Policies define what actions users can or cannot perform on resources. Each policy has an effect (allow or deny), a set of actions, and can be attached to a role. Actions follow the format "resource:action". For example, "product:Read" or "*:*" for all resources and all actions.

Available Resources

The following resources are available in the permission system: account, attribute, brand, category, job, asset-manager, organization, policy, product, role, tag, user, invoice, usage, option, option-value You can view the full list of available actions from the Permission List endpoint, accessible from any authenticated session.

Create

1

Navigate to Policy

Click Policy in the left sidebar.
2

Click Add Policy

Click the Add Policy button in the top-right toolbar.
3

Configure the policy

* Not required when Predefined is enabled.
4

Add actions

Type or select permission strings in the Actions field. Each action must match a valid "resource:action" format. Wildcards are supported:For example, granting CRUD on products and attributes:
5

Save

Click Save. The policy is ready to be attached to a role.

Read

Open Policy in the left sidebar to view all policies. Each policy shows:
  • Name
  • Effect badge (allow or deny)
  • Actions: a preview of the configured permission strings
  • Predefined indicator
Click any policy to open its detail page with the full action list.

Update

1

Select a policy

Click a policy from the list to open its detail page.
2

Click Edit

Click the Edit button to make the policy editable.
3

Modify fields

Update the name, effect, description, or add/remove actions.
4

Save

Click Save to apply changes.

Delete

1

Open policy detail

Click the policy from the list.
2

Click Delete

Click the Delete button in the top-right toolbar.
3

Confirm

Click Delete in the confirmation dialog.
Deleting a policy removes it from all roles that reference it. Users assigned to those roles will lose the permissions this policy granted.

How Authorization Works

Sellufy uses a CASL-based RBAC/ABAC system:
  1. Each user has one or more roles
  2. Each role has one or more policies
  3. Each policy has an effect and a list of actions
  4. Actions are parsed as "module:action" pairs
The system evaluates permissions by iterating through all policies attached to a user’s roles. If a user is an account owner, they automatically receive full access (can('manage', 'all')).

Predefined Policies

When your organization is created, these policies are set up automatically: Predefined policies are marked with predefined: true and linked to their corresponding predefined roles.
You need the appropriate policy permissions (Create, Read, Update, Delete) to manage policies.