Skip to content

Roles and permissions

Every person in your organization holds exactly one of six roles, and the role decides what they can see and do across the console and the mobile app.

The six roles

RoleWhat they do
Org adminEverything. Manages the organization, all business units and teams, users, profiles, assignments, workflows, webhooks, and integrations. The only role that can open Mission Control and manage webhooks and integration tokens.
Business Unit adminEverything an org admin can do, except managing webhooks and integration tokens. Typically runs a division or region.
Team adminRuns teams day to day: manages team members, builds and publishes capture profiles, creates and manages assignments, grants assignment access, and reads the audit log. Often a team lead or desk adjuster supervisor.
MemberCaptures media, works rooms and assignments in the field app, and views media. The standard role for field adjusters.
CollaboratorSame capture abilities as a member, but only on assignments they were specifically invited to. Ideal for contractors and outside adjusters.
ObserverView only. Can read media on assignments they are invited to, but cannot capture or change anything. Good for carrier representatives or managers who need visibility without access to capture.

The 13 permissions

Behind the scenes, each role is a bundle of permissions. The console enforces them server-side, so they cannot be bypassed.

PermissionPlain meaning
team.manageCreate, rename, and delete teams, and manage their members and settings.
schema.manageCreate, edit, publish, and archive capture profiles.
assignment.createCreate new assignments, including spreadsheet imports.
assignment.manageEdit assignment details, change statuses, and delete assignments.
assignment.access.grantInvite collaborators and observers to an assignment and revoke their access.
location.writeCreate, edit, reorder, and delete rooms on an assignment.
media.captureCapture photos, video, and audio in the field app.
media.readView captured media in the console and app.
media.deleteDelete media items (soft delete; the file is retained on the server).
person.writeAdd and edit people records.
webhook.manageCreate and manage webhook endpoints. Org admins only.
integration.manageCreate and revoke integration tokens. Org admins only.
audit.readView the audit log and workflow runs.

Who can assign which role

  • Only org admins can assign the org admin role. The role dropdown disables it for everyone else with the note "Only org admins can assign this role".
  • Collaborator and observer are assigned at the assignment level, not on the Users page. Org, business unit, and team admins grant them from the assignment Access tab when inviting someone by email or phone. See Assignment-level invitations.
  • Business unit admins, team admins, and members are assigned when you add or edit a user on the Users page.

The Roles page

Open People → Roles to see the page titled "What each role can do, and who holds it." It shows:

  • A card per role with a description, the permission badges it carries, and how many people currently hold it.
  • A Role assignments table listing every user with an inline role selector, so you can change roles in place without opening the user editor.

Custom roles cannot be created

The six roles are a fixed set enforced by the server. There is no way to create a custom role or tweak an individual permission. If a person needs more or less access, choose the closest role or use assignment-scoped invitations to narrow their reach.

Org membership versus assignment access

These are two separate layers, and understanding both prevents most access confusion:

  • Organization membership (the Users page) puts a person in your org with a role. Members and admins see the org's teams and assignments according to their role and your assignment visibility settings.
  • Assignment-scoped access (the assignment Access tab) grants a specific person, often someone outside the org, access to one assignment as a collaborator or observer. It does not make them an org member, and revoking it does not affect any org membership they have.

A contractor who only ever works one loss never needs org membership: invite them as a collaborator on that assignment, and revoke the invitation when the work is done.

Contents Capture Admin Guide