Control what each person can do with roles and policies
What it is
Zelun decides who may do what with two building blocks.
- A policy is one permission. It says that certain people can, or cannot, do certain things in certain places. For example: "this person can change this location".
- A role is a named bundle of policies, such as a job title. You give the role a name, attach permissions to it, and assign people to it. Everyone in the role gets everything the role contains.
Two kinds of access work without any policy or role. The Zelun administrator account can reach everything. The owner of a company can manage that company, its locations and its team without anything being set up. Roles and policies are for granting access beyond that.
Important: the Policies and Roles screens appear only for the Zelun administrator account. They are not in a shop owner's menu. If you need someone to have access you cannot give yourself, ask Zelun support to set it up using what this article describes.
Before you start
- Decide who needs the access, and what they should be able to do.
- Know the place: every company, one company, all locations of one company, or one location.
- The person must appear in the directory of people. If they do not, you can paste their Clerk user id instead.
Steps
Create a permission (a policy)
- Open Policies and press New policy.
- Under Effect, choose Can (allow) or Cannot (deny).
- Under Who, tick the people it applies to, or paste a Clerk user id. Tick Leave without people to use as a role pack if the permission should only be attached to roles.
- Under What they can do, tick the actions. They are grouped under Company, Branch and Brand (logo, accent, cover). The company and branch groups offer creating, reading, changing and listing. The brand group offers changing the brand.
- Under Where, choose All companies, One company, All branches in a company or One branch, then pick the company or branch. Press Add place to add more places.
- Check the sentence under This grant will read as:, then press Create policy.
Edit or remove a policy
Open Policies. The Who can do what list shows each permission with its effect, people, actions and place. Press Edit to change one and Save policy to keep it. Press Delete to remove it. Deleting it also takes it off any role that used it, and Zelun asks you to confirm.
Build a role
- Open Roles and press New role.
- Type the Role name and press Create role.
- On the role's page, use Add permission to attach a permission, with the same choices as a policy.
- Under People, use Assign person to choose someone from the directory, or paste their Clerk user id. Press Remove to take someone out.
- Press Detach next to a permission to take it off the role. Rename the role with Save name.
Check what someone can really do
- Effective access shows a table for one company: for each person, whether they Can change, Can see only, are Explicitly denied or have No grant, and whether that comes from a direct permission or a role pack.
- Check one thing answers a single question. Choose a Person, an Action and a Scope, then press Check. The answer is "Yes, allowed", "No, denied" or "No — nothing grants it", with the reason.
What your clients see
Your clients do not see roles or policies. The effect is indirect: the people on your team can only do what they have been given, so the right people manage your locations, brand and settings.
Common mistakes
- Expecting these screens in an owner's menu. They appear only for the Zelun administrator account.
- Forgetting that a deny wins. A Cannot (deny) permission overrides an allow, even one that comes from a role.
- Not choosing a place. Zelun asks you to choose at least one action and one place before saving.
- Granting access to the wrong place. Pick One branch rather than All companies unless you really mean everything.
- Deleting a permission that a role uses. It disappears from that role too.
- Assuming a role gives owner access. The company owner is handled separately and does not need a role. Managing roles and policies themselves is limited to the Zelun administrator account.
Related articles
The staff directory and staff time off have their own articles.
Reviewed on 2026-10-02