Overview
Mobaro gives people Backend permissions in two ways: Super User access, which includes everything in an organization, and Roles, which include only the permissions you choose. Choosing the right one for each person keeps access easy to manage when people join, change jobs or leave. This article compares the two and helps you decide.
At a glance |
|
Who can do this | Roles: Super Users, or a Role with Roles › Create or Modify. Super User status: Mobaro only. |
Where | Roles in the Backend. Super User requests: see Activating a new Super User. |
Works on | Backend (web) |
Availability | All organizations |
💡 Why this matters: Default to Roles. A Role covers almost every job, takes effect immediately and can be changed by you at any time. Super User access can't be narrowed, and only Mobaro can grant or remove it.
Super User access
Super User status applies per organization. A Super User has every permission in each organization they're a Super User of, and no extra access in any other organization. Super User access is all-or-nothing within an organization: it can't be limited to some areas or Locations, or made read-only. Only Mobaro can make someone a Super User or remove Super User status. There's no option for it in the Backend.
A few actions are reserved for Super Users, including changing a User's Roles, User Groups and Locations under Direct Memberships in the User editor, adding Locations to User Groups, setting External IDs, creating RideOps Keys and using Impersonate User. For the full list, see What is a Mobaro super user?.
Roles
A Role is a set of permissions that you create in the Backend under Roles and give to Users or User Groups. For each area, such as Checklists, Schedules, Assignments, Results, Locations or Users, you choose permissions like View, Create, Modify or Delete. A User can hold several Roles: permissions add up across all of them.
A Role applies across the whole organization. Which Locations' Results, Assignments and Notes a User sees depends on their Location membership, not their Role. See How access works in Mobaro and Set up Roles to manage permissions.
Compare Super User access and Roles
| Super User | Role |
Permissions | Every permission in the organization | Only the permissions you choose |
Limit to some areas, or read-only | No | Yes |
Manage Users and Roles | Yes | With Users and Roles permissions |
Change Roles, User Groups and Locations from the User editor | Yes | No |
Grant or remove it yourself in the Backend | No — only Mobaro | Yes |
Time to take effect | Usually one to three Mobaro support business days | Immediately |
When to ask for Super User access
Ask for Super User access for people who administer the whole organization, for example:
The person who owns Mobaro for your park and sets it up.
A system administrator who manages Users, Roles, User Groups and Configuration.
A backup administrator who covers for the first one during leave.
To request it, see Activating a new Super User. To remove it, see Deactivating a Super User.
When to use a Role instead
Use a Role whenever you can describe the job by the areas the person works in. That covers nearly every operational, supervisory and reporting job, for example:
Park or area manager: View and Modify on Checklists, Schedules and Assignments, and Results › View.
Maintenance supervisor: Assignments permissions, plus Assets › Administrate if your organization uses Assets.
Compliance officer: Results › View only, for reporting.
User administrator: Users permissions to create Users and set passwords, and Roles or User Groups permissions to give access.
People who only complete assigned Checklists in the Mobaro app don't need a Role. They need to be assignees and members of the right Locations.
⚠️ Heads-up: Don't ask for Super User access just because a Role hasn't been set up yet. Building the Role is usually faster than a Super User request, and you can change it yourself later.
Replace Super User access with a Role
When someone no longer needs Super User access, for example after moving to a regional job, ask Mobaro to remove it (see Deactivating a Super User). Then give them a Role, directly or through a User Group, that matches their new job.
Best practices
Keep at least two Super Users per organization, so someone can cover leave and urgent changes.
Start with the smallest Role that lets someone do their daily work, and add permissions when gaps appear.
Build small, reusable Roles and combine them, instead of one broad Role per person.
Review Super Users and Roles regularly, and ask Mobaro to remove Super User access as soon as someone changes job or leaves.
Frequently asked questions
How do I make someone a super user?
You can't do it in the Backend. Only Mobaro can make someone a Super User or remove Super User status. There's no option for it in the Backend. Send a request as described in Activating a new Super User.
What permissions does someone need to create users and reset passwords, without being a super user?
A Role with Users › Create and Modify. They can't change a User's Roles, User Groups or Locations in the User editor; give them Roles › Modify or User Groups › Modify to add Users from the Role or User Group editor instead.
Do I need to be a super user to create checklists and schedules?
No. A Role with Checklists › Create and Schedules › Create is enough. Create also lets people view, modify and delete the Checklists and Schedules they created themselves.
Why can't I edit a user even though I'm a super user?
Usually the User also belongs to another Mobaro organization where you don't have Users › Modify, or they're a Super User themselves, which only Mobaro can change. See What is a Mobaro super user?.
Does a super user also need roles?
Not for permissions: a Super User already has every permission in the organization. One exception: the missed-results digest only goes to Reviewers who hold a Role with Results › Validate Missing, even if they're Super Users.
