← Back to Help Center

Permissions by role

This article explains what each BriqSafe role can access and which actions each role can perform. Access can also depend on your organisation’s plan, location permissions, and activity-category permissions.

Before You Get Started

  • The Cases feature requires the Assisted Escalations entitlement. Role permissions apply only after the entitlement is available.
  • The Users & Teams area requires the External User Access entitlement. Without it, the page shows an upgrade prompt instead of the member list.
  • Role permissions do not define which locations or activity categories a person can access. Internal users start with access to all locations unless their access is restricted. External users start with no access and must be granted locations.

Role overview

RoleMain accessImportant limits
ViewerCan read dashboards, locations, assets, clients, contacts, jobs, visits, and cases that they can access.Cannot create, edit, assign, close, reopen, or otherwise act on cases. Cannot submit jobs, manage users, edit contacts, or change organisation data. Cannot open the Users & Teams list.
EngineerCan create and edit cases, add follow-up activities, upload case files, link assets and systems, delete cases, edit assets, perform jobs, and sign off assigned visits.Cannot close, reopen, assign, or link related cases. Cannot delete assets. A case action button may be visible even when the action is refused.
InspectorCan review pending asset changes, approve or reject assets, edit assets, set asset assessments, and export asset lists. Can read team members and organisation contacts.Cannot change organisation members or write organisation contacts unless separately granted by a higher role. Asset deletion requires delete permission.
ManagerCan manage users, location and activity-category access, cases, organisation contacts, visit assignments, and client weekend-service settings. Can open the internal administration app.Cannot assign the Admin or Owner role. Cannot create or edit client details, archive an organisation, or author compliance and risk rules unless the required higher permission applies.
AdminCan edit organisation details and branding, create and edit clients, assign locations to clients, manage client contacts, and author compliance and risk rules.Cannot archive an organisation. Cannot manage an existing Owner unless they are an Owner.
OwnerHas the highest organisation-level access. Can perform Admin actions, manage other Owners, archive the organisation, and manage the organisation’s last-Owner requirement.The organisation must always have at least one active Owner. The last Owner cannot be demoted or deactivated.

In member lists, the internal role names Editor and Member appear as Inspector and Engineer.

Case permissions

Case access is separate from the feature entitlement.

  • Viewer users can open and read cases, but case changes are refused.
  • Engineer users can create and edit cases, add follow-up activities, attach files, link assets and systems, and delete cases.
  • Manager, Admin, and Owner users can start, close, reopen, assign, and reassign cases, and link or unlink related cases.

Closing a case requires Manager, Admin, or Owner access. Edit permission alone is not enough. The Agree to start and Reopen case buttons can be visible to users who cannot complete those actions.

User and access administration

Manager, Admin, and Owner users can use Users & Teams to invite users and change their roles, locations, and activity-category permissions.

  • A Manager can assign the standard roles but cannot grant Admin or Owner access.
  • An Admin can grant Admin access but not Owner access.
  • Only an Owner can grant Owner access or manage an existing Owner.
  • Only an Owner can deactivate an Owner. The last active Owner cannot be deactivated.
  • Inspector and Engineer users can receive a read-only member list when the entitlement is available. Viewer users cannot open the list.

After a role change, role-based menu entries update immediately, but some buttons and permissions can wait for the member’s sign-in session to renew. Signing out and signing in applies the change at once. Location, activity-category, and external-user changes refresh when the member’s BriqSafe tab regains focus.

Organisation, client, and contact access

  • Admin and Owner users can create and edit organisations, organisation details, branding, clients, client locations, and client contacts.
  • Manager users can add, edit, and delete organisation contacts. They can also change a client’s weekend-service setting, but cannot edit the client’s other details.
  • Inspector, Engineer, and Viewer users can read organisation contacts. They cannot open contact edit panels or manage certificates and training records.
  • All roles can browse the client list, but only Owner and Admin users can edit full client details.
  • Only an Owner can archive an organisation. An Owner or Admin can unarchive one.

Archived organisations are read-only for everyone. Memberships and roles remain in place while the organisation is archived.

Location and activity access

Access scope works differently for internal and external users:

  • For an internal user, Location Permissions restrict access. An empty restriction means the user has access to all locations.
  • For an external user, Location Permissions grant access. At least one location is required, and an external user with no locations cannot see anything.
  • Activity Category Permissions can narrow activity access. Leaving activity categories empty does not restrict an external user; they can still see every activity type.

A user’s dashboard figures, map locations, jobs, and other location-based data are limited to the locations they can access.

Check your role and access

  1. Open Organisation Settings and stay on My Organisations.
  2. Review the Role column for your role in each organisation. The current organisation is marked Current.
  3. To check your locations and activity categories, open Users & Teams and select your own member row, if your role and plan allow it.

The Role column shows only your role. It does not show your location or activity-category permissions. If you cannot open your own member panel, ask a Manager, Admin, or Owner to review it for you.