Skip to content

Module · part of Koldwerk

Users & roles (RBAC)

An installer needs to fill in work orders but not see cost prices. A customer only their own data. A resident in an owners'-association building only their own home.

Five roles built in: OWNER, ADMIN, MONTEUR (installer), KLANT (customer), BEWONER (resident). Different routes and data access per role. Strict multi-tenant isolation — nobody ever sees data from another workspace.

BRL 100 and STEK are Dutch national certification schemes — full support today is NL-only. See our honest country-coverage disclosure.

What it does

  • Roles: OWNER (everything), ADMIN (everything except cancelling billing), MONTEUR (work orders + scheduling, no admin routes), KLANT (customer portal only), BEWONER (resident portal only — their own linked installation(s), report a fault).
  • Multi-tenant isolation via a tenantClient wrapper and server-side role checks.
  • Audit log for every user change.
  • Activate/deactivate via the UI.

Compliant with

AVG/GDPR multi-tenant isolatieBRL 100

Use cases

How installers use this module day to day

Customer portal invitation

The owner creates a KLANT account for a customer and links it to a Customer record. The customer logs in and sees only their own installations.

Resident portal invitation (owners' association)

The owner creates a BEWONER account and links it to one or more installations (for example a heat pump + ventilation in the same home). The resident logs in, sees only those installations and can report a fault.

FAQ

Frequently asked questions

Can I enable 2FA?

On the roadmap for the OWNER role. For now: long passwords + Argon2id hashing.

Combines with

Related modules

Ready to use users & roles (rbac)?

7 days free, no credit card needed. Cancel monthly after that — no renewal tricks.

Create account (NL)