← Centro assistenza
Generale

User roles and permissions

How roles and permissions work in Cepaos: who can view, edit and manage each section of the platform.

Tempo di lettura stimato: 4 min

Why use roles?

A winery is run by people with different responsibilities: the owner needs to see everything, the winemaker records cellar operations, the vineyard manager works only with blocks and harvests, and the administrator focuses on invoicing and accounting. Cepaos roles let each person access only what they need.

Available roles

Cepaos has four predefined roles:

Administrator (Admin)

  • Full access to every module.
  • Can invite and remove users.
  • Can change other users' roles.
  • Can modify the winery configuration (plan, modules, integrations).
  • Can view and export financial reports.
  • Accesses billing and subscription data.

Typical use: winery owner, general manager.

Winemaker

  • Full access to Cellar: vessels, rackings, blends, bottling, cellar book.
  • Full access to Laboratory: analyses, protocols.
  • Read access to Vineyard: can view blocks and harvests but not edit them.
  • Access to Traceability: lookup and export.
  • No access to: billing, accounting, winery configuration, user management.

Typical use: winemaker, cellar master.

Vineyard manager

  • Full access to Vineyard: blocks, field book, harvests, phenology, irrigation, inputs.
  • Read access to Cellar: can view vessel status but not perform operations.
  • No access to: billing, accounting, configuration, user management.

Typical use: estate manager, agronomist.

Operator

  • Limited access to specific operations: can register harvests, log field-book data, record rackings.
  • Cannot delete or void records.
  • Cannot access financial reports or configuration.

Typical use: cellar staff, harvest workers.

Inviting users

Step by step

  1. Go to Settings > Team or Users section.
  2. Click + Invite user.
  3. Enter the person's email.
  4. Select the role.
  5. Click Send invitation.

The person receives an email with a link to create their account. Once they accept, they appear in the user list with the assigned role.

User limits

The maximum number of users depends on your plan. If you need more users than your plan includes, you can add extra seats or upgrade your plan.

Change a user's role

  1. Go to Settings > Team.
  2. Click the edit icon next to the user.
  3. Select the new role.
  4. Confirm the change.

The change is immediate — the next time the user signs in, they see the new role's permissions.

Remove a user

  1. Go to Settings > Team.
  2. Click the delete icon next to the user.
  3. Confirm.

The user loses access immediately. Their records in the system (harvests entered, analyses recorded) are kept linked to their name for audit purposes.

Permissions by module

This table summarizes what each role can do in each module:

ModuleAdminWinemakerVineyard MgrOperator
DashboardSee allSee cellarSee vineyardSee summary
BlocksCreate/Edit/DeleteView onlyCreate/EditView only
HarvestsAllView onlyCreate/EditCreate
Field bookAllView onlyCreate/EditCreate
VesselsAllCreate/EditView onlyRackings
BlendsAllCreate/EditNoNo
LaboratoryAllCreate/EditNoNo
TraceabilityAllView/ExportViewNo
ReportsAllCellarVineyardNo
CRM / CustomersAllNoNoNo
InvoicingAllNoNoNo
AccountingAllNoNoNo
SettingsAllNoNoNo

Security

  • Each user has their own credentials. Do not share accounts.
  • Sessions expire after 24 hours of inactivity.
  • If a user loses their device, the admin can revoke access immediately from Settings > Team.
  • Every action is logged with the name of the user who performed it (audit log).

Frequently asked questions

Can I create custom roles?

In the current version, roles are fixed. Custom roles with granular permissions are on the roadmap.

Can a user have more than one role?

No. Each user has a single role. If someone needs access to both vineyard and cellar, assign the Admin role or contact support to review your case.

How do I know who created each record?

Every record (harvest, racking, analysis, etc.) shows the name of the user who created it and the date/time. You can see this in the record detail.

Se hai altre domande, il team di supporto è disponibile. Contatta il supporto.