Articles in this section

The three system roles at a glance

Published:
Updated:

This article introduces the three built-in roles in MobilityManager, what each can do, and how custom roles extend the model. Understanding roles helps you know why you can see some features and not others.

How access works

Every action in the platform is protected by a permission. A role is simply a named bundle of permissions, and roles are assigned to you per tenant. When you open a page or select a button, the system checks whether your role includes the required permission. If it does not, the feature is hidden or refused. This is why your menu can differ from a colleague's.

The three built-in roles

RoleWho it is forWhat it can do
SystemAdmin Platform owner / IT Full access. Automatically holds every permission in the system, including managing tenants, users, roles, licence, and settings, and the most sensitive actions such as financial corrections and budget management.
FleetManager Fleet or mobility coordinator Runs fleet operations end to end: create and manage vehicles, approve and reject bookings, work with damage cases, CRM, Strafmandate (penalty notices), Belege (receipts/expense documents), driving-licence compliance, and the operations modules.
Driver Employees who use vehicles Self-service only: create bookings, view their own bookings, view the vehicles they can book, and view and upload their own driving licence for the Führerscheinkontrolle (licence check).

What SystemAdmin can do that FleetManager cannot

FleetManager is deliberately broad but not unlimited. A few high-sensitivity capabilities are reserved for SystemAdmin, including financial corrections on Belege, fleet-cost budget management, and administration of roles and tenants. This keeps financially and structurally sensitive actions with the platform owner.

What the Driver role deliberately excludes

The Driver role does not include access to the Expenses (Belege) area. Belege is a finance and administration function, so it stays with managers and administrators rather than every driver.

Note: SystemAdmin always receives newly added permissions automatically. When a new module is introduced, administrators keep full access to it without any manual change, while other roles are granted access deliberately.

Custom roles

The three roles above are a starting point. A SystemAdmin can create custom roles from Administration → Roles & Permissions and give each one a tailored set of permissions — useful when a job needs more than a Driver but less than a full FleetManager. Note that:

  • The three built-in roles are system roles: their permission sets are fixed and cannot be edited or deleted.
  • Custom roles can be created, edited, given specific permissions, and removed.
  • Only a SystemAdmin can assign or remove the SystemAdmin role.
Tip: Assigning the Driver role to a user automatically creates a driver profile for them in that tenant, so they are ready to book straight away.

Related

  • Understanding companies and tenants
  • What MobilityManager is and who it is for
  • A tour of the main navigation and sidebar
  • Where to get help in MobilityManager
AH
Written by Alexander Hagemann
Updated:
Access denied
Access denied