DetailOAR Field Manual · Team and permissions

Add Employees, Roles, Schedules, and Permissions

Give people separate dashboard and field identities, hand out the least privilege, issue rotatable technician links, and verify what each role can read and change.

Intermediate12 min readAction: 35 minUpdated July 16, 2026
Start guide
Save or use this guide
Download checklist

Team management screen showing synthetic owner, manager, and technician accounts with roles and statusView full size
Contents
01

Start

Know the outcome.

02

Steps

Do the work in order.

  1. Step 1

    Add a dashboard account

    1. Open Manage Team.

    2. In Dashboard accounts choose Add account.

    3. Enter the person’s real Display name and a unique email/username.

    4. Choose the minimum Role plus any capability they explicitly need.

    5. Set a temporary or invited-password flow, whichever the screen offers, then choose Add account.

    6. Sign out, or use a separate browser profile, and verify the account opens its allowed screens and gets a clear 403 response on direct URLs it shouldn’t reach.

  2. Step 2

    Add an installer and schedule work

    1. Choose Add installer.

    2. Enter Name, the contact details internal operations actually needs, normal start/end availability, skills, a commission rule if approved, and the active state.

    3. Link the matching dashboard account only when the relationship is right and tenant-scoped.

    4. Choose Add installer, then open an appointment and Assign that installer.

    5. Try an overlapping assignment. The server should block the collision, or demand an authorized explicit override with a warning.

  3. Step 3

    Issue and protect field access

    1. Beside the installer choose Field access.

      Technician access settings showing schedule, permissions, field-app access, and invitation stateView full size
    2. Choose Create / rotate link, then copy the link once into an approved secure channel.

    3. Open it in a private mobile browser and check that only that installer’s assigned work appears.

    4. Choose Revoke access the moment a device or link goes missing. Create / rotate link invalidates the prior link — verify the old URL really stopped working.

  4. Step 4

    Account safety routine

    1. Require unique passwords and turn on two-factor authentication with Enable 2FA.

    2. Remove or deactivate access on the person’s last working day — taking them off the visible schedule isn’t enough.

    3. Review active accounts, field links, capabilities, and audit events on a set schedule.

    4. Never let a password or field token travel in a customer note, an invoice, or a public guide screenshot.

03

Reference

Use the detail when you need it.

Understand the two access types

Dashboard accounts sign in with a password and a role. Installer records represent schedulable workers and can carry a separate rotatable Field access link. Link the two on purpose — and never share one owner login or one field link across people.

Choose the least privilege
  • Owner: billing, integrations, workspace lifecycle, and every business record. Keep this role rare.
  • Administrator/Manager: broad operating control without platform ownership, where supported.
  • Staff: day-to-day customers, estimates, appointments, and messages, as their capabilities allow.
  • Technician: assigned field work, job stages, the allowed media/checklist actions — and none of the customer/financial reporting they don’t need.
Troubleshooting
  • User sees too much: fix the server-side role/capabilities immediately, revoke sessions, and review access logs.
  • Field link shows no jobs: check the assignment, date, active installer, and current rotated token.
  • Can’t deactivate yourself: use another Owner account — self-lockout protection is there on purpose.
  • Schedule collision warning: look at full job duration, travel, multi-day spans, and existing assignments before you force it.
04

Finish

Check the result and close the loop.

Final checklist
  • Separate identity per person.
  • Least role/capabilities assigned.
  • Direct URL denial tested.
  • Installer availability and conflict tested.
  • Field link rotated/revoked test passed.
  • 2FA and offboarding procedure documented.
05

More

Continue only where it helps.

Frequently asked questions
Can technicians share a field link?

No. One rotatable link per installer keeps assignments and actions attributable to a person.

Is hiding a navigation item enough?

No. The server has to deny unauthorized requests even when someone types the URL directly.

What should I do when a phone is lost?

Revoke or rotate the field link right away, then review recent audit/job activity.

Sources and review

Reviewed by DetailOAR Product Team on July 15, 2026. Verify current labels, interfaces, prices, and local requirements before acting.

  1. DetailOAR seeded application interface

Product screenshot