allow or deny), a set of actions, and can be attached to a role.
Actions follow the format "resource:action". For example, "product:Read" or "*:*" for all resources and all actions.
Available Resources
The following resources are available in the permission system:account, attribute, brand, category, job, asset-manager, organization, policy, product, role, tag, user, invoice, usage, option, option-value
You can view the full list of available actions from the Permission List endpoint, accessible from any authenticated session.
Create
1
Navigate to Policy
Click Policy in the left sidebar.
2
Click Add Policy
Click the Add Policy button in the top-right toolbar.
3
Configure the policy
* Not required when Predefined is enabled.
4
Add actions
Type or select permission strings in the Actions field. Each action must match a valid
"resource:action" format. Wildcards are supported:For example, granting CRUD on products and attributes:
5
Save
Click Save. The policy is ready to be attached to a role.
Read
Open Policy in the left sidebar to view all policies. Each policy shows:- Name
- Effect badge (
allowordeny) - Actions: a preview of the configured permission strings
- Predefined indicator
Update
1
Select a policy
Click a policy from the list to open its detail page.
2
Click Edit
Click the Edit button to make the policy editable.
3
Modify fields
Update the name, effect, description, or add/remove actions.
4
Save
Click Save to apply changes.
Delete
1
Open policy detail
Click the policy from the list.
2
Click Delete
Click the Delete button in the top-right toolbar.
3
Confirm
Click Delete in the confirmation dialog.
How Authorization Works
Sellufy uses a CASL-based RBAC/ABAC system:- Each user has one or more roles
- Each role has one or more policies
- Each policy has an effect and a list of actions
- Actions are parsed as
"module:action"pairs
can('manage', 'all')).
Predefined Policies
When your organization is created, these policies are set up automatically:
Predefined policies are marked with
predefined: true and linked to their corresponding predefined roles.
You need the appropriate policy permissions (Create, Read, Update, Delete) to manage policies.