Home/Knowledge Base/Settings/Roles & Permissions - Control What Each User Can Do
Back to Settings

Roles & Permissions - Control What Each User Can Do

7 min readintermediateLast updated: January 2, 2026

Overview

UniAsset uses role-based access control (RBAC) to determine what each user can see and do. Every user is assigned exactly one role — either one of the five built-in system roles or a custom role created by an Owner.

The Roles & Permissions page is where you view the built-in role definitions and manage any custom roles for your organisation.

Who Can Access This

Only the Owner can access the Roles & Permissions settings page and create or modify custom roles.

How to Access This Section

  1. Log in to your UniAsset account
  2. Click Settings in the left sidebar
  3. Select Roles & Permissions

The Five Built-in Roles

Built-in roles are fixed — they cannot be edited or deleted. Every UniAsset organisation has these five roles available.

Owner

The highest-privilege role. There is exactly one Owner per organisation.

  • Full access to all assets, categories, departments, locations, and settings
  • Can invite, edit, and remove users (including changing their roles)
  • Can manage billing and subscription settings
  • Can delete the organisation
  • Can create and manage API keys, webhooks, and integrations
  • Can create custom roles

Admin

Organisation-wide management access, excluding billing and a few Owner-exclusive actions.

Can doCannot do
Create, read, update, delete assetsAccess billing or subscription settings
Manage categories, departments, locationsDelete the organisation
Create and complete maintenance recordsManage API keys or webhooks
View reportsCreate or modify custom roles
Read user listInvite, edit, or delete users

Manager

Operational management without destructive or administrative capabilities.

Can doCannot do
Create, read, update assetsDelete assets
Assign assets to users or departmentsManage categories, departments, locations
Create and complete maintenance recordsView or manage user accounts
View reportsAccess billing, API keys, or settings

Employee

Day-to-day asset interaction — reading and updating, no deletions or management.

Can doCannot do
Read asset detailsCreate new assets
Update asset recordsDelete assets
Read and update maintenance recordsCreate maintenance records
Complete assigned maintenanceManage any settings
Mark maintenance as completeView reports

Viewer

Read-only access across the platform.

Can doCannot do
View assetsCreate, update, or delete anything
View categories and departmentsAccess settings
View organisation informationView reports

Viewers are never shown upgrade prompts or limit warnings.

Permission Reference

The table below summarises permissions across all five built-in roles:

PermissionOwnerAdminManagerEmployeeViewer
asset:create
asset:read
asset:update
asset:delete
asset:assign
category:create/update/delete
category:read
maintenance:create
maintenance:read
maintenance:update
maintenance:complete
maintenance:delete
report:view
user:create/update/delete
user:read
department:read
tenant:read
tenant:update

Custom Roles

In addition to the five built-in roles, Owners can create custom roles with granular control over asset scope and specific capabilities. Custom roles are useful when you need to give a user access to only part of your asset inventory — for example, a technician who should only see assets assigned to their department.

What a custom role defines

SettingOptions
Role nameAny label for internal reference
Asset scopeSELF, DEPARTMENT, LOCATION, or ALL
Can view assetsYes / No
Can edit assetsYes / No
Can delete assetsYes / No
Can manage usersYes / No
Can view dashboardYes / No
Can view reportsYes / No

Asset scope

The asset scope determines which assets a user with this custom role can see and act on:

ScopeWhat the user can access
SELFOnly assets assigned directly to them
DEPARTMENTAssets assigned to their department
LOCATIONAssets at their assigned location
ALLAll assets in the organisation

How to create a custom role

  1. Navigate to Settings > Roles & Permissions
  2. Click Create Custom Role
  3. Enter a Role Name
  4. Select the Asset Scope
  5. Toggle the individual permissions (view, edit, delete assets; manage users; view dashboard; view reports)
  6. Click Save

The custom role is immediately available to assign to users from the User Management page.

How to edit a custom role

  1. Navigate to Settings > Roles & Permissions
  2. Find the custom role and click Edit
  3. Update the name, scope, or permission toggles
  4. Save the changes

Changes apply to all users currently assigned that role.

How to delete a custom role

Custom roles that are assigned to one or more users cannot be deleted until those users are reassigned to a different role. Once no users hold the role, open its actions menu and select Delete.

Assigning Roles to Users

Roles are assigned from the User Management page, not from Roles & Permissions. See the User Management article for instructions on inviting users and changing their roles.

Important Notes & Limitations

Built-in roles cannot be modified

  • The five system roles (Owner, Admin, Manager, Employee, Viewer) are fixed. Their permission sets cannot be changed.

There is exactly one Owner per organisation

  • Ownership can be transferred to another user, but only one user can hold the Owner role at any time.

Custom roles are limited to asset-level scoping

  • Custom roles control asset access and a small set of capabilities. They do not provide granular control over settings pages, billing, or integrations — those remain tied to the built-in role hierarchy.

Custom role changes affect all users with that role immediately

  • Editing a custom role updates permissions for every user assigned to it in real time.

Only the Owner can manage custom roles

  • Admins cannot create, edit, or delete custom roles.

Frequently Asked Questions

Can an Admin invite and manage users?

No. Only the Owner can invite, edit, or remove users and change their roles. Admins can read the user list but cannot modify it.

What is the difference between Manager and Admin?

Admins have broader access: they can manage categories, departments, locations, and read the user list. Managers are limited to operational tasks — creating and completing maintenance, assigning assets — but cannot touch settings or user data. Neither role can access billing.

Can I create a role that only sees assets at a specific location?

Yes. Create a custom role and set the Asset Scope to LOCATION. Users with this role will only see and interact with assets at their assigned location.

Can I have multiple Owners?

No. UniAsset supports exactly one Owner per organisation. If you need Owner-level access for multiple people, consider whether the Admin role covers the required capabilities.

What happens to users assigned a custom role if that role is deleted?

You cannot delete a custom role while users are assigned to it. Reassign all users to another role first, then delete the custom role.

Can Employees create assets?

No. Employees can read and update existing assets and complete maintenance records, but they cannot create new assets. Use the Manager or Admin role for users who need to create assets.

Need Help?

If you have questions not covered in this article, our support team is here to help.

Contact Support