Permissions Overview
The dashboard landing page for Roles & Permissions — a snapshot of how many roles exist, who's assigned, what field groups are defined, and what each role can do.
Roles & Capabilities: The Permissions Model
How Aeon decides what each staff member can see and do — the role-based model of operational capabilities, configuration access, and field restrictions.
Creating a Custom Role
How to create a new permission role in Aeon — starting from a blank set of capabilities or cloning an existing role as a head start.
Cloning a Role
How to duplicate an existing Aeon role in one step — copying all of its capabilities, field restrictions, and layout assignments into a new role you can adjust.
Editing a Role: Operational Capabilities
Set what a role can do in the day-to-day workspace by choosing an access level — None, View, Edit, or Full — for each of Aeon's ten operational categories.
Editing a Role: Configuration Capabilities
How to control which sections of the Customization Manager a role can open, using the Configuration tab of the role editor.
Editing a Role: Layout Assignments
How to give a role its own request, user, and activity layouts — so different kinds of staff see forms, cards, and queues built for the way they work.
Editing a Role: Field Restrictions
Hide sensitive fields — like government IDs, contact details, or billing amounts — from a role by checking the field groups it should not be able to see.
Editing a Role: Members & Assigned Staff
View which staff are assigned to a role, assign more staff to it, and remove staff from it — all from the role editor's Members tab.
Deleting a Role
How to delete a custom role in Aeon, reassign any staff still assigned to it, and the guards that stop you from deleting system roles or locking yourself out of the admin interface.
Permissions Matrix Reference
A complete lookup of every operational capability, configuration group, and access level Aeon uses to decide what a role can do.
Managing Staff Accounts
Create, edit, copy, deactivate, and remove staff accounts — and set their passwords, roles, and site access — from the Staff tab in the Customization Manager.
Creating a New Staff Account
How to add a new staff member to Aeon — set their username, password, and (on multi-site systems) site access — then assign a role.
Assigning Roles to Staff
How to give a staff member their web-client permissions by assigning a role, what the capability summary tells you, and why the change takes effect immediately.
Resetting a Staff Member's Password
How an administrator resets the password on any staff account from the web client, including forcing a change at next login and unlocking a locked-out account.
Deactivating and Re-activating Staff Accounts
How to block a staff member from logging in without deleting their account — and how to restore access — using the Account is Locked and Account is Inactive controls on the Staff tab.
Copying a Staff Account
Duplicate an existing staff account — role, access flags, and site assignments included — to set up a similar staff member quickly.
Field Restriction Groups
What field restriction groups are, the four built-in groups Aeon includes, and how they let you hide sensitive fields like government IDs or payment details from chosen roles.
Creating a Custom Field Restriction Group
Create a named group of sensitive fields — such as patron PII or billing and cost data — that you can then hide from specific roles.
Editing a Field Restriction Group
How to rename a field restriction group, change its description, and add or remove the fields it hides from restricted roles.
Deleting a Field Restriction Group
How to permanently remove a custom field restriction group, why system default groups can't be deleted, and what to do when a group is still assigned to roles.
System Default Roles: Administrator and Staff
The two built-in roles Aeon includes — Administrator and Staff — what each one grants, and why they can't be deleted.
Protecting Against Lockout: One-Admin Minimum
How Aeon stops you from accidentally removing the last administrator's access — and how to work around the guard when it blocks a change you meant to make.
Moving Staff Accounts to Single Sign-On
The three ways to convert a staff account from a password to institutional sign-in, how Aeon matches an asserted identity to an account, and what changes for the account afterwards.
Resetting a Staff Member's Authenticator
How to clear a staff member's authenticator enrollment when they've lost the device — and how to reset your own when you're switching phones.
Support Access
How Atlas Systems support signs in to your Aeon 7 staff web client, what your grant controls, and how to review everything a support session did.