Skip to main content

Super User access vs Roles: choosing the right access model

Compare Super User access and Roles, and decide which one each person in your organization needs.

Written by Logan Bowlby

Overview

Mobaro gives people Backend permissions in two ways: Super User access, which includes everything in an organization, and Roles, which include only the permissions you choose. Choosing the right one for each person keeps access easy to manage when people join, change jobs or leave. This article compares the two and helps you decide.

At a glance

Who can do this

Roles: Super Users, or a Role with Roles › Create or Modify. Super User status: Mobaro only.

Where

Roles in the Backend. Super User requests: see Activating a new Super User.

Works on

Backend (web)

Availability

All organizations

💡 Why this matters: Default to Roles. A Role covers almost every job, takes effect immediately and can be changed by you at any time. Super User access can't be narrowed, and only Mobaro can grant or remove it.


Super User access

Super User status applies per organization. A Super User has every permission in each organization they're a Super User of, and no extra access in any other organization. Super User access is all-or-nothing within an organization: it can't be limited to some areas or Locations, or made read-only. Only Mobaro can make someone a Super User or remove Super User status. There's no option for it in the Backend.

A few actions are reserved for Super Users, including changing a User's Roles, User Groups and Locations under Direct Memberships in the User editor, adding Locations to User Groups, setting External IDs, creating RideOps Keys and using Impersonate User. For the full list, see What is a Mobaro super user?.


Roles

A Role is a set of permissions that you create in the Backend under Roles and give to Users or User Groups. For each area, such as Checklists, Schedules, Assignments, Results, Locations or Users, you choose permissions like View, Create, Modify or Delete. A User can hold several Roles: permissions add up across all of them.

A Role applies across the whole organization. Which Locations' Results, Assignments and Notes a User sees depends on their Location membership, not their Role. See How access works in Mobaro and Set up Roles to manage permissions.


Compare Super User access and Roles

Super User

Role

Permissions

Every permission in the organization

Only the permissions you choose

Limit to some areas, or read-only

No

Yes

Manage Users and Roles

Yes

With Users and Roles permissions

Change Roles, User Groups and Locations from the User editor

Yes

No

Grant or remove it yourself in the Backend

No — only Mobaro

Yes

Time to take effect

Usually one to three Mobaro support business days

Immediately


When to ask for Super User access

Ask for Super User access for people who administer the whole organization, for example:

  • The person who owns Mobaro for your park and sets it up.

  • A system administrator who manages Users, Roles, User Groups and Configuration.

  • A backup administrator who covers for the first one during leave.

To request it, see Activating a new Super User. To remove it, see Deactivating a Super User.


When to use a Role instead

Use a Role whenever you can describe the job by the areas the person works in. That covers nearly every operational, supervisory and reporting job, for example:

  • Park or area manager: View and Modify on Checklists, Schedules and Assignments, and Results › View.

  • Maintenance supervisor: Assignments permissions, plus Assets › Administrate if your organization uses Assets.

  • Compliance officer: Results › View only, for reporting.

  • User administrator: Users permissions to create Users and set passwords, and Roles or User Groups permissions to give access.

People who only complete assigned Checklists in the Mobaro app don't need a Role. They need to be assignees and members of the right Locations.

⚠️ Heads-up: Don't ask for Super User access just because a Role hasn't been set up yet. Building the Role is usually faster than a Super User request, and you can change it yourself later.


Replace Super User access with a Role

When someone no longer needs Super User access, for example after moving to a regional job, ask Mobaro to remove it (see Deactivating a Super User). Then give them a Role, directly or through a User Group, that matches their new job.


Best practices

  • Keep at least two Super Users per organization, so someone can cover leave and urgent changes.

  • Start with the smallest Role that lets someone do their daily work, and add permissions when gaps appear.

  • Build small, reusable Roles and combine them, instead of one broad Role per person.

  • Review Super Users and Roles regularly, and ask Mobaro to remove Super User access as soon as someone changes job or leaves.


Frequently asked questions

How do I make someone a super user?

You can't do it in the Backend. Only Mobaro can make someone a Super User or remove Super User status. There's no option for it in the Backend. Send a request as described in Activating a new Super User.

What permissions does someone need to create users and reset passwords, without being a super user?

A Role with Users › Create and Modify. They can't change a User's Roles, User Groups or Locations in the User editor; give them Roles › Modify or User Groups › Modify to add Users from the Role or User Group editor instead.

Do I need to be a super user to create checklists and schedules?

No. A Role with Checklists › Create and Schedules › Create is enough. Create also lets people view, modify and delete the Checklists and Schedules they created themselves.

Why can't I edit a user even though I'm a super user?

Usually the User also belongs to another Mobaro organization where you don't have Users › Modify, or they're a Super User themselves, which only Mobaro can change. See What is a Mobaro super user?.

Does a super user also need roles?

Not for permissions: a Super User already has every permission in the organization. One exception: the missed-results digest only goes to Reviewers who hold a Role with Results › Validate Missing, even if they're Super Users.

Did this answer your question?