Custom roles on a permission engine you can check
Build roles from named permissions, preview the app exactly as a person sees it, and keep an audit log of every change. Ownership of the company is never grantable.
How Tanzeem handles it
Start from built-ins
Owner, HR, Finance and the other built-in roles ship ready, each with the permissions its job needs.
Create a custom role
The owner creates a role, ticks permissions from a labelled catalogue and assigns it.
Preview as that person
The owner views the app as another person, read-only, to check what their role actually shows.
Audit every change
Role and permission changes are written to the audit log.
What is in Custom roles
Custom roles
Roles built from named, grouped permissions, created by the owner.
Screens, not rows
A permission opens a screen. Whose records appear on it is decided on the server, per person.
Line managers worked out
Line manager is derived from the reporting line, never assigned, so it cannot drift.
Salaries stay narrow
Other people's salaries are visible to Finance and the owner only.
Owner read-only preview
View the app as another person with a banner that cannot be dismissed. Nothing can be changed while previewing.
Audit log
Every change to roles and permissions, with who made it and when.
Can a custom role give someone ownership?
No. Ownership is not a permission, so no role can grant it.
Can a role remove someone's access to their own payslip?
No. Self-service permissions are never grantable, so no custom role can take them away.
Does HR see salaries?
No. Other people's salaries are visible to Finance and the owner.
Is the preview safe?
It is read-only, owner only, never another owner, and ends on its own after 30 minutes.
Who is a line manager?
Anyone with a direct report. Tanzeem works it out from the reporting line.
Bring last month’s payroll sheet to the demo
We will run it through Tanzeem on the call and show you each payslip, with the working, before you decide anything.