2. Prepare your organisation
Set up roles and permissions
A **role** is a set of permissions that defines what a user can do. Every user is assigned one or more roles, so getting roles right is how you keep people productive without giving them access they don't need. LambdaAssetCheck ships with several built-in roles, and you can create your own.
Last updated: August 2026
In this article
Who can do this: owners and admins. Where: Home → Administration → Roles.
Built-in roles
Several roles are included, each with a different permission set:
| Role | What it can do |
|---|---|
| Owner | Organisation owner — full access including billing and subscription management. Billing stays on this seeded role. |
| Admin | Org-level admin — manage users, groups, sites, templates, and operational data. Does not include billing or organisation deletion. |
| Site Manager | Site-level supervisor — assets, inspections, schedules, work requests, and tasks at the sites they have access to. |
| Inspector | Runs asset inspections (not audits); can view schedules and their tasks. Does not manage templates or users. |
| Technician | Completes work orders and tasks (maintenance and repair). |
| Auditor | Conducts audit inspections; can view assigned schedules and create tasks. Does not view assets, templates, or work requests. |
| Safety Manager | Reviews and closes audit flags; can access flag media and assign or review flags. |
| Viewer | Read-only access to dashboards, inspections, assets, and schedules — cannot conduct inspections or make changes. |
There is no seeded Reviewer role. Review and approve behaviour for work and inspections sits on Site Manager (and Admin/Owner) plus the assignment permissions you grant. Contractor is retired and maps to Technician.
The principle of least privilege
Assign the minimum permissions each person needs to do their job — no more. Review roles regularly to keep them accurate, and note why users are assigned to particular roles and why any change was made. This keeps your data secure and your audit trail clean.
Create a custom role from scratch
Custom roles depend on your plan: Basic has none, Advanced includes up to 3, and Professional is unlimited. You cannot designate a custom role as Owner.
- Title - Product role designation — pick the closest built-in behavior from the list (Other is the default and uses only the permissions you select). - Description
- Go to Administration → Roles and select Create.
- In the left column, enter the Role details:
- In the right column, choose the permissions for the role, grouped by area (Assets, Templates, Inspections, Audits, Incidents, Schedules, Work requests, Work orders, Flags, Tasks, and Assignment). Some permissions only appear when the product role designation is Admin or Site Manager.
- Select Create to save.
Some administration permissions — Organisation settings, Users, Sites, Groups — are available only when the Product role designation is Admin. Billing is owner-gated: it is not grantable on custom roles, including those with the Admin designation. Use the seeded Owner role for billing.
Copy an existing role
The fastest way to make a variant of an existing role:
- Go to Administration → Roles and select the role you want to base yours on.
- Select Copy to create custom role.
- Adjust the title, product role designation, description, and permissions.
- Select Create to save.
Site data access
Every role can be scoped to sites. The Site data access setting controls how far operational data (assets, inspections, tasks, and other site-scoped data) reaches:
- On (organisation-wide): the role can see operational data across all sites.
- Off (assigned sites only): the role is limited to the sites its users are assigned to.
Site data access doesn't replace module permissions — you still grant Tasks, Assets, and so on separately. Combine it with View own / involved only on a module to narrow a list further, down to just the records a person created or is assigned to.
Permissions reference
When you create or edit a role, you choose exactly the permissions it should have, grouped by area. Some permissions only appear when the role's Product role designation is Admin (or Site Manager) — those are noted per group. Grant only what the role needs.
Administration
Organisation settings, Users, Sites, and Groups are available only when the product role designation is Admin. Billing is not in this list for custom roles.
| Permission | What it allows |
|---|---|
| Organisation settings | Manage organisation settings such as single sign-on and custom branding, and set up integrations |
| Billing | Manage billing details and payment methods, and view tax invoices — seeded Owner only; stripped from every custom role, including Admin designation |
| Users | Add and deactivate users, and manage user details and settings |
| Sites | Create, edit, activate/deactivate sites, and manage site membership |
| Groups | Create, edit, mark groups inactive, and manage group membership |
Assets
| Permission | What it allows |
|---|---|
| Read | View assets |
| Create | Create assets |
| Update | Edit assets |
| Assign | Assign assets |
| Manage asset types | Create and manage asset types |
| Assign meters to asset types | Attach meters to asset types |
| Meter marked as Not Equipped | Mark an asset's meter as not equipped |
| New meter from asset sync – review required | Review new meters created by asset sync |
| Meter status conflict detected | Resolve meter status conflicts |
| View missing meter attempts | See missing meter-reading attempts |
Meter review, missing-meter, and asset-sync meter alert permissions are available only when the product role designation is Admin.
Templates
| Permission | What it allows |
|---|---|
| Read | View templates and configurations |
| Create | Create templates |
| Update | Edit templates and conditional logic |
| Template configuration | Manage the configurations overview, response types, audit types, and incident types |
| Archive | Archive templates and remove unpublished drafts (published templates are kept for history) |
Template configuration and Archive are available only when the product role designation is Admin.
Inspections
| Permission | What it allows |
|---|---|
| Conduct asset inspections | Create and conduct asset inspections |
| Read | View inspections within your site/data scope |
| View own / involved only | Limit inspection lists to records you created or are assigned to |
Audits
| Permission | What it allows |
|---|---|
| Conduct audit inspections | Conduct site audits |
| Read | View audits within your scope |
| View own / involved only | Limit audit lists to your own or involved records |
Incidents
| Permission | What it allows |
|---|---|
| Read | View incidents |
| Create | Report incidents |
| Assign | Assign incidents |
| View own / involved only | Limit incident lists to your own or involved records |
Schedules
| Permission | What it allows |
|---|---|
| Read | View schedules in your scope |
| Create | Create schedules and view your own or assigned ones |
| Update | Edit or cancel existing schedules |
| Assign | View and assign other users' schedules within your scope |
Work requests
| Permission | What it allows |
|---|---|
| Read | View work requests |
| Create | Create work requests |
| Update | Update work requests |
| Assign | Reassign parent work requests and orders (child task assignment stays with the current parent assignee) |
| View own / involved only | Limit lists to your own or involved records |
Work orders
The same set as work requests, applied to work orders: Read, Create, Update, Assign (parent only), and View own / involved only.
Flags
| Permission | What it allows |
|---|---|
| Read | View flags |
| Create | Create flags |
| Update | Update flags |
| Assign | Assign flags |
| Review flags (approve / reject) | Approve or reject flags at review |
| View own / involved only | Limit lists to your own or involved records |
Tasks
Controls standalone task access. For tasks under work requests or work orders, creating and assigning are controlled by the current parent assignee.
| Permission | What it allows |
|---|---|
| Read | Open and view tasks in your scope, in any status |
| View own / involved only | Limit to tasks assigned to you or your groups, or created by you |
| Create | Create standalone tasks |
| Update | Update task details and complete tasks you can act on |
| Manage status | Change status for any in-scope task without being the assignee |
| Cancel | Mark tasks as cancelled |
| Set priority | Change task priority |
| Assign | Assign standalone tasks |
| Task settings | Manage task types and task settings |
Manage status, Cancel, and Set priority are available only when the product role designation is Admin or Site Manager. Task settings is available only when Admin.
Assignment (owner / reviewer)
These decide who is eligible to be assigned as the owner or reviewer of work and issues.
| Permission | What it allows |
|---|---|
| Work Request owner | Eligible to be assigned as owner of work requests (manual and auto-created) |
| Work Request reviewer | Eligible to review work requests at IN_REVIEW; can close or cancel once all tasks are closed |
| Work Order owner | Eligible to be assigned as owner of work orders |
| Work Order reviewer | Eligible to review work orders at IN_REVIEW; can complete or cancel once all tasks are closed |
| Audit Flag owner | Eligible to be assigned new audit flags |
| Audit Flag reviewer | Eligible to review and close audit flags at REVIEW — ideally the auditor who ran the audit |
| Incident owner | Eligible to be assigned new incident reports |
| Incident reviewer | Eligible to review and close incidents |
Home dashboard tiles
The home dashboard is a read-only preview whose tiles switch on automatically based on the permissions above — there are no separate permissions to set here.
| Tile | Appears when the role can… |
|---|---|
| Open actions | read actions / tasks |
| Due today | read schedules |
| Incidents | read incidents |
| High / critical flags | act with admin-equivalent capabilities |
| In-progress inspections / tasks / work items | read inspections / tasks / work items |
| Agenda: inspections / tasks / incidents | see schedules / tasks / incidents |
Edit a role
- Go to Administration → Roles and select the custom role.
- Update the Role details and adjust permissions in Choose permissions.
- Select Save changes.
Deactivate a role
To retire a role, select its Enabled toggle on the Roles page. Its status changes from Active to Inactive. Toggle it again to re-activate.
Related articles
Previous article: Set up single sign-on
Next article: Sites →
Was this page helpful?
