Skip to content

Target Users

IQV API Middleware restricts access by reading a role field from the backend's user object (the first non-empty value among role, user_role, userRole, role_name, roleName). The single source of this logic is dashboard/src/routes/roleAccess.tsx; both the sidebar menu and the route guards use the same functions.

The only role distinction actually enforced in source is whether the role value equals exactly user. The table below shows this, alongside the role names that exist only as display labels (and carry no access restriction).

Role Accessible areas Allowed actions Access boundary
user Only Platforms (/platform); shown as the single sidebar option. The Reminder and Mail Box routes aren't in the menu, but that's not a role-based block — they're simply unlinked from the menu for everyone. Viewing platform modules and navigating via module cards. Even a direct URL visit to Notes (/notlar) or Settings (/ayarlar) is caught by RequirePlatformAccess, which redirects to /platform before the page is ever rendered.
companyadmin, organizationadmin, admin, superadmin (or an empty role field) Every page in the sidebar: Platforms, Notes, Settings. Reminder/Mail Box aren't in the menu but are reachable by direct URL (true for any logged-in user, not role-specific). Full CRUD on notes/reminders/platform modules, sharing by email, saving platform ordering. The codebase defines no distinction among these roles — they all have identical, full access. The companyadmin/organizationadmin labels only affect the badge text shown under the username (see below); they don't affect access.

Important notes

  • Session requirement: regardless of role, every page except /login sits behind RequireAuth; any visitor without a session (an empty Redux admin state) is redirected to /login.
  • The badge text is display-only: the sidebar user badge shows companyadmin → "Şirket Admini" (Company Admin), organizationadmin → "Organizasyon Admini" (Organization Admin), user → "Kullanıcı" (User); any unrecognized role, including admin/superadmin which have no mapping, always displays as "Kullanıcı" — this does not reflect the actual access level, it is display text only.
  • The codebase does not define a separate, broader permission set for admin/superadmin; those names appear only in a code comment in roleAccess.tsx, meaning "anything other than user."