Dec 26
Back-office access
Our customer needs to give employees access to the application's back office to read answers to forms, send notifications, create user accounts and add loyalty points, but these employees must not be able to modify the forms or the application's settings, as is the case for the loyalty card, for example. This is not currently the case, and can be very problematic if the employee makes changes to the application, or if he wants to black out the company and make the application non-functional. Can you differentiate these actions in order to secure the structure of the application from actions to be carried out by a simple employee?
Thank you
Pending