Every user in FacilityLane has exactly one role per organization. Roles define what a user can do in each module, and location scope defines which data they can see.

Built-in roles

Roles and permissions page showing built-in roles and custom roles with user counts

The Roles page listing built-in and custom roles

Built-in roles cannot be deleted. If a built-in role does not fit, create a custom role instead of over-assigning Admin.

Custom roles

Create a custom role when you need a permission set that the built-in roles do not cover — for example, a “Storeroom Clerk” who can fully manage inventory but only view work orders.
1

Open Roles and Permissions

Go to Settings → Roles & Permissions and select Create Role.
2

Name the role

Use a descriptive name, such as “Storeroom Clerk” or “Read-only Auditor”.
3

Set permissions per module

For each module — work orders, assets, inventory, users, and the rest — toggle Read, Create, Edit, and Delete individually.
4

Save and assign

Save the role, then assign it to users from the Users page.
Custom role editor showing a grid of modules with read, create, edit, and delete checkboxes

The permission matrix for a custom role with read/create/edit/delete toggles per module

How granular permissions work

  • Read — the user can open and view records in the module.
  • Create — the user can add new records.
  • Edit — the user can modify existing records.
  • Delete — the user can remove records.
A user without Read on a module does not see it in navigation at all.

Location-scoped access

Permissions say what a user can do; location scope says where. Each user is either:
  • Global — access applies to every location in the organization, or
  • Scoped to specific locations — the user only sees records (work orders, assets, inventory, requests) belonging to those locations.
Set the scope when inviting a user or later from their user record — see Managing users.
User detail showing Technician role combined with two selected locations in the scope field

A user record showing role plus specific-location scope

Common pattern: give site supervisors the Supervisor role scoped to their site, and give regional managers the Manager role with Global scope.

Frequently asked questions

Yes. Roles are per organization. A user can be an Admin in one workspace and a Technician in another.
The changes apply to every user with that role the next time they load the app.
No. Vendors only see work orders assigned to them. See Vendors.