Browse docs
2. Prepare your organization

Set up roles and permissions

Last updated: July 2026

A role is a set of permissions that defines what a user can do. Every user is assigned a role, so getting roles right is how you keep people productive without giving them access they don't need. LambdaAssetCheck ships with several built-in roles, and you can create your own.

Who can do this: owners and admins. Where: Home → Administration → Roles.

Built-in roles

Several roles are included, each with a different permission set:

RoleWhat it can do
AdminFull system access — manage users, groups, sites, and templates, and view all inspections and data
Site managerSite-level management — manage users, inspections, and data at their assigned sites
InspectorRun inspections and view the ones they've conducted; cannot manage templates or users
ReviewerReview and approve inspection results and view reports; cannot create or edit templates
Viewer (read-only)Read-only access to reports and data; cannot conduct inspections or make changes — suitable for stakeholders

The principle of least privilege

Assign the minimum permissions each person needs to do their job — no more. Review roles regularly to keep them accurate, and note why users are assigned to particular roles and why any change was made. This keeps your data secure and your audit trail clean.

Create a custom role from scratch

- Title - Product role designation — pick the closest built-in behavior from the list (Other is the default and uses only the permissions you select). - Description

  1. Go to Administration → Roles and select Create.
  2. In the left column, enter the Role details:
  3. In the right column, choose the permissions for the role, grouped by area (Assets, Templates, Inspections, Audits, Incidents, Schedules, Work requests, Work orders, Flags, Tasks, and Assignment). Some permissions only appear when the product role designation is Admin or Site manager.
  4. Select Create to save.
The Create Custom Role page — Role details on the left (title, product role designation, description) with the permissions chooser on the right
The Create Custom Role page — Role details on the left (title, product role designation, description) with the permissions chooser on the right

Some administration permissions — Organization settings, Billing, Users, Sites, Groups — are available only when the Product role designation is Admin.

Copy an existing role

The fastest way to make a variant of an existing role:

  1. Go to Administration → Roles and select the role you want to base yours on.
  2. Select Copy to create custom role.
  3. Adjust the title, product role designation, description, and permissions.
  4. Select Create to save.

Site data access

Every role can be scoped to sites. The Site data access setting controls how far operational data (assets, inspections, tasks, and other site-scoped data) reaches:

  • On (organization-wide): the role can see operational data across all sites.
  • Off (assigned sites only): the role is limited to the sites its users are assigned to.

Site data access doesn't replace module permissions — you still grant Tasks, Assets, and so on separately. Combine it with View own / involved only on a module to narrow a list further, down to just the records a person created or is assigned to.

Permissions reference

When you create or edit a role, you choose exactly the permissions it should have, grouped by area. Some permissions only appear when the role's Product role designation is Admin (or Site manager) — those are noted per group. Grant only what the role needs.

Administration

*Available only when the product role designation is Admin.*

PermissionWhat it allows
Organization settingsManage organization settings such as single sign-on and custom branding, and set up integrations
BillingManage billing details and payment methods, and view tax invoices
UsersAdd and deactivate users, and manage user details and settings
SitesCreate, edit, activate/deactivate sites, and manage site membership
GroupsCreate, edit, mark groups inactive, and manage group membership

Assets

PermissionWhat it allows
ReadView assets
CreateCreate assets
UpdateEdit assets
AssignAssign assets
Manage asset typesCreate and manage asset types
Assign meters to asset typesAttach meters to asset types
Meter marked as Not EquippedMark an asset's meter as not equipped
New meter from asset sync – review requiredReview new meters created by asset sync
Meter status conflict detectedResolve meter status conflicts
View missing meter attemptsSee missing meter-reading attempts

*Meter review, missing-meter, and asset-sync meter alert permissions are available only when the product role designation is Admin.*

Templates

PermissionWhat it allows
ReadView templates and configurations
CreateCreate templates
UpdateEdit templates and conditional logic
Template configurationManage the configurations overview, response types, audit types, and incident types
ArchiveArchive templates and remove unpublished drafts (published templates are kept for history)

*Template configuration and Archive are available only when the product role designation is Admin.*

Inspections

PermissionWhat it allows
Conduct asset inspectionsCreate and conduct asset inspections
ReadView inspections within your site/data scope
View own / involved onlyLimit inspection lists to records you created or are assigned to

Audits

PermissionWhat it allows
Conduct audit inspectionsConduct site audits
ReadView audits within your scope
View own / involved onlyLimit audit lists to your own or involved records

Incidents

PermissionWhat it allows
ReadView incidents
CreateReport incidents
AssignAssign incidents
View own / involved onlyLimit incident lists to your own or involved records

Schedules

PermissionWhat it allows
ReadView schedules in your scope
CreateCreate schedules and view your own or assigned ones
UpdateEdit or cancel existing schedules
AssignView and assign other users' schedules within your scope

Work requests

PermissionWhat it allows
ReadView work requests
CreateCreate work requests
UpdateUpdate work requests
AssignReassign parent work requests and orders (child task assignment stays with the current parent assignee)
View own / involved onlyLimit lists to your own or involved records

Work orders

The same set as work requests, applied to work orders: Read, Create, Update, Assign (parent only), and View own / involved only.

Flags

PermissionWhat it allows
ReadView flags
CreateCreate flags
UpdateUpdate flags
AssignAssign flags
Review flags (approve / reject)Approve or reject flags at review
View own / involved onlyLimit lists to your own or involved records

Tasks

Controls standalone task access. For tasks under work requests or work orders, creating and assigning are controlled by the current parent assignee.

PermissionWhat it allows
ReadOpen and view tasks in your scope, in any status
View own / involved onlyLimit to tasks assigned to you or your groups, or created by you
CreateCreate standalone tasks
UpdateUpdate task details and complete tasks you can act on
Manage statusChange status for any in-scope task without being the assignee
CancelMark tasks as cancelled
Set priorityChange task priority
AssignAssign standalone tasks
Task settingsManage task types and task settings

*Manage status, Cancel, and Set priority are available only when the product role designation is Admin or Site manager. Task settings is available only when Admin.*

Assignment (owner / reviewer)

These decide who is eligible to be assigned as the owner or reviewer of work and issues.

PermissionWhat it allows
Work Request ownerEligible to be assigned as owner of work requests (manual and auto-created)
Work Request reviewerEligible to review work requests at IN_REVIEW; can close or cancel once all tasks are closed
Work Order ownerEligible to be assigned as owner of work orders
Work Order reviewerEligible to review work orders at IN_REVIEW; can complete or cancel once all tasks are closed
Audit Flag ownerEligible to be assigned new audit flags
Audit Flag reviewerEligible to review and close audit flags at REVIEW — ideally the auditor who ran the audit
Incident ownerEligible to be assigned new incident reports
Incident reviewerEligible to review and close incidents

Home dashboard tiles

The home dashboard is a read-only preview whose tiles switch on automatically based on the permissions above — there are no separate permissions to set here.

TileAppears when the role can…
Open actionsread actions / tasks
Due todayread schedules
Incidentsread incidents
High / critical flagsact with admin-equivalent capabilities
In-progress inspections / tasks / work itemsread inspections / tasks / work items
Agenda: inspections / tasks / incidentssee schedules / tasks / incidents

Edit a role

  1. Go to Administration → Roles and select the custom role.
  2. Update the Role details and adjust permissions in Choose permissions.
  3. Select Save changes.

Deactivate a role

To retire a role, select its Enabled toggle on the Roles page. Its status changes from Active to Inactive. Toggle it again to re-activate.

Was this page helpful?

Top