Permissions and seats
Roles, Access Permissions, and Licenses Guide for Planado
In the Planado web application, employees can have access to the web application and the mobile application. User access management is performed using Roles (named sets of permissions). You can assign one or multiple roles to each employee with the option to scope access by business units.
1. Key Concepts and Licenses
Employee access can be paid (using a license) or free:
- Paid access (uses a license): Required for employees who create and edit jobs, clients, sites, and work with the schedule and map in the web application, as well as field workers completing jobs in the mobile app. The number of paid licenses is configured on the Settings → Billing page.
- Free access (no license used): Assigned to employees who only require read-only access in the web application or mobile app. These employees cannot make changes or execute jobs. The number of free users is unlimited.
- Trial period: In the trial version, you can add any number of employees with paid access.
- Pricing plan: Applies across all employees in the company simultaneously — users cannot be on different pricing plans.
Important: The Owner user also consumes a paid license. Only the Owner has access to the billing page. Transferring ownership to another employee can be done on the Settings → General page.
2. Default Built-in Roles
Planado comes with 5 pre-configured roles covering primary employee workflows:
- Administrator
- Purpose: Company-wide settings and service management (except the billing page).
- Permissions: Full access to all web application sections and company settings (except mobile app access).
- Details: System role; cannot be edited or deleted.
- License: Requires a paid license.
- Manager
- Purpose: Operations management without administration privileges.
- Permissions: Edit all data in the web application (jobs, clients, sites, schedule, etc.).
- Restrictions: No administrative functions and no access to the mobile app.
- License: Requires a paid license.
- Dispatcher (Operator)
- Purpose: Day-to-day work with jobs, teams, and schedule.
- Permissions: Edit jobs, clients, and sites; view teams, schedule, and employees; access the map and shift management.
- Restrictions: Cannot delete jobs.
- License: Requires a paid license.
- Field Worker (Team Lead / Performer)
- Purpose: On-site work via the mobile app.
- Permissions: Execute jobs in the mobile app (including creating jobs via the mobile app if enabled in settings).
- License: Requires a paid license.
- Read Only
- Purpose: Executives and team members who do not need to make changes or execute jobs.
- Permissions: View all pages in the web application and mobile app without editing capabilities.
- License: Not required (free role).
3. Roles Section (/admin/roles)
Manage role templates under Settings → Roles.
Section Capabilities:
- List view: Displays built-in and custom roles, a "Paid seat" indicator, and the number of assigned users.
- Creating a role: Click Create role, enter a unique name, and configure access levels (View, Edit, Delete) for each system area.
- Renaming & editing: Edit permissions in custom roles (the Administrator role is locked). Changes apply to all holders on their next page load.
- Managing licenses in roles: The "Requires a paid seat" toggle controls license consumption:
- Unticking this removes all seat-bearing permissions from the role, making it free.
- Adding seat-bearing permissions to a free role requires licenses for all holders. If insufficient licenses are available in your subscription, saving is blocked.
- Deleting a role: The Administrator role cannot be deleted. Other roles can be deleted after confirming the action, which revokes that role's access from all holders instantly.
4. Assigning Roles and Licenses to Users
Manage individual employee access in the user card (Settings → Employees → List).
- Open a user card or click Add user.
- In the Roles and permissions block:
- Click Add role.
- Select a role from the list.
- Specify the scope: All business units or specific Business units.
- Add additional roles or configure the Additional permissions block if needed.
- Check the badge indicator: the system states whether the user "Takes a paid seat" or "Does not take a paid seat".
- The used seats counter increases when a user without a seat is given a seat-bearing role.
- If all paid seats are occupied, the Owner can purchase more under Settings → Billing.
- The counter decreases when a paid role is revoked or replaced by a free role (e.g., Read Only).
- Click Save.
Access Mechanics:
- Combining roles: If a user holds multiple roles, their total permissions are merged (union of permissions).
- Instant update: Permissions update immediately upon navigating to a new page or refreshing the browser.
- Business unit scoping: Switching to a business unit where the employee lacks a role hides the corresponding sections and records.
5. Permission Delegation (Who Can Manage Users)
To allow a non-administrator user to add or edit employees, grant them user editing permissions:
- Permission limits: A user cannot grant more permissions than they possess. Assigning roles or permissions exceeding their own access level is blocked (including editing email/password for users with higher privileges).
- Unit limits: A manager or business unit administrator can manage users and assign roles only within their authorized business units.
- The Owner and an All-units Administrator can grant any role or permission company-wide.
Need help configuring roles and licenses? Submit a request or email us at support@planado.app.