DWPlatform Tutorials

Setting Roles — a photo walkthrough

This guide shows, click by click with real screenshots, how an administrator gives a user a role — and then what that user can newly do. No theory: follow the pictures.

Two different kinds of “role” — set in two different places.
1. The tenant role — is this person a normal Member (عضو) or a tenant Admin (مسؤول)? Set from the Users list (Part A).
2. Service roles — job capabilities inside one module, like Receive Desk on DWMail or External-send office. Set from the user’s detail page (Part B). One user can hold many.

Who is allowed to do this?

TaskYou need to be…
Create users / change the tenant role (Member ↔ Admin)A Tenant Admin of the organization, or a platform SuperAdmin. Seat-limited: at the plan’s limit the save is refused with a clear message.
Assign / remove a service roleAnyone with Admin / Manager / HRAdmin (globally or on the Identity service). SuperAdmin always qualifies. Not seat-limited.

Part A — Change a user’s tenant role (Member ↔ Admin)

Step 1 · Open the Identity app

From the platform rail/launcher open الهوية (Identity) — the app whose subtitle reads «المستخدمون والأدوار والصلاحيات» (users, roles & permissions).

Identity app home
The Identity (IAM) app. The side menu has لوحة التحكم (dashboard) and إدارة المستخدمين (user management) with two pages: المستخدمون (Users) and الأدوار (Roles).

Step 2 · Open the Users page

In the side menu expand إدارة المستخدمين and click المستخدمون (Users). Every user appears as a row with action buttons at its end: تعديل (edit) · تغيير الدور (change role) · حذف (delete).

Users list with row actions
The Users page. Columns: username, email, name, RFID, qualification, roles — plus إضافة مستخدم (add user) at the top.

Step 3 · Click «تغيير الدور» and choose

A small dialog opens with one choice — الدور (the role):

Pick and press حفظ (Save). That’s the whole operation.

Change role dialog
The change-role dialog. One dropdown, Save / Cancel. Promoting to Admin is checked against the plan’s admin-seat limit — at the cap you’ll get a clear “seat limit” message instead.
Protections you can rely on: the tenant Owner can never be demoted, and the last admin can never be removed — the system refuses, so you can’t lock yourself out.

Part B — Give a user a capability (service role)

This is how you make someone a Receive Desk clerk, a mail manager, an external-send office, an HR admin — any per-module capability.

Step 1 · Open the user’s page

From the Users list open the user (their name / edit). The detail page shows their info card and — on the side — the الأدوار (Roles) card:

User detail with the Roles card
The user detail page. The Roles card lists الأدوار العامة (global roles — e.g. SuperAdmin, Admin — read-only badges) and الأدوار الخاصة بالخدمات (service-specific roles), with the إضافة دور (add role) button.

Step 2 · Click «إضافة دور» — pick the service, pick the role

The إسناد دور (Assign role) dialog opens with two dropdowns:

  1. الخدمة (Service) — which module this capability applies to (e.g. DWPlatform.Correspondence for DWMail, Calendar, News…).
  2. الدور (Role) — the capability itself (e.g. ReceiveDesk).

Then press إسناد (Assign). The role appears immediately in the Roles card with a small trash icon next to it — that’s how you revoke it later.

Assign role dialog with service and role dropdowns
The assign-role dialog. Service on top, role beneath, then إسناد. A role can be paired with any service — the meaning comes from the pair (User × Role × Service).

Step 3 · The user signs out and back in

This step matters. Roles are stamped into the user’s sign-in token. The new capability takes effect on their next sign-in — ask them to log out and log back in (or refresh their session), and the new buttons/pages appear.

If the role you need isn’t in the list

The dropdown offers the roles that exist in the system. The built-in set: Admin · User · Manager · Supervisor · HRAdmin · ReceiveDesk · ReviewDesk · SecretaryDesk · CalendarAdmin · CalendarManager. Specialized names like ExternalSendingOffice, Director or Auditor must be created once first: open the الأدوار (Roles) page (next to Users in the side menu), create the role name, then assign it in Part B. For external send specifically you can skip this — granting Admin on the Mail service already unlocks it.

What the user can NEWLY do — role by role

After the sign-out/in, here is exactly what changes for them:

Granted role (on service)What they can now doWhere they see it
ReceiveDesk (Mail/Correspondence)Register formal incoming letters into the system — direction, numbers, urgency, attachments — and pass them into the desk pipeline.DWMail → the official-correspondence registration screens. See the Mail Pipeline guide.
ReviewDesk (Mail/Correspondence)Review a registered letter and decide: finish it, or forward it to the Secretary desk.DWMail → the item’s stage panel.
SecretaryDesk (Mail/Correspondence)Final processing of a registered letter — final approval, outgoing number, archive.DWMail → the item’s stage panel.
ExternalSendingOffice / Director / Admin (Mail)Send email to external addresses (outside the organization) and schedule external sends. Without one of these the composer hides the “add external” option and the server refuses with a clear message.DWMail composer — typing a raw email now offers an “Add external” chip.
Admin / Manager (Mail)Manage others’ correspondence: edit participants, delete others’ attachments, complete others’ actions, reply on any thread; release a colleague’s claim in a shared inbox.DWMail — management actions appear on items they don’t own.
HRAdmin (HR/Identity)Maintain the people registry and org structure: persons, departments, jobs, ranks.The HR / Organization app.
CalendarAdmin / CalendarManagerAdminister calendars / department-level calendar access.Calendar surfaces.
Admin (News / Media / KPIS / …)Full administration of that one module (publish news, manage Drive quotas & quarantine, manage all KPI activities…).That module’s admin controls.
Remember the difference: the tenant role (Part A) decides who administers the organization; service roles (Part B) decide who can do which job inside each module. A person can be a plain Member of the tenant yet hold powerful service roles — that’s normal and healthy: give people the smallest role that does the job.