User Roles and Permissions
Per-module permissions for technicians, administrator roles and team management
Sattotal has two user roles: Administrator and Technician. The role sets the main boundary — only administrators can open Settings, manage the team and handle billing. On top of that, for each technician you can fine-tune module by module which parts of the app they reach and at what level. It's all managed from Settings → Team.
Administrator
- Everything a Technician can do, plus the following
- Access to Settings (organisation, taxes, documents, notifications...)
- Invite, promote/demote and remove team members
- Manage the organisation's plans and billing
- Set each technician's per-module permissions
Technician
- Manage customers and devices
- Register intakes and create repairs
- Update statuses, upload photos and technical notes
- Create, send and approve quotes
- Manage deliveries and sign-off signatures
- View and reply to customer messages
- No access to Settings or Plans/billing
- Their access to each module is decided by the administrator
The role sets the floor; permissions handle the rest
By default a technician gets the whole operational workflow (customers, devices, repairs, quotes, POS…) just like an administrator. You draw the line: with per-module permissions you can leave a section read-only or take it away entirely. Settings and Plans always stay out of reach, blocked on the server.
How to assign roles
From Settings → Team, click «Invite», type the email and choose the role from a dropdown (Administrator or Technician) — an invitation is sent by email. For someone already on the team, you can promote or demote them from the same screen, or remove them entirely.
Per-module permissions
Each of the app's 22 modules (Repairs, Customers, POS, Invoicing, Parts, Warehouses…) supports three independent levels per technician. Administrators always have full access and don't show up on this screen.
No access
The module disappears from the sidebar. If the technician types the address by hand, they get a «No access» screen instead of the content.
Read only
They can view the section but can't create, edit or delete anything. A notice appears at the top and the server rejects any attempt to save.
Full access
Normal behaviour, no restrictions. It's the default level: until you change anything, every technician has it on every module.
A technician's permissions dialogue
Access permissions
Choose which parts of the app Marta can access.
Sales
7 of 9 with access
Changes can take up to a minute to take effect. Administrators always have full access.
How to assign permissions
Open the member's menu
In Settings → Team, click the three dots on the technician's row and pick «Permissions». The option doesn't appear for administrators.
Adjust module by module
Modules are grouped just like the sidebar (Workflow, Sales, Management, System). Each row has three buttons: no access, read only and full access.
Use the shortcuts for heavy restrictions
The «All: no access» and «All: read only» buttons apply one level to all 22 modules at once; then you only need to open up the ones you do want to grant.
Save
The Save button becomes enabled as soon as there are changes. The technician sees their updated menu in under a minute, with no need to sign out.
Full access by default
Only the restrictions you apply are stored. A technician whose permissions you've never touched has complete access to everything, and if you set every module back to «Full access» the restriction is deleted outright. Nothing needs configuring for a new member to work normally.
What it protects exactly
Modules set to «No access» vanish from the menu and their pages are blocked, and on «Read only» the server rejects any create, edit or delete. Bear in mind some lists are shared across sections — the customer list is also used when creating a repair, for instance — so hiding a module doesn't always hide that data on the other screens where the technician does work.
Editing a member's details
From that same three-dot menu, «Edit details» lets you complete the technician's profile. It's especially handy when someone accepts the invitation without filling in their name: until then they only show up in the list by their email.
- First name and surname, which replace the ones from their account in the team list and in technician pickers
- Internal contact phone number
- Job title, shown under the name in the team list
- Profile photo (JPG, PNG, WebP or HEIC, up to 5 MB), cropped and optimised automatically
- The «Active member» switch: turning it off stops them being offered as an available technician, but doesn't remove them from the organisation or lose their repair history
- The email can't be changed here: it belongs to each user's personal account
- Monthly payroll: the total cost to the company (gross salary + employer social security). It's confidential — only administrators see it — and feeds the Sales Dashboard (see that section)
The last administrator is protected
If only one administrator is left in the organisation, the «Remove admin» and «Remove» options appear disabled on their row. With no administrator at all, nobody could get back into Settings, Team or Plans. To demote or remove them, promote another member to administrator first.
