Keep roles, access levels and privileges current as your team changes

Keep every SignBas3 login aligned with the person's current job by reviewing roles, status, access level and privileges from Staff and access.

Best forOwner / Admin
Before you beginUse a representative record and confirm you have the permissions required for this area.

Step by step

  1. Open Settings, then Users, and read the app login and invitation counts beside the Staff and access heading.
  2. Scan the App access column in the Staff directory for each person's user type badge, role and status, narrowing with Search staff, Job group and Employment.
  3. Review the App access without a staff profile list below the directory and match any unlinked login to a staff record with Edit staff or Add staff.
  4. Open Staff actions on a row and choose Edit app access to open the Edit user access dialog.
  5. Set the Primary role, Status and App access level to match the person's current job.
  6. Under Privileges, set a feature's Special Permission to No Access, View Only Access or Full Access only where the role default is wrong, or select Use role defaults.
  7. Select Save Access and confirm the User updated message and the refreshed App access column.
  8. For anyone who has left, set Status to Inactive or Blocked, select Save Access and confirm the row shows the new status.

Good practice

Give every person a named login and review Staff and access whenever someone joins, changes role or leaves. Keep the role as the main control and reserve special permissions for genuine exceptions; the Privileges table shows role, special and effective permission side by side, so you can see where a login departs from its role.

When you are finishedEach login carries the right Primary role, Status, App access level and Privileges, and departed staff can no longer sign in.

Before you begin

  • You are signed in as an Owner or Admin.
  • Every team member already has a login from an accepted invitation.
  • You know who has changed role, joined a new department or left the business since the last review.

Complete workflow

How the workflow moves

  1. 01
    Review

    Read the App access column and the App access without a staff profile list to see who holds what.

  2. 02
    Adjust

    Use Edit app access to change Primary role, Status, App access level and Privileges, then Save Access.

  3. 03
    Confirm

    Check the updated row, then ask the person to confirm what they see on Your account.

Setup dependency

Settings that change this workflow

The same task can behave differently between organisations. Check these settings before treating a different result as an error.

Primary role/settings

Only Admin and Owner logins can open the Settings area; every other role works from the operational pages its permissions allow.

Open in SignBas3 →
Primary role/settings/billing

Subscription & Billing opens only for the Owner role.

Open in SignBas3 →
App access level/jobs

A Field / factory user is capped to job viewing, job photos, task completion, timesheets, file viewing, notifications and support regardless of role.

Open in SignBas3 →
Status/settings/users

Inactive and Blocked logins cannot sign in, and the App access column shows the status beside the person's role.

Open in SignBas3 →

What this controls

Staff and access is where an Owner or Admin decides what each person can do in SignBas3. Every login carries a Primary role that supplies default permissions, a Status that decides whether the person can sign in, an App access level that separates Office users from Field / factory users, and Privileges that can replace the role defaults feature by feature.

These settings decide who can open Settings, who can edit quotes, jobs, purchase orders and invoices, who only views them, and who is limited to field and factory work.

Before you start

Only Owners and Admins can manage users. Set password appears only for Owners, and an Admin can send a password reset to any login except an Owner.

Primary role offers Staff, Admin, Manager, Installer, ReadOnly, Accountant, Sales, Estimator, Viewer and Owner. Status offers Active, Pending, Inactive and Blocked. App access level offers Office user and Field / factory user. Privileges are grouped into General privileges, Financial privileges, SignBas3 features and Administration & API access, one row per feature.

Walkthrough

Step 1: Read the counts

Open Settings, then Users. Beside the Staff and access heading the page states the app login count and any invitations waiting.

Step 2: Read the App access column

In the App access column, a linked login shows an Office user or Field / factory user badge with the role and status beneath it, for example Staff · Active; No app login means nothing is linked and Invitation pending means the person has not yet accepted. Search staff, Job group, Employment and Clear filters narrow the Directory view.

Step 3: Resolve logins without a staff profile

App access without a staff profile lists logins not matched to an active staff record by staff ID or email, each with Edit App Access, Set Password and Send Reset buttons. Give each a staff record whose Email matches the login, or set its Status to Inactive if nobody needs it.

Step 4: Open Edit user access

From Staff actions choose Edit app access. The Edit user access dialog names the login's email address and notes that changes apply only after Save Access; Display name is optional. For a pending invitation the dialog is titled Edit invitation access, the status field reads Status after acceptance, and saving confirms with Invitation access updated.

Step 5: Set role, status and access level

Primary role sets the default permissions, and choosing a new role clears any special permissions so the defaults apply cleanly. Status controls sign-in: Active lets the person in, while Inactive and Blocked stop it. App access level switches between Office user and Field / factory user; as the dialog notes, staff records no longer control login access.

Step 6: Adjust Privileges

The Privileges table lists each feature with Role Permission, Special Permission and Effective Permission columns, each reading Full Access, View Only Access or No Access. Choose a value under Special Permission to depart from the role, or expand Individual actions to tick single actions; the first change replaces the role's set with a special set until you select Use role defaults. For a Field / factory user, features outside the cap are marked Unavailable for field / factory users, and an inactive login shows no effective access.

Step 7: Save and confirm

Select Save Access. The page confirms with User updated and refreshes the App access column.

Step 8: Handle departures

Open Edit app access, set Status to Inactive or Blocked and select Save Access; any open session is signed out. Use Archive staff from Staff actions if the staff record should also leave the directory: they move to the Inactive view, keep timesheets, job history and labour rates, and Restore active brings them back.

What changes elsewhere

  • Settings at /settings opens only for Admin and Owner logins, and Subscription & Billing at /settings/billing opens only for an Owner.
  • Quotes, Jobs, Purchasing and Invoices at /quotes, /jobs, /purchasing and /invoices follow the login's effective permissions.
  • A Field / factory user works from jobs and timesheets at /jobs and /timesheets and sees Restricted access on Your account.
  • An Inactive or Blocked login is refused at sign-in with Email, password, or organisation access is not valid, and any session still open is signed out.
  • Your account at /user/settings shows each person their own Role and Access.

Common problems

SymptomCauseFix
Staff actions offers Invite app user instead of Edit app access.No login or pending invitation is linked to that staff record by staff ID or email.Check App access without a staff profile and align the staff Email, or invite the person.
A feature is marked Unavailable for field / factory users.The App access level is Field / factory user.Change App access level to Office user if the person genuinely needs that feature.
Special permissions disappeared after changing the role.Choosing a new Primary role returns Privileges to that role's defaults.Reapply the exception after the role change, then Save Access.
Save Access is disabled.Access data is still loading or your access could not be confirmed.Wait for the directory to load, or select Retry and reopen the dialog.
Set password is missing from Staff actions.Only Owners can set a password directly.Use Send password reset, which emails the person a secure link.

Check your work

  1. Every active staff member's App access column shows the expected user type, role and Active.
  2. App access without a staff profile is empty or contains only logins you have deliberately left unlinked.
  3. Each departed person's login shows Inactive or Blocked.
  4. Anyone whose role changed confirms Your account shows the new Role and Access.

Next: resolve invite and access problems →

See how staff profiles connect to scheduling and timesheets →

If your workspace behaves differently, record the relevant job, client or record number and raise a support ticket so the team can investigate the exact context.