SPC Charts
- Traceability (4M)
- Maintenance Operations
- Overview
- Asset Registry
- Preventive Maintenance
- Work Orders
- Spare Parts
- Reliability Dashboard
- Inventory Operations
- Overview
- Material Staging
- WIP Tracking
- Kanban Replenishment
- Material Consumption
- Assets
- Asset Health
- Legal
- Construction
- Government
- Education
- Energy
- Agriculture
- Healthcare
- RevOps
- Ecommerce Operations
- Financial Audit & Fintech Ops
- Insurance
- Hospitality
- Real Estate
- Patent & R&D Operations
- Automotive & Fleet Management Ops
- Customs & Global Trade
- Enterprise & Technical
-
Enterprise Operations
- Enterprise Operations
- Overview
- Enterprise Operations Guide
- Compliance & Docs
- Overview
- Approval Workflow
- Expiry Reminders
- Document Control
- Audit Trail
- Compliance Radar
- Contracts & Warranty
- Overview
- Active Contracts
- Warranty Check
- Service Billing
- Field Service
- Overview
- Dispatch Board
- Job Management
- Van Inventory
- Performance Dashboard
- Service Desk
- Overview
- Service Requests
- SLA Monitor
- Knowledge Base
- Procurement & Vendor
- Purchase Orders
- Vendor Portal
- RFQ Management
- QHSE
- Overview
- Incident Reporting
- Permit to Work
- Safety Inspections
-
Security & Compliance
- Threat & Monitoring
- Overview
- Security Hub
- Security Audit
- IAM Visualizer
- Dependency Scanner
- Secret Scanner
- Secret Vault
- Traffic Monitor
- Audit Trail
- Threat Simulator
- Compliance Radar (MatrixAgent)
- Identity & Compliance
- Overview
- PPTX Auditor
- PDF Auditor
-
Engineering & Infrastructure
- DevOps & Infrastructure
- Overview
- Cron Builder
- CI/CD Pipeline
- Containers
- Log Streamer
- Secrets Management
- Health Monitor
- Infrastructure as Code
- Developer Tools
- Overview
- Nerve Center
- Git Diff Viewer
- Regex Tester
- JSON Transformer
- Workflow Optimizer
- Execution Replay
- Workflow Editor
- Dev Hub Terminal
- Security Hub
- Graph View
- Terminal Editor
- API Playground
- DSL Compiler
- Database Tools
- Overview
- Database Manager
- ORM Mapper
- SQL Formatter
- Schema Visualizer
- Visual Query Builder
- Seed Data Generator
- Custom Collections
- QA & Test
- Overview
- Flake Tracker
- Artifact Vault
- Web Test Module
- Test Plan & Runner
-
Data & Intelligence
- AIOps & Intelligence
- Overview
- Agents
- Agent Architect
- Model Center
- Prompt Lab
- Knowledge Base
- Agent Persona Editor
- Tool / Function Registry
- Observability & Logs
- DataOps & Analytics
- Overview
- Data Inspector
- AI Predictive Models
- Core Modules
- Ads & Social Media
- AI Assistants
- API & Integration
- App Groups
- Appointment Booking
-
Automation
- Automation
- Overview
- Workflow Editor
- Monitoring
- Execution Heatmap
- Workflow Pulse
- Trigger Control
- Task Scheduler
- Integration Hub
- Rule Engine
- Pipeline Designer
- Workflow Editor
- Overview
- Triggers
- Manual Input
- Data Sources
- Ecommerce
- Document Management
- Logic & Transform
- AI Agents
- Knowledge / AI
- Validation & Security
- Integrations
- Outputs
- Document Generation
- Image Generation
- Video Generation
- Coming Soon
- Call Center
- Collaboration
- Community
- Creative Studio
- CRM
- Fleet & Logistics
-
Finance
- Hub
- Finance Hub
- Accounting Hub
- Treasury & Banking Hub
- Commercial Accounts Hub
- Invoicing & Billing Hub
- Reporting & Analytics Hub
- Grid View
- Overview
- Accounting AI Assistant
- Treasury
- Invoice Manager
- Expense Management
- Financial Accounts
- Payroll
- Accounts Receivable
- Accounts Payable
- Bank Reconciliation
- Budget & Forecasting
- Expenses & Budget
- Profit & Loss
- Tax & Compliance
- Galleries & Curation
- Google Display Ads
-
Human Resources
- Hub
- Core HR & Organization Hub
- Talent & Acquisition Hub
- Time & Operations Hub
- Grid View
- Overview
- Org Chart
- Organization
- Roles & Permissions
- Employee Skills
- Employees
- Employees & Assignees
- Recruitment
- CV Screening
- Document Entry
- Asset Manager
- Leave Management
- Expense Management
- Overtime
- Performance KPI
- HR Reports
- Legal & Support
- Logistics
- Map Explorer
- Marketing
- My Workspace
- Plans & Pricing
- Point of Sale
- Product Management
- Purchase
- Sales
- Semantic Search
- Strategy & Fundraising
- Warehouse
- Website
- Productivity
- Project Management
- Documents
- Learning (LMS)
-
Creator Tools
- Overview
- Brand Identity Creator
- Template Creator
- Image Creator
- Overview
- Getting Started
- Image Generation
- Remix
- Upscale
- Magic Replace
- Remove Background
- Reframe
- Describe
- Magic Tags
- Magic Fill
- Style Transfer
- Style Preset
- Social Media Images
- Prompting Guide
- Video Creator
- Overview
- Getting Started with Video
- Text to Video
- Image to Video
- AI Video Transition
- Video Effects
- Scene Builder
- Short Film Creator
- Audio Creator
- Overview
- AI Audio
- Text to Speech
- Voice Cloning
- Music Generation
- Sound Effects
- Writer Tools
- App Factory
- Research
- Utilities
Roles & Add-On Access
An end-to-end overview of TotalApp's Role-Based Access Control (RBAC), add-on package entitlement, and screen-guarding (ModuleGuard) architecture.
1. Conceptual Model
The system is built on a four-layer hierarchy: Tenant → Purchased Packages (Entitlement) → Domain Capabilities → Roles → Employee assignedRoles ("hat").
| Concept | What it is |
|---|---|
| Domain | An add-on's RBAC tag (LEGAL, HEALTHCARE, MOM…). Every role and capability belongs to a domain. |
| Capability | An atomic permission written as domain:resource:action (legal:contract:approve). |
| Role | A named bundle of capabilities (Senior Partner, Plant Manager). It is domain-tagged. |
| assignedRole (hat) | A role assigned to a person. One person can hold roles in multiple domains ("multi-hat"). Assigning a role copies its capabilities onto the person (auto-grant). |
| Entitlement (package) | The add-on packages a tenant has activated. |
Capability ≠ Skill
A capability decides what a person can do in the platform (a system permission). A skill (Python, Laparoscopy, Contract Law) is a personal competency managed by HR — it does not affect access. A role binds capabilities; assigning a "Paralegal" role to someone instantly grants all of that role's capabilities.
2. Decentralized Role Management
Every add-on has its own Roles screen, but all roles live in a single tenant store. Each role is tagged with its domain in the background — you never fill in a "type" field; the tag comes from the screen you're on (implicit tagging).
Add-on Scoping
An add-on screen shows only GLOBAL + its own domain's roles and capabilities. A Legal manager cannot see Healthcare capabilities — a security boundary.
HR Master Matrix
HR → Organization → Roles & Permissions shows every domain's roles in one matrix, offers a domain filter, and provides final override over add-on roles.
Out-of-the-Box Roles
When an add-on package is active, the first time its Roles screen is opened the system seeds default roles automatically. A customer can add staff without defining a single role by hand.
3. Package Entitlement
Which add-ons each tenant has activated is stored per tenant (activePackages). The application side reads its own entitlement; the admin side (cross-tenant) can write any tenant's — the same file. So what an admin activates is exactly what ModuleGuard reads (one SSoT).
4. ModuleGuard — Two-Level Screen Protection
Every add-on screen is wrapped in <ModuleGuard> and rendered inside the app layout — a blocked screen shows a friendly Upsell/403 panel instead of a blank page or a 500 error.
Level 1 — Entitlement (Paywall)
Has the tenant purchased this add-on package? If not → an Upsell/Upgrade screen: "The [Module] module is not included in your subscription. Upgrade your plan or contact your administrator."
Level 2 — RBAC (Governance / Operational)
System/Governance data (Roles, Staff-Master) is admin-only; Operational data (Jobsites, Zones, Work Centers, Fields…) is open to any user holding a role in that domain. Otherwise → 403 Access Denied.
| User | Governance | Operational |
|---|---|---|
| Administrator (or local/demo) | Allowed | Allowed |
| User holding a domain role | 403 Denied | Allowed |
| User without a domain role | 403 Denied | 403 Denied |
| Package not active | Paywall | Paywall |
5. UI Visibility — Hiding Governance Cards
A 403 isn't enough; an unauthorized user should never even see governance cards. The sidebar and My Apps don't render these cards for non-admins. Each add-on's setup screens are split into two titled groups: OPERATIONAL SETUP (open to operational staff) and ADMINISTRATION & ACCESS (Roles + Staff-Master; admins only).
6. Staff Assignment — Auto-Grant & Multi-Hat
- Auto-grant: selecting a role attaches the role's capabilities to the person automatically; no separate trip to HR to grant permissions.
- Multi-hat (+ Add Existing Employee): an existing employee is added to another add-on without creating a duplicate record. For example, one person can hold both LEGAL: Senior Partner and HEALTHCARE: Advisor hats.
- Detach: removing a person from a team revokes that domain's hats (the employee record and HR history are never deleted).
7. Path & Title Standard
The URL is generic and domain-prefixed (/{domain}/roles, /{domain}/staff); the title is domain-specific (/legal/staff → "Legal Team", /mom/staff → "Plant Workers").