Skip to main content

Roles and permissions explained

Roles decide what a person can see and do in Trustaroo. This page explains the two roles that exist out of the box, every permission in the system, and how to build a role of your own.

An advanced screen

Roles only appears under Organization if your own role grants the permission to read roles. Single-business customers never need it: the default role already gives them everything they use.

The two roles that already exist

RolePermissionsWho gets it
AdministratorEvery permission in the systemAssigned deliberately
BusinessOwnerRead reviews and interactions, read and write the business profileEvery self-registered account

Someone who signs up at my.trustaroo.app becomes a BusinessOwner. That role covers the whole day-to-day product: the dashboard, reviews and private feedback, the business profile, locations, branding and automation. It deliberately does not include the Organization screens, which is why most customers never see them.

Every permission and what it grants

  • user.read - see the Users screen and the list of people in the organization.
  • user.write - save changes to a user and delete a user.
  • user.create - create users.
  • role.read - see the Roles screen.
  • role.write - save changes to a role and delete a role.
  • role.create - create a role.
  • interaction.read - read the ratings and private feedback customers left.
  • business_profile.read - read the business profile, its locations and their settings.
  • business_profile.write - change the business profile, its locations, branding and automation.

Read permissions control whether a screen appears at all. Write and create permissions control whether the buttons on it do anything.

Create or edit a role

  1. Expand Organization and select Roles.
  2. Choose Add to start a new role, or select the chevron at the end of a row to expand a role you already have.
  3. Type or change the role name in Name.
  4. In the matrix, tick the boxes you need. The columns are Read, Write and Create, and the rows are the Users and Roles permission groups.
  5. Choose Save. Delete on the same row removes the role.

Use the Search roles box at the top when the list is long.

The matrix only covers users and roles

The permission matrix exposes the Users and Roles groups. The review, interaction and business profile permissions exist in the system but are not editable here, so build access around the two seeded roles rather than expecting a custom role to grant profile access.

Assigning a role to someone

Roles are assigned on the person, not on the role screen. Open Users, select the row to open the detail drawer, tick the roles that person should have and choose Save. A user can hold more than one role, and permissions add up: holding any role that grants a permission is enough.

Practical advice

  • Leave Administrator with as few people as possible. It includes the ability to delete users and change every role, including its own.
  • Do not delete a role that people still hold. Remove it from them first, so you can see who is affected.
  • Changes take effect the next time the person loads the app. Ask them to reload if a screen they should now see is still missing.
Check the effect on a real person

After changing a role, open that person's row in Users and read the roles column. It is faster than asking them to describe what they can see.