Nested / Feature / Permissions
Feature · Permissions

Set data access
Matched to the role
Secure at every level

Set roles by job position, control who can see documents for which company, branch and department, separate accounting duties from document handling, and close the account of an employee who leaves immediately, with all historical data still referenceable.

Data access at 3 levels Separate accounting from purchasing System and documents in 4 languages
Everything access control needs

Control user permissionsDetailed at every level

Be confident that each person can access only the data and menus their job requires.

Standard roles, usable from day one

Pick a role by job position from the standard set, with a capability reference table you can check against — no need to build permissions from scratch, and you can fine-tune them with the advanced settings function.

Data access at 3 levels

Define which company, branch and department documents each person can see, so employees only see the work they are responsible for — reducing both errors and the risk of data leaks.

Approved means locked — unapprove first

Purchase requisitions (PR), purchase orders (PO), goods receipts (GR), vendor invoices (AP) and credit line usage records (CV) cannot be edited once approved until they are unapproved, so every change always goes through the approval chain.

Separate accounting duties from document handling

Only users with an accounting role can edit the accounting entries on vendor invoices, goods receipts and payment vouchers. Purchasing can issue documents but cannot change the accounting figures.

Close an employee's account immediately, with all data intact

Lock an account temporarily when access needs to be suspended, or deactivate it permanently when an employee leaves, while existing documents still reference the name of whoever recorded them, and send password reset emails from the system.

System and documents in 4 languages

Use the system in Thai, English, Chinese or Japanese, set a default language per person, and print document forms in a language your overseas customers or executives can read.

One connected flow

From opening a user account to the day an employee leaves
End-to-end control

Each person sees only their own work, and no one can edit approved documents at will.

Create employee records and the org chart

Specify company, department, job position, manager and signature for each person.

Open a user account

Tied to the work email, with a forced password change on first sign-in.

Set roles and data visibility

Pick a role by position, then specify the companies, branches and departments they can see.

Lock or deactivate on transfer or departure

Shut off access immediately, with existing documents still referencing the name in full.

See it in action

Employee records, rolesand signature, in one place

Keep each person's photo, job position, department, manager, default language and signature in one place.

The user permission settings page in Nested, setting permissions by menu and by company
Common questions

Frequently asked questions aboutPermission management features

Can permissions be set down to the menu level?
Permissions come in two parts. The first is the role, which defines what a user can do with documents. The second is data access at 3 levels — company, branch and department — which defines whose documents they can see. For finer view/edit control per role, you can use the advanced settings function.
Can I stop employees from editing documents that have already been approved?
Yes. Once a document has been approved, no field can be edited at all — it has to be unapproved first, then edited and resubmitted for approval. For a vendor invoice or goods receipt that has already been used to create a payment voucher, the payment voucher must be cancelled first as well. And once the books are closed, you can lock the accounting period as a further layer of protection against backdated edits.
How should we handle the account of an employee who leaves?
You have two options. To suspend access temporarily, lock the account — the user stays on the list but cannot record transactions. When someone leaves, deactivate them instead and the system moves them to the suspended users tab, while existing documents still reference the name of whoever recorded them, exactly as before. Admins can also send password reset emails to other users from the same menu.
Can overseas executives use the system in English?
Yes. The system supports 4 languages — Thai, English, Chinese and Japanese. Switch the interface language from the top right, and set a default language per person in their employee record. Document print forms can also be produced in the language you need, for sending to overseas customers or executives.
Documentation

User guideUser permissionsIn detail

The real steps, screen by screen, along with the questions customers ask us most. Read it now, no sign-up required

See everything at Setup guide

Free consultation

I'd like to try the permission management features
Get free advice from our team

Talk to our CPA team to see how well Nested's permission management fits your business. Free of charge.

LINE QR code
LScan to add on LINE