Go to Settings → Roles. CrewByte comes with three built-in roles — Owner, Manager and Team member — and you can create as many custom roles as you need.
Custom roles let you match the system to the way your business actually works instead of forcing everyone into a generic hierarchy.
How permissions work
A role is simply a list of permissions. Each permission controls a specific ability (for example “edit checklists”, “view reports”, “manage training”, or “submit support tickets”).
Anything that is not ticked is refused — both in the menus the person sees and on the server when they try to perform the action. Hiding a button is never the only protection; the system enforces the rules properly.
When we add new features in future updates, those new permissions start as off for all custom roles. Nothing is switched on automatically for people who have not been assessed.
The Owner role exception
The built-in Owner role always has every permission and cannot be restricted. This is deliberate.
If an Owner could remove “manage roles” from their own role, they could permanently lock themselves out of their own workspace with no way to recover. Keeping Owner unrestricted prevents that situation.
We recommend having at least two people with the Owner role so you are never dependent on a single account.
Access to sites
Most permissions control what a person can do. The permission called Access every location is different — it controls where those abilities apply.
Without this permission, a user only sees the specific sites they have been assigned to in the Team section. With it, they can see every site in the organisation.
This is how you give an area manager full control over their patch of sites without giving them access to the entire group.
Permissions to treat with care
Two permissions deserve extra thought before you grant them:
- Manage roles — Anyone with this permission can edit roles, including their own. They could widen their own access if they wanted to.
- Manage the team — This includes the ability to invite people, change roles, assign sites, and set or reset PINs for other users.
Both of these are clearly flagged in the role editor so you notice them.
Creating a new role
Click Add role, give it a clear name (for example “Head Chef”, “Duty Manager”, “Area Manager” or “Kitchen Porter”), and tick only the permissions that person actually needs.
It is usually better to start with fewer permissions and add more later than to give overly broad access and try to tighten it afterwards.
Assigning roles to people
Once the role exists, open the person’s record in Team and select the new role from the dropdown. Changes take effect the next time they load the app or refresh the page.
Deleting or changing a role
If you delete a role, CrewByte will ask you where to move the people who are currently on it. Nobody is left without a role.
You can edit a role’s permissions at any time. The new permissions apply to everyone who holds that role.
Good practice is to create roles that match real job titles or responsibilities in your business rather than vague labels. Clear names make it much easier to keep access under control as the team grows.
Practical tips
- Start with the three built-in roles. Only create custom ones when you hit a real limitation.
- Review who has the Owner and “Manage roles” permissions every few months.
- When someone leaves, either deactivate their account or move them to a role with no access immediately.
- If you run multiple sites, use the “Access every location” permission carefully — most people only need the sites they actually work on.
Once your roles are set up cleanly, adding new team members becomes much faster and safer because you are simply choosing the right role instead of deciding permissions from scratch each time.