---
title: "Roles & Permissions"
canonical: "https://support.out-smart.com/space/TIB/418644008/Roles%20%26%20Permissions"
format: markdown
---
Every employee you activate gets login details and you have to assign them to a user group. Based on this user group, the employee has certain rights within the backoffice. So if he logs in via a browser, he can view the planning board based on his user group or not. He may or may not create work orders and he may or may not create or even view a new customer.

So all these types of settings are based on the user group. You can create and set this up via Settings > Groups > Roles & Permissions. Here you can see the existing user groups and you can use the 'Add' button to create a new group.

In general, at least three groups are chosen:

> ℹ️ - '<span style="color: #ff991f">Admin</span>' or '<span style="color: #ff991f">Management</span>', in which everything is possible. Someone assigned to this group can do anything in the backoffice, including purchasing new licenses and change settings.
> ℹ️ - '<span style="color: #ff991f">Office</span>', in which the office staff works. They can view the scheduler and create and edit work orders, but also view customers and create quotes.
> ℹ️ - '<span style="color: #ff991f">Field service</span>', to which the field service employees are assigned. They only have to work with the app, so nothing is permitted for them in the backoffice. So everything is turned off.

Of course, a lot of variation can be applied here. For example, it is possible that only a few employees can create quotes, but not everyone of the office staff. In that case you can create a user group for office staff who are only allowed to do the planning, and a user group for office staff who are allowed to do the planning, but can also make quotes.

<span style="color: #ff991f">**Adding a new user group**</span>  
If you click ‘Add’ in Roles & permissions, you can create a new user group. For this you can choose a template, in which certain checkmarks (permissions) are already on or off. Then you give this group a name and you can adjust checkmarks if necessary. After saving, the user group is created and you can assign employees to the group.

Below you will find part of the overview of permissions that can be turned on or off within a user group:

![image](media://d778e09c-26ab-4a01-903e-8af0d36a98d9)

Most chapters can also be opened. For example, at ‘13. Work order’; you can indicate that the employee can view a work order but cannot edit it.

When you open ‘9. Employees’, you see the following:

![image](media://be0f50e7-6b45-45e1-8e1d-6b6b68908938)

If only the main check mark Employees is on, then the employee has insight into the employees, but he cannot adjust them. If he has to be able to edit, then the check mark ‘Allow to manage employees’ must be on also. Based on the Edit profile checkbox, the employee can edit their own profile, but not that of others. This is therefore useful when he wants to change his password.

> ⚠️ These settings are only about the rights and roles within the back office. For obligations and restrictions within the app; see [Device policies and settings](https://out-smart.atlassian.net/wiki/spaces/TIB/pages/418480214).