Appearance
Roles and Permissions
Continual uses role-based access control (RBAC) to manage what users can do within the platform. Each user is assigned a single role that determines their level of access.
Role Hierarchy
From most to least privileged:
- Owner
- Admin
- Manager
- Team Leader
- Operator
Function and scope
Function is a routing label—Production, Maintenance, Quality, or Engineering. It helps route checks and actions but grants no additional authority.
Scope determines which part of the plant a member can access. Admins can assign whole-organisation access or factory/line grants; manager-delegated scope assignment is planned separately. A line grant permits reading its containing factory and writing the named line, while a factory grant covers every line in that factory. Mobile's default operational surfaces show only assigned factories and lines; readable neighbouring-line information is not blended into those defaults.
Role Capabilities
Owner
Owners have full access to everything in the organisation:
- All admin capabilities
- Manage other owners (promote, demote, remove)
- Delete the organisation
- Transfer ownership
Admin
Admins can manage most aspects of the organisation:
- Configuration: Create, update, and delete factories, Lines, Groups, machines, and format definitions
- Operations: Create, update, and delete checks; change line formats; submit check results and line outputs; reorder checks
- Team: Invite users, manage member roles (except owners), remove members (except owners)
- Tenant: Update organisation settings
Admins cannot:
- Manage owners (promote users to owner, demote owners, or remove owners)
Manager
Managers can handle day-to-day operational tasks but cannot modify system configuration or manage team members:
Can do:
- Create, update, and delete checks
- Reorder checks on machines
- Approve or reject proposed check changes
- Accept eligible target proposals temporarily and record the final keep/revert verdict
- Change the active line format for production lines
- Edit line format change history timestamps
- Create, edit, and resolve manual actions
- Submit check results
- Submit line output data
- Complete or skip check instances
- View all data (dashboards, insights, check instances, stats, user lists)
Cannot do:
- Create, update, or delete factories, machines, Lines, Groups, or format definitions
- Invite users or manage team memberships
- Update organisation settings
Team Leader
Team leaders work in the mobile app or on a kiosk tablet. They do not have portal access at the moment. They can carry out approved shift-execution work but cannot manage configuration, memberships, or organisation settings.
Can do within assigned scope:
- Create, edit, resolve, and verify actions; route actions to a function
- Review eligible check proposals and approve temporary target changes
- Complete checks and see compliance for their assigned locations
Operator
Operators execute checks from the mobile app. Operator accounts cannot use the portal — signing in there redirects to a page directing them to the mobile app.
Can do:
- Complete check instances (mark as passed)
- Fail check instances (mark as failed/defective)
- Skip check instances
- Submit photo evidence for checks
- Propose changes to checks (reviewed by a Manager, Admin, or Owner)
- Change the active line format
- View operational data in the mobile app
Cannot do:
- Access the portal (mobile app only)
- Create, update, or delete any configuration (factories, Lines, Groups, machines, formats, checks)
- Approve or reject proposed check changes
- Create, edit, or resolve manual actions (Team Leaders and above only)
- Submit line output data
- Manage team members or organisation settings
Read Access
Authenticated users can read data within their readable factory scope:
- View dashboards and insights
- See check instances and their completion status
- View check statistics
- See the list of users and their roles
- Access historical data
Line grants make the containing factory readable, including neighbouring lines. Default Mobile Home, Actions, Checks, and supervisory review surfaces are intentionally narrower: they show assigned locations only. (Operators read this data in the mobile app; they cannot sign in to the portal.)
When a member needs to inspect another readable line, View another line on Mobile Home opens a separate Factory lookup flow. It is read-only and does not change the normal work context; no factory grant is crossed, and no action, check, or configuration control is available there.
Kiosk-Only Users
Users created for shared kiosk devices (those without an email address) can hold the Operator, Team Leader, or Manager role. Managers deliberately remain supported on kiosks. They cannot be promoted to Admin or Owner — those roles require an email address for portal login. See Kiosk Mode for setup.
Which kiosk devices a person can use follows directly from their access scope — the same scope that governs everything else they can read or write. A tenant-wide kiosk user appears on and can sign in to every device; a factory- or line-scoped user appears only on devices within that part of the organisation. There is no separate device setting to configure, and no way for a kiosk user to widen their own device access.
Best Practices
Role Assignment
- Owners: Limit to 1-2 trusted organisation leaders
- Admins: System administrators and technical leads who manage infrastructure
- Managers: Production supervisors, shift leads, and team managers who oversee daily operations
- Team Leaders: Shift-execution leaders who work from the mobile app or kiosk tablet
- Operators: Floor workers, technicians, and line operators who execute checks
Security Considerations
- Use the principle of least privilege — assign the lowest role that allows users to do their job
- Regularly review role assignments, especially for owners and admins
- When someone's responsibilities change, update their role promptly
- Avoid creating too many owners or admins to minimize security risk
API Enforcement
All role-based permissions are enforced at the API level using JWT-based authentication. The API validates the user's role on every request and returns a 403 Forbidden error if the user lacks permission for the requested operation.
Frontend applications (web portal and mobile app) also implement role-based UI gating to hide actions that would be rejected by the API, providing a better user experience.
Permission Matrix
| Action | Owner | Admin | Manager | Team Leader | Operator |
|---|---|---|---|---|---|
| Configuration | |||||
| Manage factories, Lines, Groups, and machines | ✓ | ✓ | ✗ | ✗ | ✗ |
| Manage format definitions | ✓ | ✓ | ✗ | ✗ | ✗ |
| Shut down/reactivate Lines and Groups | ✓ | ✓ | ✗ | ✗ | ✗ |
| Operations | |||||
| Create/edit/delete checks | ✓ | ✓ | ✓ | ✗ | ✗ |
| Reorder checks | ✓ | ✓ | ✓ | ✗ | ✗ |
| Propose check changes | ✓ | ✓ | ✓ | ✓ | ✓ |
| Approve/reject proposed changes | ✓ | ✓ | ✓ | ✓ | ✗ |
| Accept temporary target trials and record verdicts | ✓ | ✓ | ✓ | ✓ | ✗ |
| Change the active line format | ✓ | ✓ | ✓ | ✓ | ✓ |
| Edit format history | ✓ | ✓ | ✓ | ✓ | ✗ |
| Submit line outputs | ✓ | ✓ | ✓ | ✓ | ✗ |
| Complete/skip check instances (submit results) | ✓ | ✓ | ✓ | ✓ | ✓ |
| Create/edit/resolve manual actions | ✓ | ✓ | ✓ | ✓ | ✗ |
| Team Management | |||||
| Invite users | ✓ | ✓ | ✗ | ✗ | ✗ |
| Manage member roles | ✓ | ✓* | ✗ | ✗ | ✗ |
| Remove members | ✓ | ✓* | ✗ | ✗ | ✗ |
| Manage owners | ✓ | ✗ | ✗ | ✗ | ✗ |
| Organization | |||||
| Update tenant settings | ✓ | ✓ | ✗ | ✗ | ✗ |
| Delete organisation | ✓ | ✗ | ✗ | ✗ | ✗ |
| Data Access | |||||
| View all data | ✓ | ✓ | ✓ | ✓ | ✓ |
* Admins cannot manage owners