UniAsset
Home/Knowledge Base/Core Concepts/Roles and Permissions in UniAsset
Back to Core Concepts

Roles and Permissions in UniAsset

5 minBeginnerLast updated: January 2, 2026

Roles and permissions

Every user has exactly one role, which decides what they are allowed to do. There are five, in descending authority.

The five roles

RoleIntended forBroadly can
OwnerThe account holderEverything, including users, organization settings and billing
AdminOperational administratorFull asset, category and maintenance management; read users; no user management
ManagerTeam or site leadCreate and update assets, assign, manage maintenance, view reports; no deletion, no user management
EmployeeSomeone who does the workRead assets, update them, complete maintenance, check items out and in
ViewerRead-only stakeholderRead assets, categories, departments and checkouts

Each role holds an explicit set of permissions. Roles are not evaluated as a simple ladder, so "one step up" does not always mean "everything the level below can do plus one more thing" — check the table below for anything specific.

What each role can do

ActionOwnerAdminManagerEmployeeViewer
View assets, categories, departments
Create assets
Update assets
Delete / archive assets
Assign assets
View check-outs
Check assets out and in
Create people and locations
Create and edit categories
Manage departments
Record service records and PM rules
Update and complete maintenance
Configure SLA and escalation
Manage checklist templates
View reports
Executive Dashboard
View the user list
Invite, edit and deactivate users
Organization settings
Billing and subscription
API keys and webhooks
See usage warnings and upgrade prompts

Two entries in that table surprise people, so they are worth calling out:

  • Viewers cannot open Reports. Viewer is read-only on asset records, not a reporting role. If a stakeholder needs reports, give them Manager.
  • Departments are Owner-only to manage. Admins can see departments and file assets against them, but cannot create, rename or archive them.

Important: Only the Owner sees usage warnings and upgrade prompts. That is deliberate — commercial nudges belong to the person who can act on them.

Roles are not plan capabilities

Two independent checks run on every action, and both must pass.

QuestionDecided by
PermissionIs this person allowed to?The user's role
CapabilityIs this organization's plan allowed to?The plan

So:

  • A Viewer on Cosmos still cannot delete an asset — their role forbids it.
  • An Owner on Nova still cannot open the Executive Dashboard — their plan does not include it.

If something is unavailable, work out which of the two is blocking you. A padlock in the sidebar means plan; an item that is absent entirely usually means role. See Understanding plans and capabilities and Why can't I see this feature?.

Choosing a role

Owner — one per organization. The person accountable for the subscription. See How to transfer ownership.

Admin — for people who configure the system: categories, locations, statuses, maintenance setup. Admins can read the user list but cannot invite or deactivate anyone, and cannot manage departments.

Manager — for site and team leads. They run day-to-day asset operations and maintenance, and they can view reports, but they cannot delete assets or manage users. This is the right default for most supervisors — and the lowest role that can open Reports.

Employee — for technicians, field staff and warehouse operatives. They can update assets, complete maintenance and handle check-outs, but cannot create or delete assets and cannot view reports.

Viewer — for stakeholders who need to look at asset records without changing anything. Note that Viewer does not include Reports; a finance reviewer who needs report exports should be a Manager.

Tip: Start people lower than you think. Raising a role takes seconds and the change is live on their next request.

When a role change takes effect

Immediately — on the user's next request, not at their next sign-in. Role, plan and account status are re-read from the database on every request, so a demotion or a deactivation applies at once without waiting for a session to expire.

The same applies to deactivation: it revokes access on the next request.

Custom roles

(Available on Cosmos)

Cosmos organizations can define their own permission sets, specifying an asset scope — self, department, location or all — plus explicit flags for viewing, editing and deleting assets, managing users, and viewing the dashboard and reports.

Important: Custom roles can be defined and stored today, but access decisions are still made from the five system roles above. Define them if you want the structure in place, but assign the system role that actually reflects the access someone needs.

See Roles and permissions settings.

Common mistakes

Making everyone an Admin. Admins can restructure your categories and maintenance configuration. Most people need Employee or Manager.

Expecting Admin to manage users. User management is Owner-only. Admins can view the user list but not change it.

Using Viewer for people who need to update assets. Viewers cannot change anything. Technicians need Employee.

Using Viewer for people who need reports. Viewer has no report access at all. Use Manager.

Deleting a departing user's account. Deactivate instead. Deactivation revokes access immediately while preserving the history of everything they did.

Troubleshooting

"You do not have permission to perform this action." Your role does not include that permission. Ask your Owner to change it, or have someone with the right role do it. See Permission denied errors.

I'm an Admin but can't invite users. Correct — that is Owner-only.

My role changed but nothing happened. Reload the page. The change applies on the next request.

Related articles

Need Help?

If you have questions not covered in this article, our support team is here to help.

Contact Support