Skip to main content

Roles and permissions

Every user in TrackMyMachines has exactly one role, and that role decides what they see and what they can change. This page is the full reference. For the step-by-step of adding people and pairing tablets, see Setting up users.

Roles apply per organisation — a user belongs to one organisation and their role only means anything inside it.

The three people roles

Three roles are for humans, and they stack: each one can do everything the one below it can, plus more.

Engineer → Manager → Admin

Engineer

The default role. If you invite someone and don't change the role, this is what they get — most of your team should be Engineers. An Engineer can:

  • View the Dashboard, Overview board, Timeline and Explore (charts)
  • Read Reports and browse the Insights library behind them
  • Book and edit machine events — logging downtime reasons and jobs against any machine in the organisation
  • View work orders and their operations

An Engineer has no Manage menu at all. They cannot change machines, parts, downtime reasons, reports, users or settings.

Manager

A Manager runs the shop floor. They get everything an Engineer has, plus the Assets, Production and Monitoring groups of the Manage menu — but nothing under Account.

That means a Manager can set up machines, components, shift patterns, downtime reasons and alerts, and can author reports and email schedules — but cannot change organisation settings, add or remove users, or issue API keys.

Managers also get the Operator Panel shortcuts in the sidebar, so they can open any machine's panel from their desk.

Admin

Full control of the organisation. Everything a Manager has, plus the Account group: organisation settings, users, API keys, and the Operator Panel configuration page.

note

Admins cannot create or edit other Admins. They can see them in the user list, but the Edit and Delete buttons don't appear. Ask TrackMyMachines support to add or change an Admin account.

Device and system accounts

The remaining roles are not people. They exist so a screen, a terminal or an outside system can have an identity.

Tablet

A shop-floor terminal tied to one machine. It signs in by scanning a QR code and lands directly on that machine's Operator Panel. It can log events and work orders for its machine and nothing else — no dashboards, timeline or charts.

You set a username and pick the machine instead of entering an email address. See Logging in a tablet.

Display (TV)

A wallboard account for a screen hung on the factory wall. A Display user signs in and lands straight on the andon board — the full-screen TV skin of the Overview at /overview/andon — and that is the only page it can reach. Any other URL bounces it back to the board.

Like a tablet, it uses a username rather than an email address, and pairs by QR code. Combine it with area gating to hang one screen per cell.

NoLogin

A user that exists for record-keeping but can never sign in. It has no password and gets no invitation email, and shows an API Only badge in the user list.

Use it for ERP and API integrations: when an outside system reports who ran a job or caused a stoppage, that person needs a user record so their activity appears in reports — but they don't need access. Set a Foreign ID to match them to their ID in your ERP system.

What each role can manage

The Manage menu has four groups, and the role boundary is exactly "which of these groups do you see":

Manage groupPagesEngineerManagerAdmin
AssetsMachines, Machine Groups, Areas
ProductionWork Orders*, Components, Shift Planner, Shift Patterns
MonitoringDowntime Reasons, Downtime Alerts, Insights, Custom Reports, Email Schedulesread-only†
AccountOrganisation settings, Users, API Keys, Operator Panel‡

* Work Orders only appears when work orders are enabled for your organisation.

† Engineers can read Reports and Insights from the Reports section of the sidebar, but have no Manage menu and cannot edit them.

Operator Panel is listed under Monitoring in the menu, but it is an Account-level permission and stays Admin-only. Managers still get the per-machine Operator Panel shortcuts in the sidebar — it's the configuration page they don't see.

The menu is built from these permissions, so a Manager simply never sees an Account group — there are no greyed-out links.

Who can hand out which role

When an Admin creates a user, the role dropdown offers:

  • Engineer (the blank default)
  • Manager
  • Tablet
  • Display (TV)
  • NoLogin

Admin is deliberately not in that list — only TrackMyMachines support can create or change an Admin account. Contact support@trackmymachines.com if you need another Admin.

Area gating

Independently of role, any user can be pinned to an Area using the Area Gating dropdown on the user form. A gated user sees only that area, its child cells and the machines in them — on the Overview, the andon board and the machine pickers throughout the app.

Area gating narrows what a user sees; it does not change what their role lets them do. A gated Manager is still a Manager, just for one part of the factory.

Two-factor authentication. If your organisation requires 2FA, every person role — Engineer, Manager and Admin — must enrol. Tablet, Display and NoLogin accounts are exempt, because there is nobody there to hold a phone.

Grafana. If you use the Grafana integration, a user's TrackMyMachines role decides their Grafana permission: Admins and Managers become Editors, everyone else becomes a Viewer. A role change takes effect the next time that user opens Grafana and signs in through TrackMyMachines.

API keys have their own read-only / read-write roles, which are separate from user roles — see API Authentication. Only Admins can create them.