Skip to content

Roles and permissions

WorkOrder V3 uses plant scope, contractor read permission, plant-specific capabilities, and selected role checks. Access is action-specific rather than a single role ladder that applies consistently to every control.

A user must be able to read the work order’s plant before opening its detail. Contractor access can narrow that boundary further. Creation depends on the selected plant’s create permission, while several other actions use their own checks.

Availability in the interface reflects a user’s permissions: authorization is enforced by the platform, not by what the interface shows.

  • Plant scope prevents unrelated plant records from being exposed.
  • Creation permission can differ from one plant to another.
  • Elevated actions protect destructive operations and management analytics.
  • Action-specific guidance matches how access actually works, rather than a single role ladder.
Action or areaAccess modelAdditional boundary
Open work-order detailThe user must be able to read the work order’s plant.Contractor access can narrow the plant read boundary further.
Create workThe selected plant must allow the user to create work.Requester identity is filled from the authenticated user rather than chosen freely.
Assign, resolve, archive, or unarchiveControls are permission-dependent and vary with plant access and assigned capabilities.The record’s lifecycle state can also make an action unavailable.
General edits and some unarchive pathsThese can depend on the plant’s create capability.If an action is rejected, confirm plant access and assigned capabilities with an administrator.
WorkOrder analyticsRequires admin or supervisor access.Users without the elevated role do not use this management view.
Direct deletion and delete-request reviewRequires admin or supervisor access.Users without management-level delete access can request deletion instead.
Attachment deletionRequires admin or supervisor access.The work order must still be in an eligible active state.

Think about access per action:

  1. Can the user read this plant’s work order?
  2. Can the user create or edit work for this plant?
  3. Is the action available for the record’s current lifecycle state?
  4. Does the action require an admin or supervisor role?