Access Control
Access control sets what each team member can see and do. You set access for each person in Fleet → Team members.
Access applies to one organisation only. If a person is a member of two organisations, their access in one organisation has no effect on their access in the other.
A role is only a label. A team member who has only a role cannot see packages or do other tasks.
Access comes from the permission checkboxes. Select the permissions when you add or invite a person. If you set a role and do not select permissions, the person signs in to an empty dashboard.
If you change the role of a person later, their permissions do not change. You must change the permissions separately.
Roles
| Role | Function |
|---|---|
| Driver | The only role that changes behaviour. It creates a driver profile with the licence number, expiry date, country of issue, probation status, and licence type. The person becomes available for assignment and for the mobile app. |
| Manager, Dispatcher, Picker, Technician | Labels to organise your team list. These roles have no effect on access. |
| Admin | You do not assign this role. The dashboard shows each person who has all permissions as an admin. |
Permissions
Each permission has the name resource.action. The picker puts the permissions in groups by resource. Each group has a toggle that selects all permissions in the group.
| Group | Permissions | Scope |
|---|---|---|
| packages | view add update delete | Packages, dimensions, delivery windows, tracking history, proof of delivery, and failure records |
| shifts | view assign | Assign packages to drivers. Run route optimisation and see the results |
| drivers | view add update delete | Driver profiles and licence details |
| vehicles | view add update delete | Vehicles, fuel cards, card transactions, payout setup, and service rates |
| customers | view add update delete | Customer records |
| warehouse | view add update delete | Warehouse service entries |
| locations | view | Live driver locations and location history |
| team_members | view add edit delete | Add, edit, deactivate, and reactivate team members and invitations |
| service_areas | edit | Create and edit service areas. All members can see service areas without this permission |
| organisation | edit | Organisation settings |
The picker shows service_rates.*, fuel_cards.*, and transactions.view, but these permissions are not active. At this time, the vehicles permissions control fuel cards, transactions, and service rates. If you select these permissions, nothing changes.
Add a team member
- Go to Fleet → Team members. Select Add Team Member.
- Enter the details of the person. Select a Role. If you select Driver, the licence fields show.
- Select the permissions that the person needs. Do not skip this step. Refer to the warning above.
- Submit the form. The person gets an email invitation. Their access starts when they sign in for the first time.
This rule applies when you add a person directly and when you send an invitation. If you select a permission that you do not have, the system refuses the request with the message You cannot grant permissions you do not hold. The system creates nothing: no account, no invitation, and no email.
A member with team_members.add can give other people some or all of their own permissions, but not more. To give a person a permission that you do not have, ask a user with all permissions to add that person.
The person who created the organisation has all permissions. Keep this account safe.
Starting points
Use these permission sets as a start, and change them for your team.
| Job | Permissions |
|---|---|
| Driver | None. Refer to the section below. |
| Dispatcher | packages.view packages.add packages.update · shifts.view shifts.assign · drivers.view · vehicles.view · locations.view · customers.view |
| Warehouse / picker | packages.view packages.update · warehouse.view warehouse.add warehouse.update · customers.view |
| Fleet technician | vehicles.view vehicles.update · drivers.view |
| Operations manager | The dispatcher set, plus team_members.*, service_areas.edit, and organisation.edit |
Let a dispatcher manage drivers only. If you give a dispatcher drivers.add, drivers.update, or drivers.delete, the dispatcher can add, edit, and remove team members with the Driver role. The dispatcher cannot change managers or other dispatchers. For a person who manages only the driver roster, use these permissions instead of team_members.*.
What drivers get automatically
A driver does not need permissions. When you assign a package to a driver, the driver can:
- See the package, its customer, and the vehicle that the driver uses
- Record proof of delivery, delivery failures, and tracking updates for the package
- Share their location while they work
- See their profile and location history
The driver cannot see other data. They cannot see the work of other drivers or packages that are not assigned to them. Give permissions to a driver only if the driver must see more than their assignments.
Change or remove access
Change permissions. Change the permissions in the record of the team member. The changes apply from the next action of that person.
Deactivate a person. Deactivation stops sign-in and ends all active sessions of the person. The system deletes no data. The delivery history and records of the person stay. If you reactivate the person, their access comes back.
The system refuses two deactivations:
- Your own account.
- An account with all permissions. This rule prevents a lockout of the last administrator. If you must deactivate this account, first remove one permission from it.
When you deactivate many people at one time, the system processes each person separately. Some deactivations can succeed while others fail. Check the result for each person.
Tips
- Give the minimum access that the person needs. A person who must see packages usually does not need to delete them.
- Keep two accounts with all permissions. You cannot deactivate an account with all permissions, but you can lose access to it. The second account gives you a way back in.
- Be careful with
team_members.add. A holder cannot create an account with more access than their own. But the holder can give all of their own permissions to other people. - Examine access when a person changes job. A role change alone does not change access.