Overview
Mobaro has two ways to manage access for many people at once: Roles and User Groups. They answer different questions. A Role decides what a User can do. A User Group decides who they work with and where: which work reaches them, which Locations they're a member of, and which Roles the whole team gets.
Most setups use both. This article compares them and shows when to use each. For how they combine with Super Users and Location membership, see How access works in Mobaro.
At a glance |
|
Who can do this | Super Users, or a Role with Roles or User Groups permissions. A group's Administrators can also edit it. |
Where | Roles and User Groups in the Backend menu |
Works on | Backend (web). Roles and group membership also apply in the Mobile app and RideOps. |
Availability | All organizations |
💡 Why this matters: Getting the split right keeps you to a few Roles that are easy to audit, and turns a team change into one edit to a User Group instead of dozens of edits to Users.
Roles decide what someone can do
A Role is a set of permissions, chosen area by area: for example View, Create, Modify or Delete for Checklists, Schedules or Users, plus area-specific ones such as Results › Validate or Assets › Administrate. A User can hold several Roles, directly or through User Groups, and their permissions add up.
A Role applies across the whole organization. It can't be limited to certain Locations. See Role permissions reference and Set up Roles to manage permissions.
User Groups decide who and where
A User Group is a named set of Users. On its own it grants no permissions. Use it to act on the whole team at once:
Assign work: pick the group as an assignee, reviewer or owner, for example on a Schedule or an Assignment.
Notify: add the group as a recipient of a Notification Rule.
Give Location membership: add the group to a Location, and every member becomes a member of it.
Give a Role: add the group to a Role, and every member gets its permissions.
Delegate: a group's Administrators can manage its members, and Delegable user groups let members assign work to another team.
A User can be in any number of User Groups. See Create and manage User Groups and Delegable User Groups.
Side-by-side comparison
Question | Role | User Group |
Decides what a User can do | Yes | Only by being added to a Role |
Makes Users members of Locations | No | Yes |
Can be limited to certain Locations | No, it applies organization-wide | Its Locations decide where members work |
Can be an assignee, reviewer or notification recipient | No | Yes |
Has its own Administrators | No | Yes |
Lets members assign work to another team | No | Yes, with Delegable user groups |
A User can have several | Yes | Yes |
How they work together
What a User can do comes from their Roles. Which Location-based records they see comes from their Location membership, which usually comes from their User Groups. Results, Assignments, Notes, Gallery images and Downtime show only for Locations the User is a member of, whatever their Role.
For example, Maria holds a Maintenance Technician Role with Assignments › View and Modify, and is in the Maintenance — East User Group, which is a member of the East-zone Locations. She sees and updates Assignments at the East-zone Locations only. Moving her to the West group changes her Locations, with no Role change.
⚠️ Heads-up: Configuration permissions aren't limited by User Groups or Locations. If Maria's Role also had Schedules › Modify, she could edit every Schedule in the organization, East or West. Only give configuration permissions to people who may use them everywhere.
Only Super Users can add Locations to a User Group in the User Group editor. Otherwise, add the group under Direct Memberships on each Location, which needs Locations › Modify. A Role with Locations › View shows every Location record but doesn't make anyone a member. See Giving Users access to a Location.
Quick decision guide
When you set up access for someone, ask in this order:
What do they need to do? Pick or create a Role, or give the Role to their team's User Group.
Which teams are they in? Add them to one or more User Groups.
Which Locations do they cover? Give membership through their User Groups; add them to a Location directly only when their scope is unusual.
Do they assign work to teams they're not in? Add that team under Delegable user groups on their group.
Do they administer the whole organization? Consider Super User status, which only Mobaro grants. See Super User access vs Roles.
Best practices
Build a small set of reusable Roles around jobs, such as Operator, Lead, Manager and Compliance read-only. Avoid one Role per person.
Mirror your real teams, zones and departments in User Groups, and avoid one group that contains everyone.
Give Location membership through User Groups rather than User by User, so one change reaches the whole team.
Don't add people to a group "for permissions": User Groups grant permissions only through a Role.
Add Delegable user groups only for real cross-team workflows; each one lengthens assignee lists.
Frequently asked questions
I gave a user a role with view permissions, but they still can't see all locations, notes or assignments. Why?
A Role doesn't decide which Locations someone sees. Results, Assignments, Notes, Gallery images and Downtime only show for Locations the User is a member of. Add the User, or one of their User Groups, to those Locations. See How access works in Mobaro.
Can a user belong to more than one user group?
Yes, to any number. They're a member of every group's Locations, can be assigned the work of each group, and get the permissions of every Role given to those groups, added together.
Can I give a permission to just one user group, for example view-only access?
Yes. Create a Role with only the permissions they need, then add the User Group to that Role. Every member gets the Role's permissions, and members who join later get them too.
How do I limit a manager to their own park or zone?
Through Location membership, not the Role: make them a member of only those Locations, ideally through a User Group. Roles can't be limited to Locations. See How access works in Mobaro.
When is a super user the right answer instead?
Only for the few people who administer the whole organization. Super User status applies per organization, gives every permission at every Location there, and only Mobaro can grant it. See Super User access vs Roles.
