Overview
A Role is a set of permissions, chosen area by area in the Role editor. This article lists every permission you can tick on a Role, with the exact label you'll see, and what each one allows. Use it when you build or check a Role. To create a Role, see Set up Roles to manage permissions.
A Role applies across the whole organization, not per Location. Location membership separately limits which Locations' Results, Assignments, Notes, Gallery images and Downtime a User sees. See How access works in Mobaro.
At a glance |
|
Who can do this | Super Users, or a Role with Roles › Create (for Roles they create) or Roles › Modify |
Where | Administrate › Roles |
Works on | Backend (web). The permissions also apply in the Mobile app and RideOps. |
Availability | All organizations |
💡 Why this matters: Granting too much is the most common access mistake. Knowing exactly what each box unlocks lets you give a job the minimum it needs and keep your Roles easy to audit.
How permissions combine
They add up. A User gets every permission from every Role they hold, directly or through a User Group. Super Users have every permission.
Create includes your own items. For most areas, Create implies View, Modify and Delete for the items that User created. For Report Templates, it implies Modify and Delete for created Report Templates.
Some boxes tick others. Checklists › Modify also ticks Translate. Notes › Modify, Delete and Approve tick View Notes in Backoffice. Competencies › Administrate ticks View.
No Location limits. A Role can't be limited to certain Locations. Configuration permissions, such as Schedules › Modify, work on every item in the organization.
Checklists, Schedules and Assignments
Permission | What it allows |
Checklists › View | See every Checklist in the Backend. |
Checklists › Create | Create Checklists. Implies View, Modify and Delete for your own Checklists. |
Checklists › Modify | Edit any Checklist, including translations. |
Checklists › Delete | Delete any Checklist. |
Checklists › Translate | Manage a Checklist's translations without editing it. |
Schedules › View / Create / Modify / Delete | See, create, edit or delete Schedules across the organization. Create implies the others for your own Schedules. |
Assignments › View / Modify / Delete | View shows Assignments at Locations the User is a member of. Modify and Delete let them edit or delete Assignments. There's no Create box: anyone in the organization can create Assignments. |
To let someone edit only some Checklists, use permission folders instead of Checklists › Modify. See Utilizing checklist permission folders.
Results and reporting
Permission | What it allows |
Results › View | See Results at Locations the User is a member of. Doesn't include Certification Process Results. |
Results › Modify | Change the answers of a submitted Result. |
Results › Delete | Delete Results. |
Results › Validate | Approve or disapprove Results where the User, or one of their User Groups, is a Reviewer. |
Results › Validate Missing | Validate Missing Results for Schedules they review, at Locations they're a member of. Rescheduling one also needs Schedules › Create. |
Results › Validate RideOps | Validate RideOps opening and closing Results, without being a Reviewer. |
Report Templates › Create / Modify / Delete | Manage the Report Templates used to view and send Results. |
Dashboard Templates › Manage | Create and edit Dashboard Templates. |
Question Category Hierarchies › Create / View / Modify / Delete | Manage Question Category Hierarchies. |
Results has no Create box: Results come from completing Checklists.
Notes, Gallery and Library
Permission | What it allows |
Notes › View Notes in Backoffice | See Notes in the Backend. |
Notes › Modify | Edit Notes. |
Notes › Delete | Delete any Note. Users can always delete Notes they created. |
Notes › Approve | Approve Notes that require approval, or remove an approval with Reject Approval. |
Gallery › View Gallery | See all Gallery images at Locations the User is a member of. |
Gallery › Categorize Gallery | Add categories to Gallery images. |
Manuals and Directories › Create / View / Modify / Delete | Manage Library folders and their manuals, videos and links. Any of these boxes shows Library in the Backend menu. |
Operations and RideOps
Permission | What it allows |
Operations › Manage Downtime | Record and edit Downtime. |
Operations › Manage Dispatch Entries | Add and delete dispatch entries in the operational log. |
Operations › Manage Queue Entries | Add and delete queue-time entries in the operational log. |
Locations, Users and Roles
Permission | What it allows |
Locations › Create / View / Modify / Delete | Manage Location records. View shows every Location record but doesn't make the User a member. |
Location Groups › Create / View / Modify / Delete | Manage Location Groups. |
Users › Create / View / Modify / Delete | Modify lets a User set another User's password. Delete lets them delete, disable and enable Users. Neither works on Super Users. |
User Groups › Create / View / Modify / Delete | Manage User Groups and their members. |
Roles › Create / View / Modify / Delete | Manage Roles, and so other Users' permissions. |
Organization and other areas
Permission | What it allows |
Organization › Administrate | Open Organization › Configuration, including the API tab, and set the organization's default notification settings (with a Notification Rules permission to open that page). |
Notification Rules › Create / View / Modify / Delete | Manage Notification Rules. |
Competencies › Administrate | Manage Competencies, Certifications and Certification Processes. Implies View. |
Competencies › View | See Competencies and Certifications. |
Timesheets › Administrate | Manage Timesheets. |
Assets › Administrate | Manage Assets, only at Locations where the User is a member. |
🛑 Critical: Any Delete permission removes records, and Results › Delete removes inspection history. Roles › Modify, Users › Modify and Organization › Administrate let someone change who can do what. Give these to a small, trusted group and review them regularly.
Best practices
Build Roles around jobs, such as Ride Inspector or Maintenance Planner, not around people.
Start with View and add Create, Modify or Delete only when the job needs it.
Use permission folders when someone should edit only some Checklists.
Remember that Location membership, not the Role, decides which Locations' Results and Assignments someone sees.
Frequently asked questions
What permission does someone need to approve or validate checklists?
A Role with Results › Validate, plus being a Reviewer on the Schedule or Ad Hoc Slot, directly or through a User Group. For RideOps opening and closing Results, Results › Validate RideOps is enough. See Disapproving Results.
How do I make someone a super user?
You can't do it with a Role. Only Mobaro can make someone a Super User. See Activating a new Super User, or give them a Role with just the permissions their job needs.
Which permission lets someone create API keys?
Organization › Administrate. It opens Organization › Configuration, where the API tab is. Super Users can also create API keys.
How do I stop some users from seeing all the results?
Take Results › View out of their Roles and use each Schedule's Results visible to setting. See How access works in Mobaro.
Can a validator edit the answers in a result?
Not with Results › Validate alone. Changing a submitted Result's answers needs Results › Modify or Super User status.
A user without Notes › Delete can still delete notes. Is that right?
Yes, for Notes they created. Users can always delete their own Notes. Notes › Delete lets them delete other people's Notes too.
