Skip to content

Roles & permissions

Access is role-based and scoped — a role applies at a specific level of the hierarchy, and assignment invitations grant access to just one claim.

The roles

RoleScopeWho it's for
Org adminEntire orgOwners / platform admins.
Business-unit adminOne business unitDivision or regional leads.
Team adminOne teamTeam leads who build schemas and run assignments.
MemberOne teamField staff who capture across the team's assignments.
CollaboratorOne assignmentSomeone brought in to help capture a specific loss.
ObserverOne assignmentA stakeholder who should see, but not change, a loss.

What each role can do

CapabilityOrg adminBU adminTeam adminMemberCollaboratorObserver
View media & documentation
Capture & edit media / rooms / groups
Edit people & details
Delete media
Create & manage assignments
Build & publish profiles (schema)
Invite / revoke assignment access
Manage team & members
Read the audit log
Manage webhooks

NOTE

This table reflects the default permission matrix. The mobile app and web console hide or disable actions your role can't perform — and the server enforces the same rules, so access can't be bypassed by the client.

Scoping, explained

  • A team admin manages their team only — not sibling teams.
  • A collaborator/observer sees only the assignment they were invited to. Being on one loss never reveals another.
  • Higher scopes include lower ones: an org admin can do anything a team admin can, everywhere.

IMPORTANT

Users are identified by email or phone. Invite people by whichever identifier they'll actually use to sign in.

Mission-critical loss documentation. Offline-first. Nothing lost.