Skip to content
Updated Sep 15, 2026 by Barča Dvořáková · Owner: analysisactivefeaturereference Edit on GitHub

Reference: EM2 Roles & Permissions ​

Purpose: EM2 (the previous "E Manažer" product) solved a structurally similar problem — users, roles, and per-role permissions — and its actual seeded roles are a useful starting point when defining EM3's Permission Sets and Groups. This is a factual extraction from EM2's code (src/DataFixtures/RolesPermissionsFixture.php, src/DataFixtures/AdminRolesPermissionsFixtures.php, src/Entity/Role.php), not a design decision — nothing here is assumed to carry over to EM3 as-is.

EM2 runs two entirely separate role catalogues with no shared table: an app-tier catalogue (one role per user) and a smaller admin-tier catalogue for the back-office panel (a person may hold more than one admin-tier role at once).

App-tier roles (App\Entity\Role, one per user) ​

RoleLabel (Czech)What it actually grants
ROLE_ADMINAdministrátorEvery permission in the system — full administrative access.
ROLE_ADMIN_MANAGERAdmin - manažerEverything ROLE_MANAGER has, plus client-account management (view/edit/export/assign clients, auto-pair gauge readings), cross-building visibility ("see all buildings," not just assigned ones), building deletion, and removing a user's building assignment. The senior operational role — manages people, buildings, and client relationships.
ROLE_MANAGERManažerFull user management (create/edit/delete/export); building management (create/edit/export, but not delete, and not "all buildings" — scoped to assigned buildings); full gauge/meter management including specialized fields, invoicing, and remote-reading import; file management; contracts (view/create/edit/delete); reports/overview/graphs pages. No client-account access.
ROLE_CLIENT_BOSSVedení organizaceRead-only on users (view + export, no edit); broad building access (view/edit/create/export and "all buildings" visibility) but no delete; gauge management (view/edit/create/export/delete); files are read-only; reports pages. No contracts, no user CRUD. Reads like an executive/leadership view — broad visibility, limited operational/destructive rights.
ROLE_WORKER_MANAGERPracovník manažerFull user management; building management (create/edit/export, no delete, no "all buildings"); full gauge management (including invoicing and remote-reading edits, but not import); file management; reports pages. No client access, no contracts. A narrower "manager" than ROLE_MANAGER — no contracts, no bulk import.
ROLE_WORKERPracovníkNo user management at all. Buildings (create/edit/export, no delete, no "all buildings"); gauges (create/edit/export, but not delete, and missing some manager-level field edits and remote-reading edits); files (create/edit/view); reports pages. The field-level operational role.
ROLE_GUEST_EXPERTHost expertUsers: read + export only. Buildings: view/edit/create/export and "all buildings" visibility. No gauge permissions at all, no file access. Reports pages only. An external expert given broad building oversight without operational (meter/file) access.
ROLE_GUESTHostRead-only everywhere it has access at all: dashboard, building list/detail, gauge list, building-files list, file detail, reports pages. No create/edit/delete anywhere. Pure viewer.

Admin-tier roles (App\Entity\Admin\AdminRole, back-office panel, additive/multi-role) ​

RoleLabelWhat it grants
ROLE_GUESTHostDashboard only.
ROLE_ADMINISTRATORAdministrátorEvery admin-panel permission except the one superadmin-only addition below.
ROLE_SUPER_ADMINSUPERADMINEverything ROLE_ADMINISTRATOR has, plus one extra permission (client daily-consumption status).

Pattern worth carrying into EM3's design ​

Almost every app-tier role is a variation on three axes:

  • User-management rights: none (WORKER, GUEST, GUEST_EXPERT) / full CRUD (ADMIN_MANAGER, MANAGER, WORKER_MANAGER) / read-only (CLIENT_BOSS).
  • Building scope: assigned-buildings-only vs. an "all buildings" cross-visibility flag (ADMIN_MANAGER, CLIENT_BOSS, GUEST_EXPERT).
  • Operational depth on gauges/meters, files, and contracts (ranging from none, to read-only, to full CRUD with specialized field-level edit permissions).

The "all buildings" flag looks like a natural scope: all rule in EM3's PermissionRuleScope; the assigned-buildings-only case looks like exactly the restriction mechanism already being designed on groupMembership / permissionSetUserAssignment. Not yet decided how many EM3 Permission Sets/Groups this collapses into, or how directly EM2's role names map onto EM3's Groups — this is raw material for that design step, not the design itself.