What staff can see
What someone sees in the dashboard depends on their role defaults, explicit user overrides, tenant-level role configuration, applicable TRACS permission ceilings, and allowed shops. The server calculates the effective permission set; hiding a sidebar item is only the visible result of that authorization decision.
Role defaults are the starting point
Section titled “Role defaults are the starting point”The exact menu can vary with enabled features, but the current defaults follow this shape:
| Role | Typical default page access |
|---|---|
| Owner / Admin | All dashboard page scopes. Owner-only safeguards still protect ownership changes. |
| Manager | Management and customer-workflow pages, reports, settings, users, integrations, and customer apps; Billing and Permission Audit are not in the manager default. |
| Service Advisor | Daily customer workflows, reports, texting, connections, customer apps, and TRACS workflow pages; not Billing, Users, Branding, or general Settings by default. |
| Technician | Overview, Work Orders, TRACS Flow, TRACS Extended, mobile workflow, Support, and Feature Requests. |
| Member | A restricted workstation/TracsSync fallback with Overview, TRACS Extended, mobile workflow, Support, and Feature Requests. It is not a normal role to assign during staff invitations. |
Feature flags can hide a page even when the role grants it. Custom permissions can grant or revoke supported scopes, but tenant role settings, the TRACS permission ceiling, and parent-page requirements can still reduce the final access.
Sensitive areas to keep tight
Section titled “Sensitive areas to keep tight”Billing, user management, permission audit, settings, integrations, and shop branding are worth a quick access review. Also review sensitive actions—such as changing roles, billing, integration credentials, and customer or work-order data—instead of checking page visibility alone.
Multi-shop access
Section titled “Multi-shop access”Shop access is separate from page permission. A user can have permission to open a page and still be limited to selected shops; even an admin-level account can be shop-restricted. The shop selector shows only the shops allowed for that user, and a user explicitly assigned zero shops must not receive tenant-wide access.