Skip to main content

Access Control

Access control sets what each team member can see and do. You set access for each person in Fleet → Team members.

Access applies to one organisation only. If a person is a member of two organisations, their access in one organisation has no effect on their access in the other.

A role does not give access

A role is only a label. A team member who has only a role cannot see packages or do other tasks.

Access comes from the permission checkboxes. Select the permissions when you add or invite a person. If you set a role and do not select permissions, the person signs in to an empty dashboard.

If you change the role of a person later, their permissions do not change. You must change the permissions separately.

Roles​

RoleFunction
DriverThe only role that changes behaviour. It creates a driver profile with the licence number, expiry date, country of issue, probation status, and licence type. The person becomes available for assignment and for the mobile app.
Manager, Dispatcher, Picker, TechnicianLabels to organise your team list. These roles have no effect on access.
AdminYou do not assign this role. The dashboard shows each person who has all permissions as an admin.

Permissions​

Each permission has the name resource.action. The picker puts the permissions in groups by resource. Each group has a toggle that selects all permissions in the group.

GroupPermissionsScope
packagesview add update deletePackages, dimensions, delivery windows, tracking history, proof of delivery, and failure records
shiftsview assignAssign packages to drivers. Run route optimisation and see the results
driversview add update deleteDriver profiles and licence details
vehiclesview add update deleteVehicles, fuel cards, card transactions, payout setup, and service rates
customersview add update deleteCustomer records
warehouseview add update deleteWarehouse service entries
locationsviewLive driver locations and location history
team_membersview add edit deleteAdd, edit, deactivate, and reactivate team members and invitations
service_areaseditCreate and edit service areas. All members can see service areas without this permission
organisationeditOrganisation settings
Some permissions are not active yet

The picker shows service_rates.*, fuel_cards.*, and transactions.view, but these permissions are not active. At this time, the vehicles permissions control fuel cards, transactions, and service rates. If you select these permissions, nothing changes.

Add a team member​

  1. Go to Fleet → Team members. Select Add Team Member.
  2. Enter the details of the person. Select a Role. If you select Driver, the licence fields show.
  3. Select the permissions that the person needs. Do not skip this step. Refer to the warning above.
  4. Submit the form. The person gets an email invitation. Their access starts when they sign in for the first time.
You can only give permissions that you have

This rule applies when you add a person directly and when you send an invitation. If you select a permission that you do not have, the system refuses the request with the message You cannot grant permissions you do not hold. The system creates nothing: no account, no invitation, and no email.

A member with team_members.add can give other people some or all of their own permissions, but not more. To give a person a permission that you do not have, ask a user with all permissions to add that person.

The person who created the organisation has all permissions. Keep this account safe.

Starting points​

Use these permission sets as a start, and change them for your team.

JobPermissions
DriverNone. Refer to the section below.
Dispatcherpackages.view packages.add packages.update · shifts.view shifts.assign · drivers.view · vehicles.view · locations.view · customers.view
Warehouse / pickerpackages.view packages.update · warehouse.view warehouse.add warehouse.update · customers.view
Fleet technicianvehicles.view vehicles.update · drivers.view
Operations managerThe dispatcher set, plus team_members.*, service_areas.edit, and organisation.edit

Let a dispatcher manage drivers only. If you give a dispatcher drivers.add, drivers.update, or drivers.delete, the dispatcher can add, edit, and remove team members with the Driver role. The dispatcher cannot change managers or other dispatchers. For a person who manages only the driver roster, use these permissions instead of team_members.*.

What drivers get automatically​

A driver does not need permissions. When you assign a package to a driver, the driver can:

  • See the package, its customer, and the vehicle that the driver uses
  • Record proof of delivery, delivery failures, and tracking updates for the package
  • Share their location while they work
  • See their profile and location history

The driver cannot see other data. They cannot see the work of other drivers or packages that are not assigned to them. Give permissions to a driver only if the driver must see more than their assignments.

Change or remove access​

Change permissions. Change the permissions in the record of the team member. The changes apply from the next action of that person.

Deactivate a person. Deactivation stops sign-in and ends all active sessions of the person. The system deletes no data. The delivery history and records of the person stay. If you reactivate the person, their access comes back.

The system refuses two deactivations:

  • Your own account.
  • An account with all permissions. This rule prevents a lockout of the last administrator. If you must deactivate this account, first remove one permission from it.

When you deactivate many people at one time, the system processes each person separately. Some deactivations can succeed while others fail. Check the result for each person.

Tips​

  • Give the minimum access that the person needs. A person who must see packages usually does not need to delete them.
  • Keep two accounts with all permissions. You cannot deactivate an account with all permissions, but you can lose access to it. The second account gives you a way back in.
  • Be careful with team_members.add. A holder cannot create an account with more access than their own. But the holder can give all of their own permissions to other people.
  • Examine access when a person changes job. A role change alone does not change access.