For app owners

Who can see and change data

Set permissions for public pages, internal teamwork and a person’s own records.

Before you start

List what customers, technicians and managers should see. Sign-in can be enabled in app management. Roles define what each group of people can do. They require the Roles extension and permission rules set up through your assistant.

Set permissions around people’s work

  1. Separate public and internal pages

    A website, price list or booking form can be public. Customer lists, internal notes and the work board usually belong behind sign-in. Knowing the link is not a substitute for sign-in protection.

  2. Describe permissions to your assistant

    Say who can read, add, edit and delete data. If someone should see only assigned jobs, ask for the restriction to apply to data and changes too.

  3. Assign roles to colleagues

    In user management, use the same role names as the configured app. Adding a role name alone does not create permission rules. You can ask your assistant to change an existing person’s roles.

  4. Test each group

    Open the app without signing in, then as a test colleague. Check the overview, detail and an attempted change. Hiding a page or button alone is not enough to protect data.

Example request

Manager and technician
Update my service app: managers can see and edit every job, technicians only their assigned jobs and can record work done. Only managers can change the price or delete jobs. Restrict data access and changes too, not just button visibility. Only reporting a fault should remain public.

Co-author access to the preview

A co-author helps change the app’s design. In the preview, they can see data beyond ordinary user role and own-record restrictions. Give editing access to people you also want to share this data with. Check a technician’s or customer’s access in the live app using the corresponding account, rather than the preview.

How to invite a co-author

How to check the result

A technician cannot open another person’s job even by pasting its address, or make a change reserved for the manager. A customer without signing in cannot see the internal overview. Signed-in users may see internal page names in app settings even when they cannot open those pages.

How to add or remove colleaguesThe Roles extension