Permissions and Role Restrictions
The table below shows which actions are available to each role in the Access Control module. Owner and Superadmin inherit all Administrator permissions.
| Action | Administrator | BU Admin | App. Manager | Operator | Viewer |
|---|---|---|---|---|---|
| Create / edit users | ✓ | Own BU | ✓ | — | — |
| Delete users | ✓ | Own BU | — | — | — |
| Create / edit / delete groups | ✓ | ✓ | — | — | — |
| View all users | ✓ | Own BU | ✓ | ✓ | — |
| View all groups | ✓ | ✓ | Read-only | Read-only | — |
| Export data | ✓ | ✓ | ✓ | ✓ | — |
| View attendance | ✓ | Own BU | ✓ | ✓ | ✓ |
- ✓ - allowed
- — - not available
Notes
- BU Admin - scope is limited to the Business Unit they administer. They cannot see users or attendance from other Business Units.
- App. Manager - can create and edit users but cannot manage groups or delete users. Group list is visible in read-only mode.
- Operator - read-only access to users and groups; can view attendance and export data but cannot make any changes.
- Viewer - can only view attendance records for locations within their assigned scope. No user or group management.
- No role can disable its own account.