Roles & user groups

The three layers of access - role, workspace and user group - and how user groups limit which sites and networks each member sees.

Access in AssetLab has three layers. Each answers a different question, and together they decide what a member can do and see.

LayerQuestion it answersOptionsSet in
RoleWhat can this member do?Administrator, Manager, Staff, RequesterSettings → Users
WorkspaceWhich part of the app do they work in?Facilities, Infrastructure, or bothSettings → Users (Workspace column)
User groupWhich assets and features can they see?Site-based or network-basedSettings → Groups

The sections below cover roles and groups in detail; workspaces are covered under Users & invitations.

Roles are fixed

There is no per-role capability editor. Administrator, Manager, Staff, and Requester each unlock a defined set of capabilities (the roles capability matrix lists them), enforced at the route, action, and database layers. If you're looking for "Staff, but a bit more" or "Manager, but read-only", the answer is usually the next role up or down - not a customization screen.

That's deliberate: four well-understood roles audit cleanly. The flexibility lives one level down, in groups.

User groups

Settings → Groups (Administrator only). A group bundles members with a scope:

Scope dimensionExampleWhat it drives
SitesEast District facilitiesWhich sites members see, notification filtering, assignee suggestions, auto-assignment
NetworksWater mains, SidewalksWhich networks members see, infrastructure auto-assignment, notification filtering and the portal feature list
System classesMechanical, ElectricalWhich classified assets, work orders and PM schedules members see
Work categoriesHVAC, Hydrant flushingAuto-assignment: specialist groups for their categories

Groups come in two types - operational ("East Crew", "Water Crew") and requester ("Arena User Groups", "School A Staff"). Only operational groups take auto-assigned work; requester groups never do.

Infrastructure groups

Organizations with the Infrastructure module choose a workspace when they create an operational group:

A group's workspace is set when it is created. Requester groups are shared by both workspaces: one group can list sites and networks, and a requester whose groups list networks picks only features in those networks on the requester portal. A group that lists networks and no sites doesn't narrow what its members see in Facilities.

What groups drive

Designing your groups

  1. Mirror how work is actually dispatched - by district, by trade, or both. If your radio channels are "East", "West", and "Electrical", those are your groups.
  2. Leave administrators ungrouped. Ungrouped users are unrestricted, which is exactly what oversight roles need.
  3. Scope narrowly, membership generously. A group scoped to the right sites with a few extra members beats overlapping groups nobody can reason about.
  4. Revisit at reorganizations. Groups encode your org chart's delivery side; when districts merge, merge the groups the same week.

What groups are not