Role-based access control

For what this feature does, see Role-based access control in Platform.

If the feature is active and the current administrator has the required permission, Control Center shows the Roles area for the product. This item appears in the Control Center product sidebar only when the role-based access control product feature is active.

View roles

Permissions: manage_rbac

From the product overview in Control Center, select Roles in the left sidebar. In this view, all defined roles for the current product are shown. This always includes the five predefined product-specific roles: Product Admin, Product Observer, Product Operator, Product Operator (Subcontractor), and Product Booking Agent.

The predefined roles cannot be edited or deleted. However, their Requires 2FA setting can still be enabled or disabled from the actions menu.

Create a custom role

Permissions: manage_rbac

To create a role, select Create new and enter the following information.

  • Name. Enter the name of the role.
  • Select one or more of the following permissions for the role.

Product permissions

  • Edit product. This permission allows to edit the product.

Ride permissions

  • Create rides. This permission allows to create rides.
  • Delete rides. This permission allows to delete rides.
  • View rides. This permission allows to view rides.
  • Cancel rides. This permission allows to cancel rides.
  • Edit rides. This permission allows to edit rides.
  • Create bookings. This permission allows to create bookings.

Vehicle planning permissions

  • Manage pauses. This permission allows to manage pauses of task lists in the admin UI.
  • Edit task lists. This permission allows to edit task lists.
  • Create task lists. This permission allows to create task lists.
  • Delete task lists. This permission allows to delete task lists.
  • View task lists. This permission allows to view task lists.
  • Manage tasks. This permission allows to manage tasks states in the admin UI, which is mark them accepted, rejected, canceled or completed.

Vehicle permissions

  • Create vehicles. This permission allows to create vehicles.
  • Create driver vehicle connections. This permission allows to create driver vehicle connections.
  • Archive vehicles. This permission allows to archive vehicles.
  • View vehicles. This permission allows to view vehicles.
  • View driver vehicle connections. This permission allows to view driver vehicle connections.
  • Edit vehicles. This permission allows to edit vehicles.
  • Delete driver vehicle connections. This permission allows to delete driver vehicle connections.
  • Create vehicle positions. This permission allows to store vehicle positions manually.
  • Manage vehicle integrations. This permission allows to manage integrations for vehicles with third-party services.
  • View matching configurations. This permission allows to view matching configurations.

Driver permissions

  • Create drivers. This permission allows to create drivers.
  • Lock drivers. This permission allows locking and unlocking drivers.
  • Manage driver reports. This permission allows to manage driver reports.
  • View drivers. This permission allows to view drivers.
  • View driver emergencies. This permission allows to view driver emergencies.
  • Archive drivers. This permission allows to archive drivers.
  • Edit drivers. This permission allows to edit drivers.
  • Acknowledge driver emergencies. This permission allows to acknowledge driver emergencies.
  • Generate one-time codes for drivers. This permission allows to generate one-time codes for drivers that get sent to them by text message.

Station permissions

  • Create stations. This permission allows to create stations.
  • Archive stations. This permission allows to archive stations.
  • View stations. This permission allows to view stations.
  • Edit stations. This permission allows to edit stations.

Place permissions

  • Create places. This permission allows to create places.
  • Archive places. This permission allows to archive places.
  • View places. This permission allows to view places.
  • Edit places. This permission allows to edit places.

User permissions

  • Read Users. This permission allows to view users.
  • Manage RBAC. This permissions allows assigning RBAC roles.
  • Update Users. This permission allows to update user records.
  • Create Users. This permission allows to create new user records.
  • Lock Users. This permission allows to lock user records.
  • Audit RBAC. This permission allows auditing who is assigned RBAC roles.
  • Delete Users. This permission allows to GDPR delete user records.

Rating permissions

  • Create ratings. This permission allows to create ratings.
  • Edit ratings. This permission allows to edit ratings.
  • Delete ratings. This permission allows to delete ratings.

Service violation permissions

  • View service violations. This permission allows to view service violations and service violation blocks.
  • Waive service violations. This permission allows to acknowledge service violations and service violation blocks.

Passenger type permissions

  • Read passenger types. This permission allows to read passenger types.
  • Create passenger types. This permission allows to create passenger types.
  • Update passenger types. This permission allows to update passenger types.
  • Delete passenger types. This permission allows to delete passenger types.

Passenger option permissions

  • Read passenger options. This permission allows to read passenger options.
  • Create passenger options. This permission allows to create passenger options.
  • Update passenger options. This permission allows to update passenger options.
  • Delete passenger options. This permission allows to delete passenger options.

Ride option permissions

  • Read ride options. This permission allows to read ride options.
  • Create ride options. This permission allows to create ride options.
  • Update ride options. This permission allows to update ride options.
  • Delete ride options. This permission allows to delete ride options.

Payment permissions

  • View service credits. This permission allows to view service credits.
  • Create service credits. This permission allows to create service credits for a users account, free of charge.
  • Delete service credits. This permission allows to delete an unused service credit created by an admin.
  • View payment methods. This permission allows to view payment methods of a user.
  • Read booking transactions. This permission allows to access booking transactions from within the admin panel.
  • Ride tickets. This permission allows to read tickets.
  • Cancel tickets. This permission allows to cancel tickets.
  • Create refunds. This permission allows creating refunds.
  • Handle failed payments. This permission allows to get an overview over failed payments, and handle their state manually.

Permissions for personal discounts, personal discount types, and promo codes are managed on the provider level. They aren’t available for product-specific roles. For the predefined provider roles that include these permissions, see Provider-specific roles.

Text message permissions

  • Read Text Messages. This permission allows to read text messages.
  • Send Text Messages. This permission allows to send text messages.
  • Delete Text Messages. This permission allows to delete text messages.

Communication permissions

  • Read broadcasts. This permission allows reading broadcasts.
  • Create broadcasts. This permission allows creating broadcasts.
  • Send Driver Push Notifications. This permission allows to send push notifications to drivers.
  • View phone calls. This permission allows to view phone calls of that product.
  • Manage announcements. This permission allows to manage announcements.
  • Redeliver notifications. This permission allows to redeliver notifications. It is mostly useful for testing.

Area and zone permissions

  • View areas. This permission allows to view areas.
  • Create areas. This permission allows to create areas.
  • Update areas. This permission allows to update areas.
  • Delete areas. This permission allows to delete areas.
  • Manage zones. This permission allows to manage zones.
  • Manage blacklisted travel combinations. This permission allows to manage blacklisted travel combinations.
  • Manage lines. This permission allows to manage lines and line stops.

Venue permissions

  • Create venues. This permission allows to create venues.
  • View venues. This permission allows to view venues.
  • Edit venues. This permission allows to edit venues.
  • Delete venues. This permission allows to delete venues.

Select Save.

After saving the changes, this role can be assigned to administrators just like the predefined ones. Newly created custom roles have Requires 2FA disabled by default.

Open the detailed view of a role

Permissions: manage_rbac

To open the detailed view of a role, select ⚙️ > Show in the dropdown menu. Alternatively, select its name in the table. This view provides an overview of all associated permissions of the role.

Edit a custom role

Permissions: manage_rbac

To edit a custom role, select ⚙️ > Edit in the dropdown menu. Make the desired changes and then select Save. Predefined product roles cannot be edited.

Delete a custom role

Permissions: manage_rbac

To delete a custom role, select ⚙️ > Delete in the dropdown menu.

Manage the Requires 2FA setting

Permissions: manage_rbac

To change whether a role requires two-factor authentication, select ⚙️ > Enable two-factor-authentication requirement or ⚙️ > Disable two-factor-authentication requirement in the dropdown menu.