What are roles and permissions in ShopView?
A role is a named collection of permission settings that controls what a user can see and do in ShopView. Every user is assigned exactly one role. Roles control access to features and pages — when a user does not have permission for an area, that area's navigation item is hidden entirely. Feature areas are independent of each other: for example, a user can create work orders without having access to the Customers tab.
There are two types of roles:
System roles — 11 pre-built roles that ship with ShopView, representing common shop positions. Most system roles can be edited, but none can be deleted. The Office and Time Clock roles cannot be edited because they are tied to specific license types with a narrow feature set.
Custom roles — Roles you create yourself, starting from a system role template and customizing any setting. Custom roles can be edited and deleted.
What are the 11 system roles?
Admin — Full system access.
Service Manager — Full operational access with limited admin settings.
Senior Service Advisor — Work order and customer management with expanded access.
Service Advisor — Work order and customer management with invoicing access.
Foreman — Oversees technicians and work orders.
Technician — Assigned work orders and time tracking, using the simplified Tech View interface.
Parts Manager — Full parts and inventory control.
Parts Tech — Parts operations and vendor management.
Office — Office administration, reporting, and back-office operations. This role cannot be edited.
Sales Representative — Reports and financial data access only.
Time Clock — Clock in and out only. This role cannot be edited.
View the System Role Permission Matrix
What protections exist for the Admin role?
ShopView has built-in safeguards so administrators cannot accidentally lock themselves out of the system:
Every shop must always have at least one active Admin user.
The Admin role can be edited, but it cannot be changed in a way that removes its access to the Settings/Administration area.
How do I create a custom role?
Go to Administration > Roles and Permissions and click Create Custom Role. The creation flow has four steps:
Choose a starting point — Pick a system role as your template (all settings are pre-filled from it), or start from a blank slate.
Enter role details — Give the role a unique name (required) and a description (optional).
Adjust permissions — Turn individual permission settings on or off in the permission editor.
Save — The role becomes available to assign on the Staff page.
If you customize a role and want to undo your changes, you can reset it back to its template defaults.
How do I edit or delete a role?
Go to Administration > Roles and Permissions. The list shows each role's name, description, type (System or Custom), the template it was created from, and the number of users assigned. Clicking the user count opens the Staff list pre-filtered to that role. Each role has Edit, Delete, and View Permissions actions.
Custom roles can be edited or deleted at any time, as long as no users are assigned.
System roles can be edited (except Office and Time Clock) but never deleted.
A role with users assigned cannot be deleted. You will see a message telling you how many users are assigned. Reassign those users to another role first, then delete.
To review what a role grants without editing it, click View Permissions to open a read-only summary of every setting.
How do I assign a role to a staff member?
Go to Administration > Staff and edit the user. The role dropdown shows System Roles and Custom Roles in separate groups. Click View Permissions next to the selector to verify what the role grants before assigning it.
Important: Changing a user's role — or editing the permissions of a role while its users are logged in — logs those users out immediately. The new permissions take effect when they log back in.
How do View, Create and Edit, and Delete permissions work?
Most functional areas (Work Orders, Schedule, Customer Management, Part Sales, Catalog and Inventory, Vendor and Order Management, Invoicing and Payments, Timesheets) have up to three permission levels:
View — See records in the area. If View is off, the area is hidden from navigation entirely.
Create and Edit — Create new records and modify existing ones. Requires View.
Delete — Permanently remove records. Requires Create and Edit. Delete is the most privileged level and is intentionally limited to trusted roles.
These levels cascade automatically: enabling Delete auto-enables Create and Edit and View; disabling View auto-disables Create and Edit and Delete. Note that Create and Edit is a single combined permission — you cannot grant Create without Edit.
Work Order Lines is a special case: it has no separate View permission. Work order lines are visible whenever Work Orders View is on.
What do the Work Order sub-settings control?
Three additional toggles appear under Work Orders in the role editor. Each only requires Work Orders: View — the user does not need Create and Edit:
Review Work Orders — Shows the Review option on work orders.
Pick Parts — Pick parts from inventory onto a work order line.
Order Parts — Place purchase orders for parts on a work order, receive part deliveries, and see the Parts tab on the work order. Order Parts also requires See Financial Data to be on.
These are independent — for example, a Foreman can have Pick Parts on and Order Parts off.
What does the Parts Department toggle do?
Parts Department is a parent toggle that gates three areas: Part Sales, Catalog and Inventory, and Vendor and Order Management. When Parts Department is off, all three areas are inaccessible and hidden from navigation, regardless of their individual permissions. Turning it back on restores the previous settings. Shops that don't use the parts module can switch off the whole section with this one toggle.
What does See Financial Data control?
See Financial Data is a single toggle that controls visibility of all financial data across the app — every dollar-sign value, including pricing, costs, margins, labor rates, taxes, and financial columns and totals. When it is off, the user can still perform their permitted actions, but no dollar amounts are displayed anywhere in the core app. (It does not apply to the Customer Portal, Billing Portal, or Settings pages.)
Some permissions require See Financial Data to be on:
Invoicing and Payments (all levels)
Part Sales (all levels)
Order Parts (Work Orders sub-setting)
Manage Accounts Payable and Receivable
If you enable one of these while See Financial Data is off, a confirmation prompt asks whether to enable See Financial Data. If you later turn See Financial Data off, you will be prompted to disable any dependent settings that are still on.
What does Manage Accounts Payable and Receivable control?
Manage Accounts Payable and Receivable (Manage AP/AR) controls access to consolidated payment and credit information. It requires See Financial Data to be on. When Manage AP/AR is on, the user can:
See the Unpaid Invoices, Payments, and Credits tabs on Customer and Vendor detail pages, and make bulk payments from Unpaid Invoices.
See sensitive customer fields on the Edit Customer modal and Customer Overview panel: Credit Terms, Credit Limit, Default Labor Rate, Default Shop Supplies, Min and Max, Taxes, and PO is Required.
See sensitive vendor fields (Credit Terms, Credit Limit, Taxes) on the Edit Vendor modal and Vendor Overview card.
Manage AP/AR is independent of See Financial Data: a role can see pricing throughout the app (See Financial Data on) while being blocked from AP/AR tabs and sensitive credit fields (Manage AP/AR off). A user without Manage AP/AR can still create invoices and process payments if they have Invoicing permissions.
What is the difference between Tech View and Full View?
The View Mode setting controls how complex the work order interface looks. It is a display simplification, not a security boundary — data access is controlled by the permission settings, not by View Mode.
Full View shows the complete work order interface with all fields and workflow actions, including the Send to Portal button and actual estimate values.
Tech View is a simplified interface designed for technicians. Compared to Full View, a Tech View user:
Sees Tech Time in the Estimate column instead of the actual estimate value, and has no tech time input field.
Cannot approve work orders or work order lines.
Cannot see or use the Send to Portal button.
Cannot view labor rates, and sees a simplified parts request form.
Can create new work order lines but cannot edit existing ones; a line becomes read-only once approved.
What does the Settings permission control?
The Settings toggle controls access to the Administration area. When it is off, the Administration navigation item is hidden. When it is on, seven independent sub-settings control which sections the user sees:
App Settings — Organization info, branding, locale, plus Roles and Permissions management, Staff and Workplaces, and departments.
Service — Labor types, canned lines, asset types, and Digital Inspections configuration.
Parts — Pricing matrices, categories, and parts configuration.
Integrations — QuickBooks, IBS, and Open API settings.
Finance — Tax configuration, payment settings, and payment methods.
Data Import — Bulk import of customers, vehicles, parts, and other records.
View/Manage Wages — View and manage employee wage rates. This lets you allow someone to manage staff records while restricting their access to wage information.
What do the Reports, Customer Portal, and Billing Portal toggles control?
Reports — Access to the Reports page. This is all-or-nothing: a user with Reports on sees every report, including AR/AP aging reports, regardless of other settings. There is no per-report control.
Customer Portal — Access to manage the customer-facing portal.
Billing Portal — Access to manage the billing portal.
These are simple yes/no toggles that operate independently of other permission settings. When any of them is off, the corresponding navigation item is hidden.
How were the old roles migrated to the new system?
The previous 15 fixed roles were automatically mapped to the 11 new system roles. No action is required from you — the migration happens automatically. Key mappings:
The Owner and Administrator roles were merged into Admin.
The four Service Advisor variations were consolidated into Senior Service Advisor (or Service Advisor for the limited-view variant).
Sales Representative and Reporting users were consolidated into a refined Sales Representative role.
Some roles gained or lost specific capabilities in the process; these changes are intentional. Contact support if a user is missing an ability they need.
System Role Permission Matrix
Each Permission setting has up to three independent levels
View - Allows user to read displayed information/data without the ability to make modifications. If off, the area is hidden entirely.
Edit - Allows user to create or modify existing information/data upon new input from the user. Requires "View" to be on.
Delete - Allows user to permanently or temporarily remove a specific record from the database storage. Requires "Edit" to be on.
" — " means users are unable to View, Edit, or Delete the information/data.
Permission Dependency rules: "Delete" requires "Edit", and "Edit" requires "View". These cascade in both directions.
Enabling a higher level auto-enables the levels below it. For example, enabling Edit auto-enables View. Enabling Delete auto-enables both Edit and View.
Disabling a lower level auto-disables the levels above it. For example, disabling View auto-disables Edit and Delete. Disabling Edit auto-disables Delete.
Core Area | Administrator | Service Manager | Senior Service Advisor | Service Advisor | Foreman | Technician | Parts Manager | Parts Technician | Office User | Sales Representative | Time Clock User |
Work Orders |
|
|
|
|
|
|
|
|
|
|
|
Work Order Lines |
|
|
|
|
|
|
|
|
|
|
— |
Schedule |
|
|
|
|
|
|
|
|
|
— |
|
Customers |
|
|
|
|
|
|
|
|
|
|
— |
Part Sales |
|
|
|
|
|
— |
|
|
|
|
— |
Catalog & Inventory |
|
|
|
|
|
— |
|
|
|
— |
— |
Vendor & Order |
|
|
|
|
|
— |
|
|
|
— |
— |
Invoicing |
|
|
|
|
|
— |
|
|
|
— |
— |
Timesheets |
|
|
|
|
|
— |
— |
|
|
— |
|
Frequently asked questions
Why can't a user see prices or dollar amounts?
Their role has See Financial Data turned off. This hides all pricing, costs, margins, and totals across the app. Edit the role and enable See Financial Data to restore financial visibility.
Why can't a user delete a customer payment?
Deleting payments requires Invoicing and Payments: Delete — not Customer Management: Delete and not Work Orders: Delete. Invoicing Delete also requires Manage Accounts Payable and Receivable to be on.
Can a user order parts without being able to edit work orders?
Yes. The Order Parts sub-setting only requires Work Orders: View plus See Financial Data. The user does not need Work Orders: Create and Edit.
Why can't a user see the Parts pages even though their Part Sales permissions are on?
The Parts Department parent toggle is off for their role. It must be on for Part Sales, Catalog and Inventory, and Vendor and Order Management to be accessible.
Can everyone clock in and out?
Yes. Attendance clock in/out is always available to every user regardless of role or Timesheets permissions, and anyone who can clock in can see My Timesheets. The Timesheets permission controls viewing and editing other staff timesheets from work orders — adjusting timesheet entries requires Timesheets: Create and Edit.
Why doesn't a user appear on the technician schedule?
Appearing on the schedule is not controlled by role. It is controlled by the staff member's department assignment on their staff record — users in a schedule-visible department appear on the dispatch board regardless of role. Similarly, the ability to clock into work order line tasks is controlled by the Time Clock setting on the staff record, not by the role.
Why is the Delete button disabled when I try to delete a role?
The role still has users assigned to it. Reassign every user to a different role, then delete. System roles can never be deleted.
What happens when I change someone's role?
The user is logged out immediately. Their new permissions take effect when they log back in. The same applies if you edit the permissions of a role that users are currently assigned to.
Can I edit the built-in system roles?
Yes, with two exceptions: the Office and Time Clock roles cannot be edited because they are tied to specific license types (clicking them opens a read-only permission summary). The Admin role can be edited, but cannot be changed in a way that removes its access to the Settings area, and every shop must keep at least one active Admin user.
Can I undo my changes to a role?
Yes. A custom role or a modified system role can be reset back to its template defaults.
Can Office users create invoices?
No. Office users can process payments but cannot create invoices. The Create Invoice button is disabled for Office users on Work Orders and Part Sales, regardless of the role's Invoicing permissions.
Can a user reverse an invoice?
Reversing an invoice on a work order requires Work Orders: Delete. Reversing a part sale invoice requires Part Sales: Delete. Reversal is only possible when validation criteria are met (for example, no payments have been made).
Can a user be assigned more than one role?
No. Each user has exactly one role at a time.
