Roles & permissions matrix
Tero.Ops uses fine-grained, role-based permissions scoped to company and worksite level. This page is the at-a-glance matrix.

The five standard roles
Company admin
Full read/write on everything at every worksite they belong to:
- Create/delete worksites
- Invite, edit, disable users
- Configure settings, branding, integrations
- Send announcements
- All operational permissions below
Worksite admin
Full read/write within a single worksite (or a defined set):
- Manage all assets, jobs, inventory at the worksite
- Approve inventory requests, raise POs
- Invite users into this worksite (cannot create new worksites)
- Cannot change company-wide settings
Manager (Maintenance / Procurement / Fleet)
Operational manager — sees fleet/worksite views but isn’t a configuration admin:
- Schedule jobs, create job templates
- Manage PM schedules
- Run reports
- Cannot invite users or change settings
Technician / Crew
Day-to-day operational user:
- See own assigned tasks, scan QR codes
- Record job completions
- Log meter readings
- Submit work requests and inventory requests
- Read-only on assets, history
Contractor (external)
Limited, project-scoped read access:
- See projects you’re assigned to
- See work requests linked to those projects
- Update status on your own work
- Cannot see other projects, other contractors, or company data
Full matrix
| Action | Company admin | Worksite admin | Manager | Technician | Contractor |
|---|---|---|---|---|---|
| View assets | ✅ | ✅ | ✅ | ✅ | Assigned only |
| Create/edit assets | ✅ | ✅ | ✅ | ❌ | ❌ |
| Delete assets | ✅ | ✅ | ❌ | ❌ | ❌ |
| Create jobs | ✅ | ✅ | ✅ | ❌ | ❌ |
| Complete own jobs | ✅ | ✅ | ✅ | ✅ | Assigned only |
| Approve inventory request | ✅ | ✅ | ✅ (procurement) | ❌ | ❌ |
| Create / send PO | ✅ | ✅ | ✅ (procurement) | ❌ | ❌ |
| Receive stock | ✅ | ✅ | ✅ | ✅ | ❌ |
| Create project | ✅ | ✅ | ✅ | ❌ | ❌ |
| Manage users | ✅ | ✅ (own worksite) | ❌ | ❌ | ❌ |
| Configure settings | ✅ | ❌ | ❌ | ❌ | ❌ |
| Send announcements | ✅ | ✅ (own worksite) | ❌ | ❌ | ❌ |
Custom roles
If none of the standard roles fits, create a custom role in Company admin → Roles. Pick exactly which permissions it grants. Custom roles assign to users the same way as standard ones.