The SystemAdmin role and what it can do
This article describes the SystemAdmin role in MobilityManager, the most powerful built-in role. It explains what SystemAdmin can do, why its permissions never fall behind the product, and the guardrails that protect it.
What SystemAdmin is
SystemAdmin is a built-in system role. It automatically holds every permission registered in the platform. This is deliberate: when a new module is added and its permissions are registered, SystemAdmin gains them at once, so the role never drifts out of date as the product grows.
Note: Because SystemAdmin is a system role, its permission set cannot be edited or narrowed, and the role itself cannot be deleted. If you need a more limited administrator, create a custom role instead.
What SystemAdmin can do
In practice, holding every permission means a SystemAdmin can:
- Manage tenants — create, edit, deactivate, and view them.
- Manage all users across every tenant, including creating, editing, activating, and deactivating accounts.
- Manage roles and permissions, including creating custom roles and setting their permissions.
- Run every fleet-operations module end to end: vehicles, bookings, damage management, CRM, Strafmandate (penalty notices), Belege (expense documents), maintenance, warehouse, Tankmanagement (fuel), Versicherung (insurance), and the Fleet Cost Cockpit.
- Use the most sensitive financial actions that are withheld from other roles, such as correcting expense financials and managing fleet cost budgets.
- Install or replace the software licence.
Powers unique to SystemAdmin
Some actions are reserved for SystemAdmin regardless of any other permission a user holds:
- Cross-tenant reach. A SystemAdmin may manage users and roles in every tenant, not just their own.
- Acting on any account. Only a SystemAdmin may edit, deactivate, or reset the password of another SystemAdmin. Non-SystemAdmins are always blocked from touching a SystemAdmin account.
- Granting SystemAdmin. Only an existing SystemAdmin can assign or remove the SystemAdmin role.
Warning: SystemAdmin bypasses the tenant boundaries that limit other administrators. Grant it sparingly and only to trusted operators, and keep at least two SystemAdmin accounts so you never lock yourself out.
When to use it
Reserve SystemAdmin for platform operators who genuinely need control over tenants, licensing, and the most sensitive financial actions. For day-to-day fleet operations, the FleetManager role is the intended operational role, and for people who only manage users within a single tenant, a custom role that grants just users:manage is a safer fit.
Related
- The FleetManager role and its permissions
- Who can assign the SystemAdmin role
- Create a custom role
- The permission catalog and categories