BriqSafe Help Center
← Back to Help Center

Roles and permissions

This article provides an overview of roles and permissions in BriqSafe. It is intended for users who manage access within their organisation, including owners, admins, managers, and team members.

Note

Required role: Manager or higher to invite and manage users; Owner or Admin for organisation-level administration.

Understanding User Roles

Roles in BriqSafe determine a user's level of access and capabilities within an organisation. The main roles include Owner, Admin, Manager, Inspector, Engineer, and Viewer. Your ability to assign or alter roles depends on your own role:

  • Owner – the highest role with full control, including managing other owners.
  • Admin – administrative privileges but cannot manage Owners.
  • Manager – manages users but cannot assign Admin or Owner roles.
  • Inspector and Engineer – team members with read or action permissions but no management rights.
  • Viewer – read-only access without permission to see or manage users.

Only an Owner can assign or remove the Owner role, and only an Admin or Owner can assign the Admin role. Managers can assign all other roles.

Inviting Users to Your Organisation

Users screen for the Hotel Gran Vía site, displaying a list of site users with their status, roles, and activity categories, and featuring an "Add user to site" button to manage user access.

Invite new team members or external partners with predefined roles and scoped access.

  1. Open Users & Teams and select Add team member to open the Invite User form.
  2. Enter the new user’s Email address. You may enter multiple addresses separated by commas, semicolons, or by pressing Enter.
  3. If the person is outside your organisation, enable the External User toggle.
  4. Choose a Role from the dropdown; only roles at or below your own appear.
  5. Under Site Permissions, click Add Site to grant location access.
  6. Under Activity Category Permissions, click Add Activity Category to scope access.
  7. Click Invite User; a confirmation message User invitation sent successfully appears.

Note: Internal users start with full access by default, so your site and activity selections restrict them. External users start with no access, so you must grant at least one location and relevant activities; otherwise, they see no information after signing in. Selecting the Owner role forces the user to be internal regardless of the External User toggle.

Editing User Roles and Access

Change an existing user's role, location access, or activity-category access when responsibilities change.

  1. Open Users & Teams and select the user to open the Update User panel.
  2. Adjust the Role, Site Permissions, or Activity Category Permissions.
  3. Click Update to save changes; updates take effect immediately.

Important: The organisation must always have at least one Owner. You cannot change or deactivate the last Owner without first assigning another Owner. Changing activity-category access updates permissions only and does not reassign scheduled jobs, so review upcoming work.

Managing Invitations

Resend or withdraw pending invitations as needed.

  1. In Users & Teams, find the user with status Pending invite.
  2. Select the user to open the form as Update User.
  3. Optionally update role, sites, or activity categories.
  4. Click Update and Reinvite to resend the invitation with updated access.
  5. To withdraw the invitation, use the Delete invite action.

Deleting an invitation revokes access immediately and removes it from the list. The previously sent invitation link will no longer work.

Deactivating and Reactivating Users

Suspend or restore a user’s access when they leave or return.

  1. Open Users & Teams and select the user.
  2. Click Deactivate User and confirm; this immediately revokes login access and removes assignments.
  3. To restore access, select the inactive user and click Activate User.

Deactivation is a status change—not a deletion—so historical records are preserved. A deactivated user cannot log in until reactivated.

External User Access Scoping

When inviting external users such as subcontractors, limit their access only to relevant locations and activity types.

  1. Enable External User during invitation.
  2. Grant at least one location under Site Permissions using Add Site.
  3. Select required activity categories under Activity Category Permissions with Add Activity Category. Activity categories are grouped by domain.

Note: External users start with no access; you must grant access explicitly. An external user with no location granted can sign in but will see no information.

Organisation Roles and Permissions Overview

BriqSafe restricts role assignment according to a strict hierarchy:

RoleCan Assign RolesAccess Level
OwnerAll roles including OwnerFull organisation control
AdminAll except OwnerOrganisation administration (cannot manage Owners)
ManagerManager, Inspector, Engineer, ViewerUser management excluding Admin and Owner roles
Inspector, EngineerNoneOperational roles with scoped access
ViewerNoneRead-only, no user visibility

Additional Notes on Permissions

  • Role changes take effect immediately and do not require the user to log out or back in.
  • Only an Owner can manage or remove the Owner role; attempting otherwise results in an error.
  • The organisation must always retain at least one Owner; attempts to remove or demote the last Owner are blocked.
  • Users can belong to multiple organisations, but roles are specific to each organisation.
  • Currently, users cannot view a consolidated summary of their own roles and permissions within the app; contact your organisation's administrator for this information.