Plenix 2026.09.3 — Access control down to each screen and each action

Roles and per-user access now go below the module level. Choose which screens someone can open (Bills but not Invoices, Tax Rates but not Reports) and what they can do on each (view, create, edit, delete, admin). People management is limited to HR and administrators, and invites always start at Viewer.

T
The Plenix Team·29 September 2026·3 min read

Release 2026.09.3 is about access control. Before this release you could give someone a whole module, such as Accounting or Ticketing. Now you can decide which screens inside a module they can use, and what they can do on each screen.

New features

Per-screen access

  • Every module lists its screens, taken from the menu itself. For example, Accounting has Invoices, Bills, Tax Rates, Reports and more.
  • Give a role or a single person access to some screens and not others: Bills but not Invoices, or Tax Rates but not Reports. This works the same way in Ticketing, RMM, CRM, HR and every other module.
  • Screens someone can't open are hidden from their menu, and the server refuses them too, so a direct link doesn't get around it.

Per-action access

  • For each module or screen, choose View, Edit, Full control, or Custom.
  • Custom lets you tick exactly the actions you want: view, create, edit, delete and admin (approve, void, configure). For example, someone can create and edit invoices but never delete one.
  • Buttons for actions a person can't perform are hidden. For example, New Invoice, Mark Paid, New Bill, bill approval and New Ticket only appear if the person has that action.

Access for each person

  • Set a person's access on their employee record (Module access). A setting on one person overrides their role for that module or screen, including No access, which takes one screen away even if their role allows the whole module.

Changes

Who can manage people and access

  • Only HR Admins, HR Managers, Administrators and Super Admins can edit employee and user records. This covers personal details, employment, emergency contacts, notes, adding and importing people, and bulk changes. Other roles, including Directors, now see these records read-only.
  • Only Administrators and Super Admins can change roles, per-screen access, or whether someone can sign in. Only a Super Admin can change roles and permissions across the platform. In a tenant workspace, only Administrators can.
  • HR Admins, HR Managers, Administrators and Super Admins can invite people, but an invite from HR always gives the person the Viewer role. An administrator can raise their access later.
  • Nobody except a Super Admin can change a Super Admin's record.
  • These rules are based on each person's actual role, not on what a role is called. A custom role named "Admin" gets no extra powers.

Fixes

  • A Director could open a Super Admin's employee profile and change personal details such as date of birth. That is no longer possible.