Skip to content
Guide

Roles and permissions

Thirteen roles. What each one is for, how much of the company it sees, and who can see what things cost.

A role carries two separate things: a set of permissions — what a person may do — and a data scope, which decides how much of the company those permissions apply to. Holding assets:read with a scope of “only their own records” shows a person their own laptop and nobody else’s.

Somebody can hold more than one role. Permissions add up; the narrowest scope wins, so combining Manager with Registered Employee does not widen what either can see.

Every role in PioAssets with its purpose, data scope and cost visibility
RoleWhat it is forSeesCosts?
Super AdminFull access: users, roles, offices, workflows and platform settings.The whole company Yes
IT AdministratorIT equipment, assignments, warranties and device lifecycle.The whole companyNo
HREmployees, onboarding and offboarding.The whole companyNo
Office AdministratorFurniture, kitchen equipment, pantry stock and office supplies.The whole companyNo
FinanceCosts, invoice verification, purchase approvals, vendor spend and budgets.The whole company Yes
ManagerReviews and approves requests raised by their direct reports.Themselves and the people they manageNo
Registered EmployeeSees their own equipment, raises requests, reports damage.Only their own recordsNo
AuditorRead-only: assets, invoices, approvals, the audit log and reports.The whole companyNo
Company AdminOwns the tenant — users, roles, workflows and configuration for the company.The whole company Yes
IT TechnicianCarries out the IT work: deploy, assign, repair, maintain.The whole companyNo
Procurement ManagerVendors, purchase requests and orders, RFQs and sourcing.The whole companyNo
Inventory ManagerStock, receiving, transfers and provisioning.The whole companyNo
VendorAn external supplier, signed in to keep its own catalogue. Sees only its own offers, orders and invoices — never another supplier’s prices, and never how offers compare.Only their own recordsNo

This table is generated from the same permission matrix the server enforces, so it cannot drift out of step with the product.

Why money is its own question

Purchase prices, invoice values and budgets are visible only to roles that carry a cost permission — Finance, Super Admin and Company Admin. Everyone else sees the equipment without its price, and the cost columns are absent from the response entirely rather than hidden in the page, so there is nothing to uncover by looking.

Scope, in practice

  • The whole company — most operational roles. They are trusted with the fleet, not restricted to a corner of it.
  • Themselves and the people they manage — Manager. Enough to approve what a direct report asks for, and no more.
  • Only their own records — Registered Employee and Vendor. Someone else’s laptop is not merely hidden from the page: the server will not return it.

Combinations the system will question

Some pairings undermine the point of having separate roles — raising a purchase and approving it, for instance. Assigning them together triggers a segregation-of-duties warning that has to be acknowledged deliberately. It is not blocked: a small company may have no choice, and pretending otherwise would only push the work outside the system.

Changing somebody’s role

Open People, choose the person, tick the roles and save. Changes take effect on their next request to the server — there is no overnight job to wait for.

Roles are also what decides who appears in an approval chain. A step that waits on “IT review” waits on whoever holds the IT Administrator role; if nobody holds it, the request cannot move, and the request page will say so.