Set up roles and permissions
Last updated: July 2026
A role is a set of permissions that defines what a user can do. Every user is assigned a role, so getting roles right is how you keep people productive without giving them access they don't need. LambdaAssetCheck ships with several built-in roles, and you can create your own.
Who can do this: owners and admins. Where: Home → Administration → Roles.
Built-in roles
Several roles are included, each with a different permission set:
| Role | What it can do |
|---|---|
| Admin | Full system access — manage users, groups, sites, and templates, and view all inspections and data |
| Site manager | Site-level management — manage users, inspections, and data at their assigned sites |
| Inspector | Run inspections and view the ones they've conducted; cannot manage templates or users |
| Reviewer | Review and approve inspection results and view reports; cannot create or edit templates |
| Viewer (read-only) | Read-only access to reports and data; cannot conduct inspections or make changes — suitable for stakeholders |
The principle of least privilege
Assign the minimum permissions each person needs to do their job — no more. Review roles regularly to keep them accurate, and note why users are assigned to particular roles and why any change was made. This keeps your data secure and your audit trail clean.
Create a custom role from scratch
- Title - Product role designation — pick the closest built-in behavior from the list (Other is the default and uses only the permissions you select). - Description
- Go to Administration → Roles and select Create.
- In the left column, enter the Role details:
- In the right column, choose the permissions for the role, grouped by area (Assets, Templates, Inspections, Audits, Incidents, Schedules, Work requests, Work orders, Flags, Tasks, and Assignment). Some permissions only appear when the product role designation is Admin or Site manager.
- Select Create to save.

Some administration permissions — Organization settings, Billing, Users, Sites, Groups — are available only when the Product role designation is Admin.
Copy an existing role
The fastest way to make a variant of an existing role:
- Go to Administration → Roles and select the role you want to base yours on.
- Select Copy to create custom role.
- Adjust the title, product role designation, description, and permissions.
- Select Create to save.
Site data access
Every role can be scoped to sites. The Site data access setting controls how far operational data (assets, inspections, tasks, and other site-scoped data) reaches:
- On (organization-wide): the role can see operational data across all sites.
- Off (assigned sites only): the role is limited to the sites its users are assigned to.
Site data access doesn't replace module permissions — you still grant Tasks, Assets, and so on separately. Combine it with View own / involved only on a module to narrow a list further, down to just the records a person created or is assigned to.
Permissions reference
When you create or edit a role, you choose exactly the permissions it should have, grouped by area. Some permissions only appear when the role's Product role designation is Admin (or Site manager) — those are noted per group. Grant only what the role needs.
Administration
*Available only when the product role designation is Admin.*
| Permission | What it allows |
|---|---|
| Organization settings | Manage organization settings such as single sign-on and custom branding, and set up integrations |
| Billing | Manage billing details and payment methods, and view tax invoices |
| Users | Add and deactivate users, and manage user details and settings |
| Sites | Create, edit, activate/deactivate sites, and manage site membership |
| Groups | Create, edit, mark groups inactive, and manage group membership |
Assets
| Permission | What it allows |
|---|---|
| Read | View assets |
| Create | Create assets |
| Update | Edit assets |
| Assign | Assign assets |
| Manage asset types | Create and manage asset types |
| Assign meters to asset types | Attach meters to asset types |
| Meter marked as Not Equipped | Mark an asset's meter as not equipped |
| New meter from asset sync – review required | Review new meters created by asset sync |
| Meter status conflict detected | Resolve meter status conflicts |
| View missing meter attempts | See missing meter-reading attempts |
*Meter review, missing-meter, and asset-sync meter alert permissions are available only when the product role designation is Admin.*
Templates
| Permission | What it allows |
|---|---|
| Read | View templates and configurations |
| Create | Create templates |
| Update | Edit templates and conditional logic |
| Template configuration | Manage the configurations overview, response types, audit types, and incident types |
| Archive | Archive templates and remove unpublished drafts (published templates are kept for history) |
*Template configuration and Archive are available only when the product role designation is Admin.*
Inspections
| Permission | What it allows |
|---|---|
| Conduct asset inspections | Create and conduct asset inspections |
| Read | View inspections within your site/data scope |
| View own / involved only | Limit inspection lists to records you created or are assigned to |
Audits
| Permission | What it allows |
|---|---|
| Conduct audit inspections | Conduct site audits |
| Read | View audits within your scope |
| View own / involved only | Limit audit lists to your own or involved records |
Incidents
| Permission | What it allows |
|---|---|
| Read | View incidents |
| Create | Report incidents |
| Assign | Assign incidents |
| View own / involved only | Limit incident lists to your own or involved records |
Schedules
| Permission | What it allows |
|---|---|
| Read | View schedules in your scope |
| Create | Create schedules and view your own or assigned ones |
| Update | Edit or cancel existing schedules |
| Assign | View and assign other users' schedules within your scope |
Work requests
| Permission | What it allows |
|---|---|
| Read | View work requests |
| Create | Create work requests |
| Update | Update work requests |
| Assign | Reassign parent work requests and orders (child task assignment stays with the current parent assignee) |
| View own / involved only | Limit lists to your own or involved records |
Work orders
The same set as work requests, applied to work orders: Read, Create, Update, Assign (parent only), and View own / involved only.
Flags
| Permission | What it allows |
|---|---|
| Read | View flags |
| Create | Create flags |
| Update | Update flags |
| Assign | Assign flags |
| Review flags (approve / reject) | Approve or reject flags at review |
| View own / involved only | Limit lists to your own or involved records |
Tasks
Controls standalone task access. For tasks under work requests or work orders, creating and assigning are controlled by the current parent assignee.
| Permission | What it allows |
|---|---|
| Read | Open and view tasks in your scope, in any status |
| View own / involved only | Limit to tasks assigned to you or your groups, or created by you |
| Create | Create standalone tasks |
| Update | Update task details and complete tasks you can act on |
| Manage status | Change status for any in-scope task without being the assignee |
| Cancel | Mark tasks as cancelled |
| Set priority | Change task priority |
| Assign | Assign standalone tasks |
| Task settings | Manage task types and task settings |
*Manage status, Cancel, and Set priority are available only when the product role designation is Admin or Site manager. Task settings is available only when Admin.*
Assignment (owner / reviewer)
These decide who is eligible to be assigned as the owner or reviewer of work and issues.
| Permission | What it allows |
|---|---|
| Work Request owner | Eligible to be assigned as owner of work requests (manual and auto-created) |
| Work Request reviewer | Eligible to review work requests at IN_REVIEW; can close or cancel once all tasks are closed |
| Work Order owner | Eligible to be assigned as owner of work orders |
| Work Order reviewer | Eligible to review work orders at IN_REVIEW; can complete or cancel once all tasks are closed |
| Audit Flag owner | Eligible to be assigned new audit flags |
| Audit Flag reviewer | Eligible to review and close audit flags at REVIEW — ideally the auditor who ran the audit |
| Incident owner | Eligible to be assigned new incident reports |
| Incident reviewer | Eligible to review and close incidents |
Home dashboard tiles
The home dashboard is a read-only preview whose tiles switch on automatically based on the permissions above — there are no separate permissions to set here.
| Tile | Appears when the role can… |
|---|---|
| Open actions | read actions / tasks |
| Due today | read schedules |
| Incidents | read incidents |
| High / critical flags | act with admin-equivalent capabilities |
| In-progress inspections / tasks / work items | read inspections / tasks / work items |
| Agenda: inspections / tasks / incidents | see schedules / tasks / incidents |
Edit a role
- Go to Administration → Roles and select the custom role.
- Update the Role details and adjust permissions in Choose permissions.
- Select Save changes.
Deactivate a role
To retire a role, select its Enabled toggle on the Roles page. Its status changes from Active to Inactive. Toggle it again to re-activate.
Related articles
Was this page helpful?
