Skip to main content

Set up Roles to manage permissions

Create a Role, tick the permissions a job needs, give it to Users or User Groups, and edit or delete Roles safely.

Written by Logan Bowlby

Overview

Create a Role for each kind of work people do in Mobaro, tick the permissions that job needs, and give the Role to Users or User Groups. When the job changes, you edit the Role once and everyone holding it gets the change.

For what Roles are and their limits, see Introduction to Roles. For what each permission allows, see the Role permissions reference.

At a glance

Who can do this

Super Users, or a Role with Roles › Create (for Roles you create) or Roles › Modify

Where

Administrate › Roles

Works on

Backend (web). The Public API can list, update and delete Roles, but not create them.

Availability

All organizations

🛑 Critical: Anyone who can create or edit Roles can give any permission to anyone, including themselves. Give Roles permissions only to a small, trusted group of administrators.


Create a Role

1. Open Roles

In the Backend, go to Administrate › Roles. The list shows each Role's Name, Description, Users and User Groups.

Roles in the Administrate menu of the Mobaro Backend

2. Click Create

Click the + button (Create) in the toolbar above the list.

Create button on the Roles page

3. Name the Role

Enter a clear, job-based Name, such as Checklist Creator or Assignment Administrator. The name is required. Add a Description if it helps others understand what the Role is for.

Name and Description fields in the Role editor

4. Add Users and User Groups

Add individual Users under Users, or add teams under User Groups. Every member of an added User Group gets the Role, including people who join the group later.

Users and User Groups fields in the Role editor

5. Tick permissions and save

Tick the permissions for each area, granting only what the job needs. Some boxes tick others: for example, Checklists › Modify also ticks Translate. Click Save; you see "Role saved successfully." See the Role permissions reference for every box.

Permission checkboxes by area in the Role editor

Give a Role to more people

There are three ways to give someone a Role:

  • In the Role editor. Open the Role, click Edit and add them under Users. Anyone who can modify the Role can do this.

  • Through a User Group. Add their User Group to the Role, or add them to a User Group that already has it.

  • In the User editor. Super Users can add Roles under Direct Memberships › Roles. For everyone else, this field is read-only.

A User's Inherited Memberships show the Roles they get through User Groups.


Edit or delete a Role

To edit a Role, select it in Administrate › Roles and click Edit. Changes apply straight away to everyone holding the Role.

To delete a Role, select one Role, click Delete and confirm with Yes. Its Users and User Groups lose the permissions it gave them, unless another of their Roles grants the same ones. The Users and User Groups themselves aren't affected.

🛑 Critical: Deleting a Role can't be undone. Before you delete it, check its Users and User Groups columns, and give those people another Role if they still need access.


Best practices

  • Prefer focused, job-named Roles like Assignment Admin over one broad Administrator Role.

  • Give Roles to User Groups rather than User by User, so access follows team membership.

  • Start with View and add Create, Modify or Delete only when the job needs it.

  • Remember that a Role applies across the whole organization. To limit which Locations' Results and Assignments someone sees, use Location membership.

  • Review Roles regularly, especially Roles with Roles, User Groups, Users or Delete permissions. User Groups › Modify lets someone add people, including themselves, to a User Group that holds a Role.


Frequently asked questions

Why can't I add a role in a user's profile?

Only Super Users can change Roles in the User editor. With Roles › Modify, open the Role in Administrate › Roles and add the User under Users, or add them to a User Group that has the Role.

How do I give a new user the same access as an existing user?

Open the existing User and note their Roles, User Groups and Locations under Direct Memberships. Add the new User to the same Roles, User Groups and Locations. Schedules, Notification Rules and Assignments that name the existing User individually aren't copied.

Can I create a view-only user?

Mostly. Give them a Role with only View boxes. Anyone in the organization can still create Assignments, because Assignments have no Create permission.

How do I let someone only record downtime?

Make them a member of the Locations they report for: members can start Downtime there, unless your organization limits operational state management to certain User Groups. To also edit, close or delete Downtime, add a Role with only Operations › Manage Downtime.

What permissions does someone need to create users and add them to user groups?

Users › Create to create Users, and User Groups › Modify to add them to groups in the User Group editor. To give them Roles, they need Roles › Modify and add them in the Role editor.

Did this answer your question?