Roles and permissions
Thirteen roles. What each one is for, how much of the company it sees, and who can see what things cost.
A role carries two separate things: a set of permissions — what a person may do — and a data scope, which decides how much of the company those permissions apply to. Holding assets:read with a scope of “only their own records” shows a person their own laptop and nobody else’s.
Somebody can hold more than one role. Permissions add up; the narrowest scope wins, so combining Manager with Registered Employee does not widen what either can see.
| Role | What it is for | Sees | Costs? |
|---|---|---|---|
| Super Admin | Full access: users, roles, offices, workflows and platform settings. | The whole company | Yes |
| IT Administrator | IT equipment, assignments, warranties and device lifecycle. | The whole company | No |
| HR | Employees, onboarding and offboarding. | The whole company | No |
| Office Administrator | Furniture, kitchen equipment, pantry stock and office supplies. | The whole company | No |
| Finance | Costs, invoice verification, purchase approvals, vendor spend and budgets. | The whole company | Yes |
| Manager | Reviews and approves requests raised by their direct reports. | Themselves and the people they manage | No |
| Registered Employee | Sees their own equipment, raises requests, reports damage. | Only their own records | No |
| Auditor | Read-only: assets, invoices, approvals, the audit log and reports. | The whole company | No |
| Company Admin | Owns the tenant — users, roles, workflows and configuration for the company. | The whole company | Yes |
| IT Technician | Carries out the IT work: deploy, assign, repair, maintain. | The whole company | No |
| Procurement Manager | Vendors, purchase requests and orders, RFQs and sourcing. | The whole company | No |
| Inventory Manager | Stock, receiving, transfers and provisioning. | The whole company | No |
| Vendor | An external supplier, signed in to keep its own catalogue. Sees only its own offers, orders and invoices — never another supplier’s prices, and never how offers compare. | Only their own records | No |
This table is generated from the same permission matrix the server enforces, so it cannot drift out of step with the product.
Why money is its own question
Purchase prices, invoice values and budgets are visible only to roles that carry a cost permission — Finance, Super Admin and Company Admin. Everyone else sees the equipment without its price, and the cost columns are absent from the response entirely rather than hidden in the page, so there is nothing to uncover by looking.
Scope, in practice
- The whole company — most operational roles. They are trusted with the fleet, not restricted to a corner of it.
- Themselves and the people they manage — Manager. Enough to approve what a direct report asks for, and no more.
- Only their own records — Registered Employee and Vendor. Someone else’s laptop is not merely hidden from the page: the server will not return it.
Combinations the system will question
Some pairings undermine the point of having separate roles — raising a purchase and approving it, for instance. Assigning them together triggers a segregation-of-duties warning that has to be acknowledged deliberately. It is not blocked: a small company may have no choice, and pretending otherwise would only push the work outside the system.
Changing somebody’s role
Open People, choose the person, tick the roles and save. Changes take effect on their next request to the server — there is no overnight job to wait for.
Roles are also what decides who appears in an approval chain. A step that waits on “IT review” waits on whoever holds the IT Administrator role; if nobody holds it, the request cannot move, and the request page will say so.