Administration
Roles and Permissions
Understand Rivolq's seven standard roles, custom roles and scopes, labor rates, role changes, and service accounts for managing access.
Updated September 15, 2026
Every user has a role, and that role maps to operational capabilities. The standard roles cover most teams; custom and enterprise roles handle the edge cases.
Standard roles
- Admin: full access to billing, security, integrations, users, settings, and all operational data.
- Supervisor / Planner: plans, assigns, and closes work, manages assets and PMs, sees costs, and can approve operational requests.
- Technician: executes work, creates and updates work orders, closes assigned work, views needed asset context, and creates requests. No financial visibility by default.
- Inventory Manager: manages parts, stock, purchasing, receiving, and inventory cost context.
- Viewer: read-only access to operations and reports, including cost context where the organization allows it.
- Requester: submits requests and tracks their own submissions.
- Contractor: external assigned-work access. Contractors update assigned work and view needed asset context, but do not browse inventory or see costs.
Keep users on the narrowest role that lets them do their job.
Custom roles
Open Settings, then Roles, then New role. Each custom role is a set of permissions and a scope. Permissions cover view, create, edit, and delete on each resource type plus specials such as invite users, manage billing, configure integrations, run reports, and access the audit log. Scope controls visible data: all facilities, specific facilities, specific asset classes, or self only. Common examples are a PM-only technician and a single-site facility manager.
Labor rates
Each role can carry a default labor rate used for cost calculations when a user logs hours. Configure it under Settings, then Roles, then Labor rates: standard rate, overtime multiplier, and weekend or holiday rate. Per-user overrides take precedence.
Changing someone's role
Open Settings, then Team, then the user, then Role. The change takes effect on their next page load and the audit log records it. If you are reducing someone's access, reassign what they own first: integrations, scheduled reports, billing, service accounts, or purchasing approvals do not transfer automatically.
Service accounts and tips
For integrations and API access, create a service account under Settings, then Service accounts instead of using a real person's login. See API keys and service accounts. Assign the right role when you invite your team, and map identity provider groups to roles with SSO and SAML.
Still need help?
Reach out for broken behavior, account-specific help, or billing questions.
