RBAC Overview & Job Visibility
How Zato's six role levels control what you can see and do.
Every user in Zato is assigned one of six role levels, from L1 (Admin) up to L6 (Director). Each level determines which modules and functions are available, and whether access is scoped to specifically assigned clients and jobs or extends across the whole firm.
The six role levels
Job visibility and branch scoping
For users at L5 and below, branch assignment restricts visibility to that branch's clients and jobs, and this restriction is applied before role-based permissions are checked. Directors (L6) are never restricted by branch and can see every client and job in the firm.
Where the permissions matrix shows Y* rather than a plain Y for a given function, that role can only act on clients or jobs they are personally assigned to, with no firm-wide bypass.
Checking what a role can do
1. Open Firm Setup, then Permissions & Users.
2. In the Permissions Reference panel, select the role level you want to check.
3. Expand any module to see the specific functions enabled or disabled for that role.
How to access: Firm Setup, then Permissions & Users, then the Permissions Reference panel.