User instructions
Set user permissions
Browser update 1.30.1: use the grouped sidebar for workspaces and Account for personal/tools actions. Home no longer repeats the workspace-card grid. Named project administrators can manage users and departments under Administration. Desktop Admin remains available.
Give each account the access it needs
- Open Users & access → select user → Permissions… as an administrator.
- Start from Role defaults, View only or All operational access, then review each tick box. Viewing an area is required before its action permissions can be enabled.
- Enter a reason and Save permissions. The user signs in again with the new access; saved work is not erased.
| Area | Available controls |
|---|---|
| Checklists | View, create records, record checks, approve assigned items, manage eligible live items, finalise and export. |
| Logs | View, add, correct own or all entries, void, export and view released references. |
| Inventory | View, edit items and asset profiles/pictures, move stock, run verifications and export/print QR labels. |
| Tasks | View and perform scoped tasks, manage/review eligible assignments and export scoped reports. |
| Maintenance | View, record assigned work, manage orders, approve assigned steps and export. |
| Toolbox Talks | View, conduct owned talks, personally acknowledge and export. |
| Certificates | View including source files, create/update records and export register reports. |
| Calendar | View dates and links, still subject to each source permission. |
| Original documents / backups | View/download originals; download the full project backup subject to private-task safeguards. |
Existing explicit restrictions do not gain new capabilities automatically. Source files already downloaded cannot be recalled by changing permissions. Project, user, department, template and library management remain administrator-only.
For a person who must see only selected vessels, use Fleet & manifests → User vessel access and explicitly choose Vessel-only access. General project permissions and department membership are not vessel boundaries. Read Set vessel-only access before changing an account.
Vessel-specific Logs are available through /fleet → Logbooks only after an administrator links the book and grants the account separate site log permissions. Existing project-wide accounts retain their broader access. Read Use vessel-specific logbooks and Set vessel log permissions before commissioning restricted accounts.
For a read-only overview, use Users & access → Review effective access. Read the scope and export guidance
Document-specific invitations
The Document invitations permission group separates Join and sign a specifically invited document, Issue document-specific QR invitations and Allow temporary external document visitors. Administrators retain full access. Ordinary role defaults allow joining but not issuing or external sharing; previously saved explicit permission sets do not gain new flags automatically. Review the relevant named accounts once, rather than promoting a demo guest to Administrator.
Issuing also requires that the person is the document’s actual author and has normal Handovers create or Toolbox conduct access. Named participation also requires the module’s acknowledgement permission. External visitors must be deliberately enabled for that invitation by an authorised creator. A visitor has no project membership, directory/search access, normal API token or ability to browse other records. The server checks this scope on every read and file download. Hiding navigation is not the permission boundary.
Revoking the organiser’s sharing authority, disabling an account or changing credentials ends the affected unfinished visits. A changed document, timeout, explicit finish or organiser closure also ends access. Shared demo and vessel-only identities do not use named project invitations. An independent publicly enabled demonstration remains separately reachable through its normal public URL; a document invitation cannot make that public demonstration private.
QR signatures are participation evidence, not proof of identity, physical presence or authority to operate equipment. This release supports toolbox talks and handover acknowledgement only. Maintenance witness/approval adapters, individual invitations and optional organiser admission are separate future work. No automatic role, permission, account or project changes are made.