Roles and Permissions
Each company team member can be given a precise set of permissions for each VCR the company operates. The company owner scopes them — for example, full access in one control room but billing-only in another.
You manage this on the person, not on a company screen: open them under People, go to Roles & access, and pick the room.
Only the company owner (or a super admin) can change a company member's CleverOps roles — the only people this lane describes are owners and admins, so setting one is reaching across your own tier. Owners always have full access to every VCR and can't be scoped. Access is only ever what has been granted: a member with nothing ticked in a workspace can open it but sees the Dashboard alone.
Setting a member's permissions
- Open People and click the person.
- Go to the Roles & access tab.
- Pick the control room you want to change — the list shows every room the company operates, and whether they hold a seat in it.
- Tick or untick the roles that person should have in that room. Changes save immediately.
Repeat per room. Somebody who needs different access across control rooms is handled by picking each room in turn.
Access is roles, only — grouped chips, each bringing everything that job needs, apps included. There is no per-capability editor: when a role grants too much, the catalog splits it into a finer role instead (Asset manager beside Asset inspector is the pattern). What does each role grant? at the bottom of the editor folds open the exact capability list behind every chip.
Four chips are add-ons to a base role rather than jobs of their own: Account closures (beside Sites admin), Radio removals (beside Radio swaps), and Billing runs and Credits and voids (beside Billing / accounts). They exist so a control room can decide that only some of its site admins may cancel a site, only some of its billing staff may press Issue or credit an invoice, and only some of its radio people may delete a panel for good. Company owners and admin seats hold all four without a chip.
The capabilities
These are the CleverOps capabilities a member can hold in each VCR. You do not tick them directly — a role brings its whole bundle — but What does each role grant? at the bottom of the editor folds open exactly this list per chip:
| Capability | What it allows |
|---|---|
| Customers & sites | Create and edit customers, contacts, memos and status schedules. Creating, editing and cancelling sites are the three capabilities below — the Sites admin role carries the first two. |
| Create sites | Add a site and Add personal cover, start onboarding for a customer, and Approve a site connection request. Granted by the Sites admin role; owners, admins and Administrators have it. |
| Edit sites | Change a site's name, type, address, pin, photo and setup fields on Site details. Granted by the Sites admin role (and, for the CleverTech app, by Technician and Technical coordinator); owners, admins and Administrators have it. Per-room settings — monitoring policy, notes, area, schedules — follow the control-room rules they always did. |
| Cancel & reinstate sites | Cancel a site, reinstate it or undo a cancellation, Disconnect it from the control room, and Decline a connection request. Granted by the Account closures role. Owners and admins always have this without any role. |
| Replace & remove site radios | On Site details: swap a site's alarm communicator (radio swap), Replace entire system, Remove from site, or Archive config. Granted by the Radio swaps role. Owners and admins always have this without any role. |
| Claim, add & release hubs | Claim hub, Add hub on a site, Re-register hub, Add billing, and Release hub on the Hubs page. Granted by the Radio swaps and Technical coordinator roles; owners and admins have it. |
| Remove hubs & panels permanently | Remove permanently on a panel, Delete hub + billing, and Remove billing. Granted by the Radio removals role. Owners and admins always have this without any role. |
| Sales & leads | Work leads, own the funnel, and create, send and revise sales quotes, including Start subscriptions on a won one. Technical quotes are read-only, and Convert to job and Bill directly stay with Service operations (see Quotes → Permissions). Customers are read-only: a sales person can open them, start a New quote and log a memo or call, but editing a customer is Customers & sites. |
| Approve quotes for sending | Clear a draft quote to be sent to the customer. Only relevant when the VCR has Require quote approval switched on. Granted by the Technical coordinator role; owners and Administrators hold it already. Access is roles only, so it cannot be granted on its own. |
| Service operations | Service jobs, quotes, catalog, technicians, scheduling and maintenance. |
| Billing & invoices | Plans, subscriptions, invoices, payments, arrangements, reminders and statements. This is billing your own customers. Running batches, reducing what a customer owes, and the front desk are the three capabilities below. |
| Run invoice batches | Simulate, Create draft batch, Issue, Discard, Rebuild and Exclude on Billing → Runs, and Create draft invoices from dispatch charges. Granted by the Billing runs role; owners and admins have it. Billing managers without it still see the batches. |
| Credit notes, voids & adjustments | Issue credit note, Apply credit, Void, Unmark paid, Delete last payment, Adjust balance, Transfer credit and the opening-balance import. Granted by the Credits and voids role; owners and admins have it. |
| Take payments & cash up | The front desk: record customer payments, see the payments you took, close your own drawer at the end of the day on Billing → Payments — Billing opens as that one tab — and run the Till. Granted by the Cashier role. Billing & invoices includes all of it, for every drawer. |
| CleverCam charges | See what your company pays CleverCam — device counts and negotiated unit pricing, on the CleverCam subscription tab. Granted by the Manager role; owners always have it. Not the same as Billing & invoices above. |
| Fleet & vehicles | Vehicles, vehicle checks, fuel & trips, firearms, vehicle asset tags and trackers. Not the asset register — that has its own pair below. |
| Manage assets | Run the asset register — categories, checklists, registering, moving and retiring assets. Includes everything Inspect assets allows. |
| Inspect assets | Read the asset register and run inspections — scan a tag, walk the checklist, submit. No register changes. |
| Manage stock & warehouse | Run the stock module — raise, send, receive and capture: handovers to and from technicians, stocktakes, bins and the movement ledger. Granted by the Stock controller role. |
| Approve purchase orders | Sign an open level on the approval ladder — purchase orders, supplier bills, payment runs and supplier changes — and send documents back. Granted by the Manager and Technical coordinator roles. |
| Pay suppliers | Build, export and mark paid the supplier payment runs and their bank batches. Granted by the Billing / accounts and Manager roles. |
| Manage the roster | Run the guarding roster — shift patterns, posts, demand, the day-of board and offers. Granted by the Control room manager role. |
| Response & operators | Response units, responders, operator roster and scheduled alarms. |
| Operator roles | Assign control-room roles and edit custom role permission sets. |
| Review queue | Action Review Queue items — resolve, snooze, and burglary casework. |
| Reports | View and export reports. |
| VCR settings | Control-room settings, SLA, routing, dispatch limits and alarm handling. |
| Audit trail | View the audit trail of changes. |
This page is about company team members — the people who sign in to CleverOps. Control-room (CleverCommand) actions — working events, snoozing cameras, the AI Caller, and so on — are not set here; those belong to control-room operators, who sign in with a login code and get a role per VCR on the Control Room → Operator management page instead.
How it's enforced
A company member's effective permissions for a VCR come from the database resolver fn_my_company_permissions (owners and super admins resolve to everything). The per-VCR sets are stored server-side behind an owner-gated function, so the permissions you set here are the source of truth.
In CleverOps, a scoped member's permissions decide which areas of the app they can use:
- Sidebar — navigation items for areas the member can't use are hidden.
- Direct links — opening a gated area by URL shows a "You don't have access to this area" notice instead of the page.
- In-page controls — inside an area, buttons and editors the member isn't allowed to use stay hidden or disabled as before.
Which capability unlocks which area:
| Area | Unlocked by any of |
|---|---|
| Dashboard | Always available to every workspace member. The cards on it follow this same table — each one shows only if you can open the area it summarises (see Dashboard Overview). |
| Control Room | VCR settings, Response & operators* |
| Response | Response & operators, Fleet & vehicles, VCR settings |
| Suburbs | VCR settings, Response & operators |
| Sites | VCR settings, Customers & sites, Service operations |
| Hubs | VCR settings, Service operations |
| Sales (Leads, Quotes, Onboarding) | Sales & leads (also unlocks Quotes on its own — Service operations unlocks Quotes too, but not Leads or Onboarding)† |
| Customers | Customers & sites, Sales & leads |
| Tickets | Customers & sites, Service operations |
| Service Ops | Service operations |
| Team | Response & operators, Service operations |
| Billing | Billing & invoices; Take payments & cash up (the Payments tab only) |
| Settings → CleverCam subscription | CleverCam charges |
| Review Queue | VCR settings, Review queue |
| Performance & Reports | Reports, VCR settings |
| Communities | VCR settings |
| Settings | VCR settings |
* Control-room operators (who sign in with a login code) see the Control Room and Sites areas through their operator role, independently of these company-member capabilities. That operator role only counts on an operator seat — one with CleverCommand access, or a reaction unit. A person who holds a field role alone (Sales, Technician) has no operator seat, so Sales unlocks the Sales and Customers areas and nothing else: no Control Room, no Sites.
† Leads, Quotes, and Onboarding (see Onboarding) share one sidebar entry, Sales, with a switcher between them. Underneath, each still checks its own permission when opened directly: the Leads board and the Onboarding board need Sales & leads; the Quotes screen and the shared Sales overview open for Sales & leads or Service operations — a service-only member can reach Quotes and the overview but gets a "you don't have access" notice on Leads or Onboarding specifically.
Members you have never scoped, and owners, hold every capability and see the whole app — nothing changes until you deliberately restrict someone.
Someone whose only place in a control room is as a reaction unit — a responder who signs in to CleverResponder — cannot open Billing, even when their role grants Billing & invoices.
Every billing action is refused for them in the database, so granting the capability would only produce an error when they clicked Accept, Reject or Save. The area is hidden instead. This does not apply if the same person is also a company team member, or holds staff permissions as a technician in that control room — then their capabilities work normally.