Access to the connector is controlled by a single role picker on each user (Settings > Users > 3PL Connector): Read Only, Ops or Admin. Each level includes everything below it, and every button in the app is role-aware - users simply do not see actions they cannot perform.
| Capability | Read Only | Ops | Admin |
|---|---|---|---|
| See dashboard, all Operations pages, Sync Log | yes | yes | yes |
| Open instances, mappings, providers (read) | yes | yes | yes |
| See credentials / Connection tab | no | no | yes |
| Run operations (push orders, polls, inventory sync, match) | no | yes | yes |
| Send an order / create a return from the sales order | no | yes | yes |
| Push products, add in bulk, mark as existing | no | yes | yes |
| Retry / acknowledge Sync Log entries | no | yes | yes |
| Email Support from a log entry | no | yes | yes |
| Process an unmatched return's receipt | no | no | yes |
| Re-open an acknowledged error | no | no | yes |
| Fetch Despatch Now (manual despatch pull) | no | no | yes |
| Create/edit instances, mappings, settings, providers | no | no | yes |
| Activate / pause instances | no | no | yes |
Notes on the model: