Skip to main content
Every new organisation starts with twelve roles. They are a starting point — you can change what each includes, and add your own.

The roles

Where the boundaries sit

A supervisor moves a preventive round; only a planner decides it stops happening. The supervisor owns today; the planner owns the schedule.
A technician may add a photograph or a comment to a job; they may not remove one. A supervisor may. The photograph of the thing you were sent to fix is evidence, and evidence should not be removable by the person it concerns.
Technicians can create and edit meter readings. Taking a reading is the most ordinary thing a technician does — a role that could fit a new meter and then not write a number on it would be an inversion.
A maintenance manager reads inventory but does not move stock; a storekeeper moves stock but does not plan maintenance. A manager can approve a requisition.
Deliberately narrow. A vendor sees the jobs given to them and the assets those concern — not your asset register, not your other vendors, not your costs.
A technician may ask the copilot and read what comes back — somebody standing at the machine wanting to know how to repair it is the whole point of the feature. They may not accept a suggestion, because accepting writes to a record, and that stays with the roles that already edit one.Agreeing to switch the copilot on at all is a configuration permission, not a maintenance one.
Both read everything and change nothing. An auditor additionally gets the audit trail — field-level history of who changed what. An executive gets analytics instead.

Combining roles

Give somebody several and they get the union. A working combination is Planner + Supervisor for a small plant where one person does both.

Making your own

Add a role and choose its permissions on the permission grid: one row per resource, grouped by area — assets, work, maintenance, inventory, tools, workforce, vendors, procurement, reliability, analytics, documents, admin — one column per action. View, Create, Edit, Assign, Close and Export are the ordinary verbs; Delete, Approve and Admin are flagged as dangerous because they’re the ones that are hard to walk back.
The twelve defaults are marked as system roles. You can edit what they contain — that’s expected, and the edit is permanent, not something a later release reverts or re-applies over. When a future release adds a new permission, it arrives ungranted everywhere, system roles included — nobody has it until an admin grants it.System roles can be edited but not deleted, so there’s always at least one role that can reach admin capability. See deleting a role. The codes themselves don’t change, so the dashboards keep knowing which board to offer whom.

Which dashboard each role gets

Roles are not scope

A role says what somebody may do. It does not say where. Site and asset access do that, and they are set per user — see people and access.