Guide 06 · Accountable access

Give each person exactly the access their work needs.

Revolution Road combines invite-only Supabase Auth, organization-scoped rows, explicit permissions, assignment rules, and named approvals.

01

Apply the scoped-role migration

Run 202608060023_scoped_role_access.sql after the earlier migrations. The legacy Manager role is removed and every operational row is evaluated against a store boundary.

02

Invite the team

Admins can invite any available role and choose its required scope. District Managers see a General Manager invitation only and must choose a store in their own district. General Managers do not see an invitation control. Market Presidents automatically cover every active market. Every recipient creates an eight-character-or-longer password and enters it twice.

03

Assign work

Admins and operating leaders select an active member on a work order inside their scope. Assignment and critical-priority events appear in-app and enter the notification outbox.

04

Request and decide approval

Technicians and operating leaders request review from a work order. Only an eligible approver inside that work order’s store or district can decide it.

05

Revoke or remove access

Deactivate a member, revoke sessions, or permanently delete a profile from Team. Deactivation is reversible. Profile deletion removes sign-in and contact information while preserving the member’s name on submitted work orders and other maintenance history.

Default roles

A role model the team can explain.

AdminSecurity, team, roles, sessions, and every operation
Market PresidentEvery market, district, store, and operational record; no security administration
District ManagerOperational records for one required district and all stores inside it
General ManagerOperational records for one required store
TechnicianAssigned field work, evidence, labor, parts use, and approval requests
ViewerRead-only records for one required market, district, or store
Open the productManage team access →