Appearance
Reference: EM2 Roles & Permissions
Purpose: EM2 (the previous "E Manažer" product) solved a structurally similar problem — users, roles, and per-role permissions — and its actual seeded roles are a useful starting point when defining EM3's Permission Sets and Groups. This is a factual extraction from EM2's code (src/DataFixtures/RolesPermissionsFixture.php, src/DataFixtures/AdminRolesPermissionsFixtures.php, src/Entity/Role.php), not a design decision — nothing here is assumed to carry over to EM3 as-is.
EM2 runs two entirely separate role catalogues with no shared table: an app-tier catalogue (one role per user) and a smaller admin-tier catalogue for the back-office panel (a person may hold more than one admin-tier role at once).
App-tier roles (App\Entity\Role, one per user)
| Role | Label (Czech) | What it actually grants |
|---|---|---|
ROLE_ADMIN | Administrátor | Every permission in the system — full administrative access. |
ROLE_ADMIN_MANAGER | Admin - manažer | Everything ROLE_MANAGER has, plus client-account management (view/edit/export/assign clients, auto-pair gauge readings), cross-building visibility ("see all buildings," not just assigned ones), building deletion, and removing a user's building assignment. The senior operational role — manages people, buildings, and client relationships. |
ROLE_MANAGER | Manažer | Full user management (create/edit/delete/export); building management (create/edit/export, but not delete, and not "all buildings" — scoped to assigned buildings); full gauge/meter management including specialized fields, invoicing, and remote-reading import; file management; contracts (view/create/edit/delete); reports/overview/graphs pages. No client-account access. |
ROLE_CLIENT_BOSS | Vedení organizace | Read-only on users (view + export, no edit); broad building access (view/edit/create/export and "all buildings" visibility) but no delete; gauge management (view/edit/create/export/delete); files are read-only; reports pages. No contracts, no user CRUD. Reads like an executive/leadership view — broad visibility, limited operational/destructive rights. |
ROLE_WORKER_MANAGER | Pracovník manažer | Full user management; building management (create/edit/export, no delete, no "all buildings"); full gauge management (including invoicing and remote-reading edits, but not import); file management; reports pages. No client access, no contracts. A narrower "manager" than ROLE_MANAGER — no contracts, no bulk import. |
ROLE_WORKER | Pracovník | No user management at all. Buildings (create/edit/export, no delete, no "all buildings"); gauges (create/edit/export, but not delete, and missing some manager-level field edits and remote-reading edits); files (create/edit/view); reports pages. The field-level operational role. |
ROLE_GUEST_EXPERT | Host expert | Users: read + export only. Buildings: view/edit/create/export and "all buildings" visibility. No gauge permissions at all, no file access. Reports pages only. An external expert given broad building oversight without operational (meter/file) access. |
ROLE_GUEST | Host | Read-only everywhere it has access at all: dashboard, building list/detail, gauge list, building-files list, file detail, reports pages. No create/edit/delete anywhere. Pure viewer. |
Admin-tier roles (App\Entity\Admin\AdminRole, back-office panel, additive/multi-role)
| Role | Label | What it grants |
|---|---|---|
ROLE_GUEST | Host | Dashboard only. |
ROLE_ADMINISTRATOR | Administrátor | Every admin-panel permission except the one superadmin-only addition below. |
ROLE_SUPER_ADMIN | SUPERADMIN | Everything ROLE_ADMINISTRATOR has, plus one extra permission (client daily-consumption status). |
Pattern worth carrying into EM3's design
Almost every app-tier role is a variation on three axes:
- User-management rights: none (
WORKER,GUEST,GUEST_EXPERT) / full CRUD (ADMIN_MANAGER,MANAGER,WORKER_MANAGER) / read-only (CLIENT_BOSS). - Building scope: assigned-buildings-only vs. an "all buildings" cross-visibility flag (
ADMIN_MANAGER,CLIENT_BOSS,GUEST_EXPERT). - Operational depth on gauges/meters, files, and contracts (ranging from none, to read-only, to full CRUD with specialized field-level edit permissions).
The "all buildings" flag looks like a natural scope: all rule in EM3's PermissionRuleScope; the assigned-buildings-only case looks like exactly the restriction mechanism already being designed on groupMembership / permissionSetUserAssignment. Not yet decided how many EM3 Permission Sets/Groups this collapses into, or how directly EM2's role names map onto EM3's Groups — this is raw material for that design step, not the design itself.