Roles and permissions
Every user has exactly one role, which decides what they are allowed to do. There are five, in descending authority.
The five roles
| Role | Intended for | Broadly can |
|---|---|---|
| Owner | The account holder | Everything, including users, organization settings and billing |
| Admin | Operational administrator | Full asset, category and maintenance management; read users; no user management |
| Manager | Team or site lead | Create and update assets, assign, manage maintenance, view reports; no deletion, no user management |
| Employee | Someone who does the work | Read assets, update them, complete maintenance, check items out and in |
| Viewer | Read-only stakeholder | Read assets, categories, departments and checkouts |
Each role holds an explicit set of permissions. Roles are not evaluated as a simple ladder, so "one step up" does not always mean "everything the level below can do plus one more thing" — check the table below for anything specific.
What each role can do
| Action | Owner | Admin | Manager | Employee | Viewer |
|---|---|---|---|---|---|
| View assets, categories, departments | ● | ● | ● | ● | ● |
| Create assets | ● | ● | ● | — | — |
| Update assets | ● | ● | ● | ● | — |
| Delete / archive assets | ● | ● | — | — | — |
| Assign assets | ● | ● | ● | — | — |
| View check-outs | ● | ● | ● | ● | ● |
| Check assets out and in | ● | ● | ● | ● | — |
| Create people and locations | ● | ● | ● | — | — |
| Create and edit categories | ● | ● | — | — | — |
| Manage departments | ● | — | — | — | — |
| Record service records and PM rules | ● | ● | ● | — | — |
| Update and complete maintenance | ● | ● | ● | ● | — |
| Configure SLA and escalation | ● | ● | ● | — | — |
| Manage checklist templates | ● | ● | ● | — | — |
| View reports | ● | ● | ● | — | — |
| Executive Dashboard | ● | ● | — | — | — |
| View the user list | ● | ● | — | — | — |
| Invite, edit and deactivate users | ● | — | — | — | — |
| Organization settings | ● | — | — | — | — |
| Billing and subscription | ● | — | — | — | — |
| API keys and webhooks | ● | — | — | — | — |
| See usage warnings and upgrade prompts | ● | — | — | — | — |
Two entries in that table surprise people, so they are worth calling out:
- Viewers cannot open Reports. Viewer is read-only on asset records, not a reporting role. If a stakeholder needs reports, give them Manager.
- Departments are Owner-only to manage. Admins can see departments and file assets against them, but cannot create, rename or archive them.
Important: Only the Owner sees usage warnings and upgrade prompts. That is deliberate — commercial nudges belong to the person who can act on them.
Roles are not plan capabilities
Two independent checks run on every action, and both must pass.
| Question | Decided by | |
|---|---|---|
| Permission | Is this person allowed to? | The user's role |
| Capability | Is this organization's plan allowed to? | The plan |
So:
- A Viewer on Cosmos still cannot delete an asset — their role forbids it.
- An Owner on Nova still cannot open the Executive Dashboard — their plan does not include it.
If something is unavailable, work out which of the two is blocking you. A padlock in the sidebar means plan; an item that is absent entirely usually means role. See Understanding plans and capabilities and Why can't I see this feature?.
Choosing a role
Owner — one per organization. The person accountable for the subscription. See How to transfer ownership.
Admin — for people who configure the system: categories, locations, statuses, maintenance setup. Admins can read the user list but cannot invite or deactivate anyone, and cannot manage departments.
Manager — for site and team leads. They run day-to-day asset operations and maintenance, and they can view reports, but they cannot delete assets or manage users. This is the right default for most supervisors — and the lowest role that can open Reports.
Employee — for technicians, field staff and warehouse operatives. They can update assets, complete maintenance and handle check-outs, but cannot create or delete assets and cannot view reports.
Viewer — for stakeholders who need to look at asset records without changing anything. Note that Viewer does not include Reports; a finance reviewer who needs report exports should be a Manager.
Tip: Start people lower than you think. Raising a role takes seconds and the change is live on their next request.
When a role change takes effect
Immediately — on the user's next request, not at their next sign-in. Role, plan and account status are re-read from the database on every request, so a demotion or a deactivation applies at once without waiting for a session to expire.
The same applies to deactivation: it revokes access on the next request.
Custom roles
(Available on Cosmos)
Cosmos organizations can define their own permission sets, specifying an asset scope — self, department, location or all — plus explicit flags for viewing, editing and deleting assets, managing users, and viewing the dashboard and reports.
Important: Custom roles can be defined and stored today, but access decisions are still made from the five system roles above. Define them if you want the structure in place, but assign the system role that actually reflects the access someone needs.
See Roles and permissions settings.
Common mistakes
Making everyone an Admin. Admins can restructure your categories and maintenance configuration. Most people need Employee or Manager.
Expecting Admin to manage users. User management is Owner-only. Admins can view the user list but not change it.
Using Viewer for people who need to update assets. Viewers cannot change anything. Technicians need Employee.
Using Viewer for people who need reports. Viewer has no report access at all. Use Manager.
Deleting a departing user's account. Deactivate instead. Deactivation revokes access immediately while preserving the history of everything they did.
Troubleshooting
"You do not have permission to perform this action." Your role does not include that permission. Ask your Owner to change it, or have someone with the right role do it. See Permission denied errors.
I'm an Admin but can't invite users. Correct — that is Owner-only.
My role changed but nothing happened. Reload the page. The change applies on the next request.
Related articles
Need Help?
If you have questions not covered in this article, our support team is here to help.
Contact Support