SAM · Guide

Understand staff roles and permissions

EnglishUpdated Sep 13, 2026

A role groups permissions. Your workshop can customise roles, so a role name alone does not guarantee access. The table describes the current default staff presets; older or customised workshops can differ.

  • System Admin — Typical default responsibilities: Full workshop administration. Important boundary: Use a personal account rather than sharing this login.
  • Service Manager — Typical default responsibilities: Workshop supervision, approvals, invoicing, finance, stock, reports and employees. Important boundary: Not every system-setting or role-administration permission is part of the manager preset.
  • Service Advisor — Typical default responsibilities: Customers, vehicles, visits, estimates, job preparation, assignment and invoice drafts/payments. Important boundary: Invoice issue, cost approval, work approval and rework are not all included by default.
  • Receptionist — Typical default responsibilities: Customer/vehicle intake, work-order creation and booking visibility. Important boundary: Viewing bookings does not include managing them by default.
  • Technician — Typical default responsibilities: Assigned work, timers, relevant inspections and parts requests. Important boundary: The technician workflow is not unrestricted job editing or access to everyone's pay.
  • Cashier — Typical default responsibilities: Invoice preparation, approval, issue, sending and payments; selected finance/report access. Important boundary: Transfers, reversals and supplier payments are separate responsibilities.

Other role names, including Service Writer, Store Manager and Warranty Manager, may exist. Have the administrator inspect their actual permissions rather than assuming a preset from the name.

Review or change access

  1. An authorised administrator opens Configuration → Users and reviews the person's Roles.
  2. Open Configuration → Roles to inspect the chosen role's Permissions.
  3. Use Edit, select only the responsibilities intended for that role, and Save.
  4. Recheck the person's available actions after the access change.

Changing a role can affect every user assigned to it. A staff login and an employee/technician record also need to be correctly linked for assignment and timers.

Permissions that should not be confused

  • Viewing a record is separate from creating, editing or deleting it.
  • Approve Cost, Approve Work, rework and hour overrides are separate job actions.
  • Invoice drafting, approval, issue, sending and payments are separate responsibilities.
  • Finance recording, transfers, supplier payments and reversals are separate.
  • Inspection recording, completion and sharing are separate.
  • Cost figures, employee compensation and individual reports can have additional access checks.
  • Campaign preparation does not automatically include campaign sending.

Troubleshooting

A feature can require both permission and a plan entitlement. Sami follows the same access boundaries. If a menu is visible but the action is refused, report the exact page and message to the administrator rather than granting broad access just to remove the error.

Related articles

Explore more SAM guides

People, when you need them

Let’s work it out together.

Still stuck? Tell us what you’re trying to do. Our team will help you find your next step.

Opens a conversation on this page