Back to Knowledge Base

Access Control & Roles

Updated September 24, 2026

Access Control & Roles

Control who can see and do what in your Attlock dashboard with role-based access control (RBAC). Assign system roles or create custom roles with granular permissions.

Accessing Access Control

Attlock dashboard showing the main operations workspace and navigation.
Dashboard: use the left navigation to open the required workflow.

Navigate to Team → Access Control in the sidebar, or press G and search "Roles".

System Roles

Attlock includes built-in roles that cannot be deleted:

RoleAccess Level--------------------Super AdminFull access to everything across all companiesCompany AdminFull access within their companySupervisorManage guards and operations at assigned sitesGuardMobile app access for field operationsClientClient portal access for their assigned sites

Creating Custom Roles

  1. Go to Access Control → Roles.
  2. Click Create Role.
  3. Enter a Role Name (e.g., "Operations Manager").
  4. Select Permissions from the permission matrix:
    • Guards: View, Create, Edit, Delete, Deactivate
    • Sites: View, Create, Edit, Delete
    • Shifts: View, Create, Edit, Delete, Publish
    • Incidents: View, Create, Edit, Close
    • Reports: View, Create, Export
    • Payroll: View, Create, Approve
    • Settings: View, Edit
    • And more for each module.
  5. Save.

Assigning Roles to Users

  1. Go to Access Control → Users.
  2. Click a user's row.
  3. Select the Role to assign.
  4. Save.

Users inherit all permissions from their assigned role.

Managing Users

The Users page shows all admin and staff accounts:

  • Search by name or email.
  • Filter by role or status.
  • Activate/Deactivate users.
  • View activity logs for each user.

Sending Invitations

  1. Go to Team → Invitations.
  2. Click Invite User.
  3. Enter their email address.
  4. Select their role.
  5. Send the invitation.
  6. Track status: Pending, Accepted, Expired.
  7. Resend expired invitations.

Permission Checks

The system enforces permissions at every level:

  • Sidebar navigation — only shows pages the user has access to.
  • Page content — data is filtered to what the user can see.
  • Actions — buttons and forms are hidden/disabled for unauthorized actions.
  • API level — backend validates permissions on every request.

Tips

  • Use the principle of least privilege — give users only the permissions they need.
  • Create a "Shift Manager" custom role if you have staff who only handle scheduling.
  • Audit roles regularly — remove permissions that are no longer needed.
  • Review the Audit Log to see what users are doing with their access.

Related Articles

  • Managing Guards
  • Settings & Configuration
  • Audit Log
  • Invitations

Was this article helpful? Contact Support