User groups and permissions
Breww's access controls let you decide exactly which parts of Breww each of your team can use. Permissions are granted through user groups, and can be topped up per person with additional permissions.
You'll need the Brewery admin permission to manage users, groups and permissions. Everything on this page is found under Settings -> User groups & permissions and Settings -> Users & security settings.
How Breww works out what someone can do
A user's access is the combination of two things:
- The groups they belong to. Every permission held by any of their groups is granted to them.
- Their additional permissions. Permissions granted directly to that person, on top of whatever their groups give them.
The two are added together, and there is no way to subtract. If a group grants a permission, everyone in that group has it, and it cannot be taken away from one member individually. To remove it from that person, either take them out of the group or remove the permission from the group (which affects every member).
Brewery admin is not a normal permission. Anyone who holds it, whether through a group or as an additional permission, passes every permission check in Breww. Their other groups and permissions become irrelevant, and they can manage users, permissions, billing and every setting. Grant it sparingly.
Users with no permissions at all
A user who ends up with no groups and no additional permissions cannot use your Breww account. The next time they load a page, they are disconnected from your brewery and shown a message asking an admin to grant them the permissions they need. Their user account itself still exists, and re-adding them to a group restores their access.
Because of this, always leave a user with at least one meaningful permission, or remove their access properly instead (see "Removing and reinstating access" below).
System groups and custom groups
Settings -> User groups & permissions shows two lists.
System groups are built and maintained by Breww:
- Brewery admin
- Containers
- Deliveries
- Excise duty
- Production
- Reporting
- Sales
- Settings
You cannot edit or delete these, and you don't need to. When Breww adds a new permission, the relevant system groups are updated automatically, so members pick up sensible access to new features without you doing anything.
Custom groups are your own. They give you complete control over the exact set of permissions, but they will not be updated automatically when new permissions are added to Breww, so it is worth reviewing them occasionally.
Groups are useful beyond permissions too. Tasks can be assigned to a whole group rather than an individual, so a group can be a handy way to represent a team even if its permissions are modest.
Creating and editing a custom group
- Go to
Settings->User groups & permissions - Click New group (or the pencil icon on an existing custom group)
- Give the group a Name. Names must be unique, and cannot clash with a system group name
- Tick the Users who should be in the group
- Tick the Permissions the group should grant
- Click Save group
Both the Users and Permissions lists on this form replace what was there before. Whatever is ticked when you save becomes the complete membership and the complete permission set for that group, so check the existing ticks before saving rather than only adding your new ones.
To see a group's permissions and members at a glance, click the eye icon to open its detail page.
Deleting a group
Only custom groups can be deleted, and only once they have no members. If the delete button isn't available, remove the remaining users from the group first. System groups can never be deleted.
Managing an individual user
Go to Settings -> Users & security settings and click a user to open their page. From here you can:
- Manage user's groups - tick the groups this person belongs to. As with the group form, the ticked list becomes their complete set of groups
- Manage user's additional permissions - grant permissions on top of their groups. Again, the ticked list replaces their existing additional permissions
- Remove a single group - use the red cross next to a group in the User groups table
Each permission badge on this page has a tooltip explaining what that permission allows, so hover over anything you're unsure about.
Permissions worth understanding
Most permission names describe themselves well, but a few are broader than they first appear:
| Permission | Worth knowing |
|---|---|
| Brewery admin | Full access to everything, including managing other users' permissions and your billing |
| Settings | Covers far more than it sounds like. As well as the main settings pages (invoicing, email, delivery, production, products, purchasing, labels), it includes sites and locations, customer tags, your trade store settings and the data import tools. It does not grant user or permission management |
| Reporting vs All reporting | Reporting gives access to reports in line with the user's other permissions. All reporting grants every report regardless of what else they hold, without granting the ability to create or change data |
| Export reports and bulk data | Needed to export reports and lists to Excel or CSV. It does not affect exporting individual records such as an invoice or delivery note PDF |
| Redact customer data | Helpful for GDPR requests, but very destructive and not reversible |
| Update pricing after invoicing and Revert invoiced orders back to confirmed orders | Both unlock records that Breww normally locks once invoiced. Changes made this way are not synced to your accounting software and must be handled manually |
| Unblock order processing | Anyone can block order processing for a customer, but only holders of this permission can allow it again |
| View other users' leads and Manage other salespeople's sales visits | Control whether salespeople can see colleagues' leads and visits. Unassigned leads and visits remain visible either way |
User flags
The user's page also has User flags, which are separate from permissions.
- Sales person - marks the user as a salesperson. Only people with this flag can be picked as the salesperson on customers, leads, deals, sales visits, orders and credit notes, or be selected as the recipient when transferring customer assignments between users
- Advanced sales visit routing - gives this user access to the Advanced sales visit routing addon
Advanced sales visit routing is a billable addon, charged per subscribed user per month. You'll be asked to confirm you understand this when enabling it. Turning it on for someone who isn't already a salesperson marks them as one automatically, and you must turn the addon off for a user before you can un-mark them as a salesperson.
Adding ordinary users costs nothing. All Breww accounts include unlimited users, and your subscription is based on your production volume rather than your headcount. This addon is the exception.
Removing and reinstating access
To remove someone, open their user page and click Remove user. They immediately lose access to your brewery, and if they were using it at the time they are disconnected from it. Their records stay intact, so past sales, production actions and other history remain reportable.
Removed users appear in a Users who previously had access table at the bottom of Settings -> Users & security settings, and you can reinstate them at any time with the Reinstate access button on their page. You cannot remove your own access.
Before removing someone, transfer their outstanding tasks and customer assignments to a colleague. See Transferring user data between team members. This can still be done after their access has been revoked.
Auditing who can do what
Two tools live under the Actions & tools menu on Settings -> Users & security settings.
Export user permissions
Downloads an Excel workbook with four sheets:
- Users - one row per user with their groups, whether they're a brewery admin, how many permissions they hold and when they last logged in
- Permission matrix - every user against every permission, marked
Groupwhere a group grants it,Directwhere it was granted individually, andAdminfor brewery admins (who hold everything) - Groups - every group in use, its type, how many members it has and exactly which permissions it grants
- Permission reference - the full list of permissions and what each one allows
This is a good way to review access periodically, or to hand evidence to an auditor.
Permission change log
A simple audit trail of permission changes, showing who changed what, for whom, and when. It records invites being sent, access being revoked or reinstated, a user's groups or additional permissions being updated, a user being removed from a group, and 2FA being cleared for a user.
Records have only been kept since 23 July 2025, so earlier changes will not appear. Changes made by editing a group itself (its permissions or its membership list) are not currently recorded here, so a group edit that changes what its members can do won't show up.
Security settings
The Security settings section on Settings -> Users & security settings lets you require two-factor authentication for everyone on the account. See Setting up Two-factor authentication (2FA) for how this works and what it means for users who are already logged in.