- Home
- Getting Started
- Account & Settings
- Roles & Add-On Access
- Settings
- Agentic
- White Label
- Agents & Engines
- Engines
-
Agents
- Overview
- Core Agents
- Core Agents
- Matrix Agent
- Audit Agent
- Industry Agents
- Patent Agent
- Add-On Modules
-
Manufacturing
- Manufacturing
- Overview
- Work Orders
- Production Scheduling
- Shop Floor Monitor
- OEE Dashboard
- Production Counters
- Plant & Process Setup
- Work Centers
- Bill of Materials
- Manufactured Products
- Work Instructions
- Quality Operations
- Overview
- Inspection Plans
- Quality Checklist
- Non-Conformance (NCR)
- SPC Charts
- Traceability (4M)
- Maintenance Operations
- Overview
- Asset Registry
- Preventive Maintenance
- Work Orders
- Spare Parts
- Reliability Dashboard
- Inventory Operations
- Overview
- Material Staging
- WIP Tracking
- Kanban Replenishment
- Material Consumption
- Assets
- Asset Health
- Legal
- Construction
- Government
- Education
- Energy
- Agriculture
- Healthcare
- RevOps
- Ecommerce Operations
- Financial Audit & Fintech Ops
- Insurance
- Hospitality
- Real Estate
- Patent & R&D Operations
- Automotive & Fleet Management Ops
- Customs & Global Trade
- Enterprise & Technical
-
Enterprise Operations
- Enterprise Operations
- Overview
- Enterprise Operations Guide
- Compliance & Docs
- Overview
- Approval Workflow
- Expiry Reminders
- Document Control
- Audit Trail
- Compliance Radar
- Contracts & Warranty
- Overview
- Active Contracts
- Warranty Check
- Service Billing
- Field Service
- Overview
- Dispatch Board
- Job Management
- Van Inventory
- Performance Dashboard
- Service Desk
- Overview
- Service Requests
- SLA Monitor
- Knowledge Base
- Procurement & Vendor
- Purchase Orders
- Vendor Portal
- RFQ Management
- QHSE
- Overview
- Incident Reporting
- Permit to Work
- Safety Inspections
-
Security & Compliance
- Threat & Monitoring
- Overview
- Security Hub
- Security Audit
- IAM Visualizer
- Dependency Scanner
- Secret Scanner
- Secret Vault
- Traffic Monitor
- Audit Trail
- Threat Simulator
- Compliance Radar (MatrixAgent)
- Identity & Compliance
- Overview
- PPTX Auditor
- PDF Auditor
-
Engineering & Infrastructure
- DevOps & Infrastructure
- Overview
- Cron Builder
- CI/CD Pipeline
- Containers
- Log Streamer
- Secrets Management
- Health Monitor
- Infrastructure as Code
- Developer Tools
- Overview
- Nerve Center
- Git Diff Viewer
- Regex Tester
- JSON Transformer
- Workflow Optimizer
- Execution Replay
- Workflow Editor
- Dev Hub Terminal
- Security Hub
- Graph View
- Terminal Editor
- API Playground
- DSL Compiler
- Database Tools
- Overview
- Database Manager
- ORM Mapper
- SQL Formatter
- Schema Visualizer
- Visual Query Builder
- Seed Data Generator
- Custom Collections
- QA & Test
- Overview
- Flake Tracker
- Artifact Vault
- Web Test Module
- Test Plan & Runner
-
Data & Intelligence
- AIOps & Intelligence
- Overview
- Agents
- Agent Architect
- Model Center
- Prompt Lab
- Knowledge Base
- Agent Persona Editor
- Tool / Function Registry
- Observability & Logs
- DataOps & Analytics
- Overview
- Data Inspector
- AI Predictive Models
- Core Modules
- Ads & Social Media
- AI Assistants
- API & Integration
- App Groups
- Appointment Booking
-
Automation
- Automation
- Overview
- Workflow Editor
- Monitoring
- Execution Heatmap
- Workflow Pulse
- Trigger Control
- Task Scheduler
- Integration Hub
- Rule Engine
- Pipeline Designer
- Workflow Editor
- Overview
- Triggers
- Manual Input
- Data Sources
- Ecommerce
- Document Management
- Logic & Transform
- AI Agents
- Knowledge / AI
- Validation & Security
- Integrations
- Outputs
- Document Generation
- Image Generation
- Video Generation
- Coming Soon
- Call Center
- Collaboration
- Community
- Creative Studio
- CRM
- Fleet & Logistics
-
Finance
- Hub
- Finance Hub
- Accounting Hub
- Treasury & Banking Hub
- Commercial Accounts Hub
- Invoicing & Billing Hub
- Reporting & Analytics Hub
- Grid View
- Overview
- Accounting AI Assistant
- Treasury
- Invoice Manager
- Expense Management
- Financial Accounts
- Payroll
- Accounts Receivable
- Accounts Payable
- Bank Reconciliation
- Budget & Forecasting
- Expenses & Budget
- Profit & Loss
- Tax & Compliance
- Galleries & Curation
- Google Display Ads
-
Human Resources
- Hub
- Core HR & Organization Hub
- Talent & Acquisition Hub
- Time & Operations Hub
- Grid View
- Overview
- Org Chart
- Organization
- Roles & Permissions
- Employee Skills
- Employees
- Employees & Assignees
- Recruitment
- CV Screening
- Document Entry
- Asset Manager
- Leave Management
- Expense Management
- Overtime
- Performance KPI
- HR Reports
- Legal & Support
- Logistics
- Map Explorer
- Marketing
- My Workspace
- Plans & Pricing
- Point of Sale
- Product Management
- Purchase
- Sales
- Semantic Search
- Strategy & Fundraising
- Warehouse
- Website
- Productivity
- Project Management
- Documents
- Learning (LMS)
-
Creator Tools
- Overview
- Brand Identity Creator
- Template Creator
- Image Creator
- Overview
- Getting Started
- Image Generation
- Remix
- Upscale
- Magic Replace
- Remove Background
- Reframe
- Describe
- Magic Tags
- Magic Fill
- Style Transfer
- Style Preset
- Social Media Images
- Prompting Guide
- Video Creator
- Overview
- Getting Started with Video
- Text to Video
- Image to Video
- AI Video Transition
- Video Effects
- Scene Builder
- Short Film Creator
- Audio Creator
- Overview
- AI Audio
- Text to Speech
- Voice Cloning
- Music Generation
- Sound Effects
- Writer Tools
- App Factory
- Research
- Utilities
Roles & Permissions
Decentralized Role Management (RBAC). Each add-on defines its own roles and capabilities in its own scoped screen, while HR sees every module's roles in one master matrix with a domain filter and override control.
Overview
TotalApp uses Decentralized Role Management: every add-on ships with its own Roles screen — the first icon in its sidebar, right after My Apps — where that add-on's manager creates roles and binds them to capabilities without ever leaving the add-on. A Legal firm administrator opens Legal → Roles and works only with Legal roles and Legal capabilities; they never see Healthcare or Payroll permissions.
All of these roles are written to a single, tenant-scoped store, and every role is tagged with a domain (LEGAL, HEALTHCARE, PAYROLL, …) in the background — the manager never fills in a "type" field. HR then reads that same store as a master matrix in HR → Organization → Roles & Permissions, where an HR admin can see every module's roles at once, filter by domain, and override any of them.
Implicit Domain Tagging
The domain is set from the screen's context, not by the user. Create a role inside the Legal add-on and it is stored with domain: LEGAL automatically. Add-on screens then filter to GLOBAL plus their own domain, so each add-on shows only relevant roles — while HR, the single source of truth, sees the whole set.
Roles vs. Capabilities
A Role is a named bundle (e.g. Paralegal). A Capability is a single fine-grained permission scoped to a domain (e.g. Draft Contracts, Approve Contracts). You bind capabilities to a role once; assigning that role to a person then grants all of its capabilities at once, instead of ticking permissions per person.
Scoped Capability Picker
When a Legal manager builds a role, the capability list shows only Legal (plus any cross-cutting Global) capabilities. This scoping is a security boundary: no add-on can grant another add-on's permissions.
Approver Flag
Some capabilities (e.g. Approve Contracts, Manage Legal Staff) carry approval authority. A role that includes any of them is automatically marked as an Approver role, surfaced with a badge in both the add-on screen and the HR matrix.
Out-of-the-Box Roles
Each add-on seeds sensible default roles the first time its Roles screen is opened, so a customer can start adding staff without defining a single role by hand. Defaults are marked Default; roles you create are marked Custom.
Legal Out-of-the-Box Roles
Installing the Legal add-on seeds three ready-to-use roles:
| Role | Capabilities |
|---|---|
| Senior Partner | All Legal capabilities + approval authority (Approver) |
| Associate Lawyer | Standard Legal capabilities for day-to-day matter work |
| Paralegal | Restricted read/draft capabilities in support of lawyers |
Creating a Custom Role (Add-on)
- Open the add-on's Roles screen (e.g. Legal → Roles).
- Click Add Role.
- Enter a Role Name (e.g. "Trainee Lawyer") and an optional Description.
- Tick the Capabilities this role should grant — only this add-on's (and Global) capabilities are shown.
- Click Save. The role is stored with this add-on's domain tag and appears immediately in the list — and in HR's master matrix.
Edit or delete a role from its row action; deleting asks for inline confirmation first.
HR Master Matrix
In HR → Organization → Roles & Permissions, HR sees every domain's roles in one table. A Domain filter dropdown narrows the view (e.g. "show only Healthcare roles"), and each row shows the role's domain badge, capability count, and whether it's a Default or Custom role. HR can edit or delete any role here — including ones created inside an add-on — giving HR final override control while day-to-day role authoring stays decentralized in each add-on.
Global Search
Each add-on's Roles screen is searchable from the top-bar global search — searching "roles" surfaces the module-qualified result (e.g. Roles (Legal)), so you can jump straight to a specific add-on's roles from anywhere.
Frequently Asked Questions
roles/roles.json), each tagged with its domain. Add-on screens filter that store by domain; HR reads the whole store as a master matrix.