Articles in this section

Assign and remove user roles

Published:
Updated:

This article explains how to give a user a role in a tenant and how to take a role away. In MobilityManager, roles are always assigned per tenant, so the same person can hold different roles in different tenants.

How roles work

A user's permissions come from the roles they hold in a given tenant. A role assignment ties together three things: the user, the tenant, and the role name. Because assignments are scoped to a tenant, a FleetManager in one tenant has no fleet-management rights in another tenant unless assigned there too.

Before you start

Assigning and removing roles is permission-gated:

  • Through user administration, role assignment requires users:manage.
  • Through the roles area, assigning a role requires roles:assign and removing one requires roles:remove.
  • The SystemAdmin role holds all of these. A non-SystemAdmin may only assign or remove roles in a tenant where they hold the relevant permission.
Warning: Only a SystemAdmin can assign or remove the SystemAdmin role. Any other user's attempt to grant or revoke SystemAdmin is refused, even if they otherwise manage users in that tenant.

Assign a role

  1. Open the user you want to change.
  2. Choose to assign a role, then select the tenant and the role.
  3. Confirm. The user immediately gains the permissions that role carries in that tenant.

If the user already holds that role in that tenant, the action reports that the role is already assigned and no duplicate is created.

Note: Assigning the Driver role also creates a Fahrer (driver) profile for the user in that tenant, so they can be selected for bookings straight away.

Remove a role

  1. Open the user and view their current roles per tenant.
  2. Choose to remove the role for the relevant tenant.
  3. Confirm. The permissions that role granted in that tenant are withdrawn.

If the role is not currently assigned for that tenant, the action reports that the assignment was not found.

Review a user's roles

Each user's detail view lists every tenant they belong to and the roles they hold there. Use this to confirm an assignment took effect or to audit who has elevated access before removing a role.

Tip: Removing a role does not delete the user. To stop someone signing in entirely while keeping their history, deactivate the account instead.

Related

  • The SystemAdmin role and what it can do
  • The FleetManager role and its permissions
  • The Driver self-service role
  • Who can assign the SystemAdmin role
AH
Written by Alexander Hagemann
Updated:
Access denied
Access denied