Owner · HR · 3 min read
Your ops team, and who sees what
There are exactly two kinds of login, and the split is the most important thing in the product. Your ops team sees the station; a driver sees their own day and nothing about anybody else. Getting this right is what makes it safe to put your roster, your injuries and your drivers’ phone numbers in one place.
The two groups
- The ops team
- Owner, Ops Manager, Lead Dispatcher, Dispatcher, HR, Fleet Manager, Fleet Tech. Broad access, narrowed by which stations they work at and what their role may reach.
- Delivery Associates
- Their own schedule, their own scorecard, their own van, their own messages, their own forms. Never each other’s.
A driver cannot reach an ops screen even by typing its address, and the rule that stops them lives in the database rather than on the screen — so a bug on a page cannot leak a name the page was never sent.
Permissions are a list you edit, not a role you are stuck with
Users › Roles
Every role holds one setting per module: none, view or edit. So a dispatcher who should see phone numbers but not change them is a view; a Fleet Tech who closes tickets but has no business in HR is an edit on one module and none on the other. Change a role and everybody holding it changes with it, in one press.
Stations decide what an ops login sees
A role says what kind of thing somebody may reach; their stations say whose. Somebody at one yard cannot read the other’s board, roster or vans — and somebody who works both gets a chip to switch between them and a combined view of anything that merges honestly. Counts are never summed across stations, because a board is dispatched one station at a time and a merged number is one nobody can act on.
Adding somebody
Users › Members › Add someone
Type their name and work address, pick their role, and tick the stations they work at.
Send the invite.
They get an emailed link that is good for 24 hours. Opening it asks them to choose a password; nobody else ever sees or types it.
Have them turn notifications on.
In their account menu, on every browser and phone they use. Permission is asked for per browser, so a laptop and a phone are two separate switches — and it is how form alerts and the early-morning driver check reach a person rather than a screen nobody is looking at.
When somebody leaves
Users › Members › the person › Offboard
Offboarding switches their access off and bans the sign-in in the same press, which ends any session already open — including one on a phone in somebody’s pocket. Their name and everything they did stays, because the history has to remain answerable. There is a Bring back for the person who returns, and the screen tells you in words if either half did not land rather than reporting success over a job half done.
For a driver, do it from their profile in People instead: that one press also clears their future schedule days and their future board rows, gives their van seat back, and moves whoever was second call on that van up a place.