SAM · Guide
Understand staff roles and permissions
EnglishUpdated Sep 13, 2026
A role groups permissions. Your workshop can customise roles, so a role name alone does not guarantee access. The table describes the current default staff presets; older or customised workshops can differ.
- System Admin — Typical default responsibilities: Full workshop administration. Important boundary: Use a personal account rather than sharing this login.
- Service Manager — Typical default responsibilities: Workshop supervision, approvals, invoicing, finance, stock, reports and employees. Important boundary: Not every system-setting or role-administration permission is part of the manager preset.
- Service Advisor — Typical default responsibilities: Customers, vehicles, visits, estimates, job preparation, assignment and invoice drafts/payments. Important boundary: Invoice issue, cost approval, work approval and rework are not all included by default.
- Receptionist — Typical default responsibilities: Customer/vehicle intake, work-order creation and booking visibility. Important boundary: Viewing bookings does not include managing them by default.
- Technician — Typical default responsibilities: Assigned work, timers, relevant inspections and parts requests. Important boundary: The technician workflow is not unrestricted job editing or access to everyone's pay.
- Cashier — Typical default responsibilities: Invoice preparation, approval, issue, sending and payments; selected finance/report access. Important boundary: Transfers, reversals and supplier payments are separate responsibilities.
Other role names, including Service Writer, Store Manager and Warranty Manager, may exist. Have the administrator inspect their actual permissions rather than assuming a preset from the name.
Review or change access
- An authorised administrator opens Configuration → Users and reviews the person's Roles.
- Open Configuration → Roles to inspect the chosen role's Permissions.
- Use Edit, select only the responsibilities intended for that role, and Save.
- Recheck the person's available actions after the access change.
Changing a role can affect every user assigned to it. A staff login and an employee/technician record also need to be correctly linked for assignment and timers.
Permissions that should not be confused
- Viewing a record is separate from creating, editing or deleting it.
- Approve Cost, Approve Work, rework and hour overrides are separate job actions.
- Invoice drafting, approval, issue, sending and payments are separate responsibilities.
- Finance recording, transfers, supplier payments and reversals are separate.
- Inspection recording, completion and sharing are separate.
- Cost figures, employee compensation and individual reports can have additional access checks.
- Campaign preparation does not automatically include campaign sending.
Troubleshooting
A feature can require both permission and a plan entitlement. Sami follows the same access boundaries. If a menu is visible but the action is refused, report the exact page and message to the administrator rather than granting broad access just to remove the error.