RBAC Overview & Job Visibility

How Zato's six role levels control what you can see and do.

Every user in Zato is assigned one of six role levels, from L1 (Admin) up to L6 (Director). Each level determines which modules and functions are available, and whether access is scoped to specifically assigned clients and jobs or extends across the whole firm.

The six role levels

Level

Name

Summary

L6

Director

Full firm-wide access, no branch restrictions.

L5

Manager

Senior review, sign-off, and oversight.

L4

Accountant

Preparer-level access, scoped to assigned clients/jobs.

L3

Connect Domain

External/outsourced preparer, restricted to assigned work only.

L2

Junior Accountant

Limited preparer access, scoped to assigned clients/jobs.

L1

Admin

Firm setup and user management, not day-to-day client work.

Job visibility and branch scoping

For users at L5 and below, branch assignment restricts visibility to that branch's clients and jobs, and this restriction is applied before role-based permissions are checked. Directors (L6) are never restricted by branch and can see every client and job in the firm.

Where the permissions matrix shows Y* rather than a plain Y for a given function, that role can only act on clients or jobs they are personally assigned to, with no firm-wide bypass.

Checking what a role can do

1. Open Firm Setup, then Permissions & Users.

2. In the Permissions Reference panel, select the role level you want to check.

3. Expand any module to see the specific functions enabled or disabled for that role.

How to access: Firm Setup, then Permissions & Users, then the Permissions Reference panel.