Skip to content

Roles & permissions matrix

Tero.Ops uses fine-grained, role-based permissions scoped to company and worksite level. This page is the at-a-glance matrix.

Roles matrix overview

The five standard roles

Company admin

Full read/write on everything at every worksite they belong to:

  • Create/delete worksites
  • Invite, edit, disable users
  • Configure settings, branding, integrations
  • Send announcements
  • All operational permissions below

Worksite admin

Full read/write within a single worksite (or a defined set):

  • Manage all assets, jobs, inventory at the worksite
  • Approve inventory requests, raise POs
  • Invite users into this worksite (cannot create new worksites)
  • Cannot change company-wide settings

Manager (Maintenance / Procurement / Fleet)

Operational manager — sees fleet/worksite views but isn’t a configuration admin:

  • Schedule jobs, create job templates
  • Manage PM schedules
  • Run reports
  • Cannot invite users or change settings

Technician / Crew

Day-to-day operational user:

  • See own assigned tasks, scan QR codes
  • Record job completions
  • Log meter readings
  • Submit work requests and inventory requests
  • Read-only on assets, history

Contractor (external)

Limited, project-scoped read access:

  • See projects you’re assigned to
  • See work requests linked to those projects
  • Update status on your own work
  • Cannot see other projects, other contractors, or company data

Full matrix

ActionCompany adminWorksite adminManagerTechnicianContractor
View assetsAssigned only
Create/edit assets
Delete assets
Create jobs
Complete own jobsAssigned only
Approve inventory request✅ (procurement)
Create / send PO✅ (procurement)
Receive stock
Create project
Manage users✅ (own worksite)
Configure settings
Send announcements✅ (own worksite)

Custom roles

If none of the standard roles fits, create a custom role in Company admin → Roles. Pick exactly which permissions it grants. Custom roles assign to users the same way as standard ones.