This guide shows, click by click with real screenshots, how an administrator gives a user a role — and then what that user can newly do. No theory: follow the pictures.
| Task | You need to be… |
|---|---|
| Create users / change the tenant role (Member ↔ Admin) | A Tenant Admin of the organization, or a platform SuperAdmin. Seat-limited: at the plan’s limit the save is refused with a clear message. |
| Assign / remove a service role | Anyone with Admin / Manager / HRAdmin (globally or on the Identity service). SuperAdmin always qualifies. Not seat-limited. |
From the platform rail/launcher open الهوية (Identity) — the app whose subtitle reads «المستخدمون والأدوار والصلاحيات» (users, roles & permissions).
In the side menu expand إدارة المستخدمين and click المستخدمون (Users). Every user appears as a row with action buttons at its end: تعديل (edit) · تغيير الدور (change role) · حذف (delete).
A small dialog opens with one choice — الدور (the role):
Pick and press حفظ (Save). That’s the whole operation.
This is how you make someone a Receive Desk clerk, a mail manager, an external-send office, an HR admin — any per-module capability.
From the Users list open the user (their name / edit). The detail page shows their info card and — on the side — the الأدوار (Roles) card:
The إسناد دور (Assign role) dialog opens with two dropdowns:
Then press إسناد (Assign). The role appears immediately in the Roles card with a small trash icon next to it — that’s how you revoke it later.
The dropdown offers the roles that exist in the system. The built-in set: Admin · User · Manager ·
Supervisor · HRAdmin · ReceiveDesk · ReviewDesk · SecretaryDesk · CalendarAdmin · CalendarManager.
Specialized names like ExternalSendingOffice, Director or Auditor must be
created once first: open the الأدوار (Roles) page (next to Users in the side menu), create the role
name, then assign it in Part B. For external send specifically you can skip this — granting Admin on the
Mail service already unlocks it.
After the sign-out/in, here is exactly what changes for them:
| Granted role (on service) | What they can now do | Where they see it |
|---|---|---|
| ReceiveDesk (Mail/Correspondence) | Register formal incoming letters into the system — direction, numbers, urgency, attachments — and pass them into the desk pipeline. | DWMail → the official-correspondence registration screens. See the Mail Pipeline guide. |
| ReviewDesk (Mail/Correspondence) | Review a registered letter and decide: finish it, or forward it to the Secretary desk. | DWMail → the item’s stage panel. |
| SecretaryDesk (Mail/Correspondence) | Final processing of a registered letter — final approval, outgoing number, archive. | DWMail → the item’s stage panel. |
| ExternalSendingOffice / Director / Admin (Mail) | Send email to external addresses (outside the organization) and schedule external sends. Without one of these the composer hides the “add external” option and the server refuses with a clear message. | DWMail composer — typing a raw email now offers an “Add external” chip. |
| Admin / Manager (Mail) | Manage others’ correspondence: edit participants, delete others’ attachments, complete others’ actions, reply on any thread; release a colleague’s claim in a shared inbox. | DWMail — management actions appear on items they don’t own. |
| HRAdmin (HR/Identity) | Maintain the people registry and org structure: persons, departments, jobs, ranks. | The HR / Organization app. |
| CalendarAdmin / CalendarManager | Administer calendars / department-level calendar access. | Calendar surfaces. |
| Admin (News / Media / KPIS / …) | Full administration of that one module (publish news, manage Drive quotas & quarantine, manage all KPI activities…). | That module’s admin controls. |