Skip to content

User Roles and Permissions

Per-module permissions for technicians, administrator roles and team management

Sattotal has two user roles: Administrator and Technician. The role sets the main boundary — only administrators can open Settings, manage the team and handle billing. On top of that, for each technician you can fine-tune module by module which parts of the app they reach and at what level. It's all managed from Settings → Team.

Administrator

  • Everything a Technician can do, plus the following
  • Access to Settings (organization, taxes, documents, notifications...)
  • Invite, promote/demote and remove team members
  • Manage the organization's plans and billing
  • Set each technician's per-module permissions

Technician

  • Manage customers and devices
  • Register intakes and create repairs
  • Update statuses, upload photos and technical notes
  • Create, send and approve quotes
  • Manage deliveries and sign-off signatures
  • View and reply to customer messages
  • No access to Settings or Plans/billing
  • Their access to each module is decided by the administrator

The role sets the floor; permissions handle the rest

By default a technician gets the whole operational workflow (customers, devices, repairs, quotes, POS…) just like an administrator. You draw the line: with per-module permissions you can leave a section read-only or take it away entirely. Settings and Plans always stay out of reach, blocked on the server.

How to assign roles

From Settings → Team, click "Invite", enter the email and pick the role from a dropdown (Administrator or Technician) — an email invitation is sent. For someone already on the team, you can promote or demote them from the same screen, or remove them entirely.

Per-module permissions

Each of the app's 22 modules (Repairs, Customers, POS, Invoicing, Parts, Warehouses, Stock transfers…) supports three independent levels per technician. Administrators always have full access and don't show up on this screen.

No access

The module disappears from the sidebar. If the technician types the address by hand, they get a "No access" screen instead of the content.

Read only

They can view the section but can't create, edit or delete anything. A notice appears at the top and the server rejects any attempt to save.

Full access

Normal behaviour, no restrictions. It's the default level: until you change anything, every technician has it on every module.

A technician's permissions dialog

Access permissions

Choose which parts of the app Marta can access.

All: no accessAll: read onlyAll: full access

Sales

7 of 9 with access

POS
Invoicing
Items / Parts
Suppliers

Changes can take up to a minute to take effect. Administrators always have full access.

How to assign permissions

1

Open the member's menu

In Settings → Team, click the three dots on the technician's row and pick "Permissions". The option doesn't appear for administrators.

2

Adjust module by module

Modules are grouped just like the sidebar (Workflow, Sales, Management, System). Each row has three buttons: no access, read only and full access.

3

Use the shortcuts for heavy restrictions

The "All: no access" and "All: read only" buttons apply one level to all 22 modules at once; then you only need to open up the ones you do want to grant.

4

Save

The Save button enables as soon as there are changes. The technician sees their updated menu in under a minute, with no need to sign out.

Full access by default

Only the restrictions you apply are stored. A technician whose permissions you've never touched has complete access to everything, and if you set every module back to "Full access" the restriction is deleted outright. Nothing needs configuring for a new member to work normally.

What it protects exactly

Modules set to "No access" vanish from the menu and their pages are blocked, and on "Read only" the server rejects any create, edit or delete. Bear in mind some lists are shared across sections — the customer list is also used when creating a repair, for instance — so hiding a module doesn't always hide that data on the other screens where the technician does work.

Editing a member's details

From that same three-dot menu, "Edit details" lets you complete the technician's profile. It's especially handy when someone accepts the invitation without filling in their name: until then they only show up in the list by their email.

  • First name and surname, which replace the ones from their account in the team list and in technician pickers
  • Internal contact phone number
  • Job title, shown under the name in the team list
  • Profile photo (JPG, PNG, WebP or HEIC, up to 5 MB), cropped and optimised automatically
  • The "Active member" switch: turning it off stops them being offered as an available technician, but doesn't remove them from the organisation or lose their repair history
  • The email can't be changed here: it belongs to each user's personal account
  • Monthly payroll: the total cost to the company (gross salary + employer social security). It's confidential — only administrators see it — and feeds the Sales Dashboard (see that section)

The last administrator is protected

If only one administrator is left in the organisation, the "Remove admin" and "Delete" options appear disabled on their row. With no administrator at all, nobody could get back into Settings, Team or Plans. To demote or delete them, promote another member to administrator first.

Want to try it yourself?

Try Sattotal free with sample data, no credit card required.