Roles & Permissions
WAKU Care uses a role-based access system. Permissions are assigned at two levels: the Workspace level and the Deployment level. A user’s effective permissions are determined by their roles at both levels.
Managing users and roles
Section titled “Managing users and roles”To invite users and assign roles, go to Workspace Settings > Users & Permissions. See Managing Members for detailed instructions.
Workspace Roles
Section titled “Workspace Roles”Workspace roles control access to organization-wide features like settings, templates, and team management.
| Role | Description |
|---|---|
| Admin | Full access to all workspace features. Can manage settings, invite users, and create templates. Is automatically given the Admin deployment role on existing and future deployments (this role can be removed per deployment). |
| Viewer | Read-only access to workspace-level information. Cannot make changes. |
Deployment Roles
Section titled “Deployment Roles”Deployment roles control what a user can do within a specific site or installation.
| Role | Description |
|---|---|
| Admin | Full read and write access to everything within the deployment. |
| Technician | Can view devices, create and complete work orders, create cases, and manage spare parts within the deployment. |
| Viewer | Read-only access to the deployment’s devices, work orders, cases, and inventory. |
| End-Customer | Can view devices and create cases. Designed for customers who need to report issues but don’t perform maintenance work. |
How roles work together
Section titled “How roles work together”A user’s effective access is determined by the combination of their workspace role and deployment role(s):
- There is no automatic inheritance of roles: access to a deployment always comes from an explicit deployment role.
- A Workspace Admin is, however, automatically given the Admin deployment role on existing and future deployments. This explicit role can also be removed per deployment.
- A user without this automatic assignment needs an explicit deployment role to access a specific deployment.
- A Viewer at the workspace level can see workspace-wide information but their ability to act within a deployment depends on their deployment role.
Common role configurations
Section titled “Common role configurations”| Scenario | Workspace Role | Deployment Role |
|---|---|---|
| Organization administrator | Admin | Admin (per deployment) |
| Field technician at one site | — | Technician |
| Manager overseeing multiple sites | Viewer | Admin (per deployment) |
| Customer reporting issues | — | End-Customer |
| External auditor | Viewer | Viewer |
Roles in customer workspaces with deployments
Section titled “Roles in customer workspaces with deployments”When you set up a customer workspace as a manufacturer or service provider, your current workspace users receive their respective role (e.g. Admin or Viewer) in the new customer workspace and its deployment as well. You can adjust these roles later to create a configuration that suits your needs.
Next steps
Section titled “Next steps”- Managing Devices — Organize and track devices
- Creating Work Orders — Document maintenance and repair work
- Cases — Capture and resolve incidents

