Guide 06 · Accountable access
Give each person exactly the access their work needs.
Revolution Road combines invite-only Supabase Auth, organization-scoped rows, explicit permissions, assignment rules, and named approvals.
Apply the scoped-role migration
Run 202608060023_scoped_role_access.sql after the earlier migrations. The legacy Manager role is removed and every operational row is evaluated against a store boundary.
Invite the team
Admins can invite any available role and choose its required scope. District Managers see a General Manager invitation only and must choose a store in their own district. General Managers do not see an invitation control. Market Presidents automatically cover every active market. Every recipient creates an eight-character-or-longer password and enters it twice.
Assign work
Admins and operating leaders select an active member on a work order inside their scope. Assignment and critical-priority events appear in-app and enter the notification outbox.
Request and decide approval
Technicians and operating leaders request review from a work order. Only an eligible approver inside that work order’s store or district can decide it.
Revoke or remove access
Deactivate a member, revoke sessions, or permanently delete a profile from Team. Deactivation is reversible. Profile deletion removes sign-in and contact information while preserving the member’s name on submitted work orders and other maintenance history.
Default roles