Permission Matrix
The full grid of who can do what. Use this when you want to compare two roles side by side, or when you're deciding which role to assign someone.
If this is your first time on this page, read How Permissions Work first - the legend below assumes you know the difference between org-wide access ("everything in the company") and assigned access ("only what's granted to me").
The Project Manager column shows what the per-project PM assignment grants on the assigned project. It is not an org-wide role: outside the assigned project, a PM sees only what their org-wide role (usually Viewer) gives them. Crane Operator and Escort behave like Driver and Rigger/Operator Supervisor (assigned loads only); they are omitted from the grid below to keep it readable, see User Roles for their exact grants.
Legend
| Cell value | Meaning |
|---|---|
| Manage | Full control: read, edit, add new, delete |
| Manage+Export | Full control plus download/print |
| Update | Edit existing items, not add new or delete |
| Create | Add new items (and edit them, since Create implies Update); not delete |
| Read | View only |
| Read+Export | View and download/print |
| Request | Propose a change for approval (the change goes pending until someone with Manage applies it) |
| — | No access at all |
| (assigned) | Only on items assigned to this user, not the whole company |
When two values appear together, the user has both. Manage+Export means they can manage and export.
User roles: Company-level
How the user roles relate to your company itself: settings, members, equipment catalog, locations.
| Subject | Org Admin | Ops Manager | Project Mgr | Dispatcher | Permit Coord | Driver | Rigger/Op Sup | Viewer |
|---|---|---|---|---|---|---|---|---|
| Company info | Manage | Read | Read | Read | Read | — | — | Read |
| Team members (invite, role) | Manage | Read | Read | Read | Read | — | — | Read |
| Company settings | Manage | Read | Read | Read | Read | — | — | Read |
| Trucks, trailers, people, equipment | Manage | Manage | from org role | Read | Read | Read | Read | Read |
| Equipment types | Manage | Read | from org role | Read | Read | Read | Read | Read |
| Points of interest | Manage | Manage | from org role | Read | Read | Manage | Read | Read |
| Saved locations | Manage | Manage | from org role | Read | Read | Manage | Read | Read |
Drivers and Rigger / Operator Supervisors have no access to the company record itself (info, members, settings): they never see the company profile or the team roster. They do still see the shared resources they work with, trucks, trailers, people, equipment, points of interest, and saved locations.
The Project Manager column at company level is "from org role": a PM assignment is scoped to a project, so it grants nothing at the company level. Company-wide access (like reading the resource catalog) comes from the PM holder's org-wide role, usually Viewer.
Why drivers manage POIs and saved locations: drivers add real-world spots from the field (yards they actually use, alternate stop locations, etc.). The catalog grows from the ground up. Managing this catalog doesn't require admin rights.
User roles: Project-level
A project is your job/contract wrapper. Loads belong to projects.
| Subject | Org Admin | Ops Manager | Project Mgr | Dispatcher | Permit Coord | Driver | Rigger/Op Sup | Viewer |
|---|---|---|---|---|---|---|---|---|
| Projects | Manage | Manage | Manage (assigned) | Read | Read | Read (assigned) | Read (assigned) | Read |
| Schedule & crew | inherits Manage | inherits Manage | inherits Manage (assigned) | inherits Read | inherits Read | inherits Read (assigned) | inherits Read (assigned) | inherits Read |
| Project documents | Manage+Export | Manage+Export | Manage+Export (assigned) | inherits Read | Manage+Export | Create+Export (assigned) | inherits Read (assigned) | Read+Export |
| Project planned routes | Manage+Export | Manage+Export | Manage+Export (assigned) | inherits Read | Manage+Export | Create+Export (assigned) | inherits Read (assigned) | Read+Export |
| Project surveys | inherits Manage | inherits Manage | inherits Manage (assigned) | inherits Read | inherits Read | inherits Read (assigned) | inherits Read (assigned) | inherits Read |
"inherits" means the cell isn't set explicitly - it picks up the parent's grant. So a Dispatcher's permission on Schedule & Crew is whatever Dispatcher has on Project, which is Read. We use this notation so you can see the inheritance at a glance.
"Manage (assigned)" for Project Manager: the PM assignment grants Manage on the project it's assigned to. Browsing other projects comes from the PM holder's org-wide role (usually Viewer's org-wide Read), not from the assignment.
User roles: Load-level
A load is a single shipment. Most heavy haul work happens here.
| Subject | Org Admin | Ops Manager | Project Mgr | Dispatcher | Permit Coord | Driver | Rigger/Op Sup | Viewer |
|---|---|---|---|---|---|---|---|---|
| Loads | Manage | Manage | Manage (assigned) | Manage | Read | Read (assigned) | Read (assigned) | Read |
| Load details | inherits Manage | inherits Manage | inherits Manage (assigned) | inherits Manage | inherits Read | inherits Read (assigned) | inherits Read (assigned) | inherits Read |
| Load schedule | inherits Manage | inherits Manage | inherits Manage (assigned) | inherits Manage | inherits Read | Request (assigned) | Request (assigned) | inherits Read |
| Equipment setup | inherits Manage | inherits Manage | inherits Manage (assigned) | inherits Manage | inherits Read | Update (assigned) | inherits Read (assigned) | inherits Read |
| Equipment assignments | inherits Manage | inherits Manage | inherits Manage (assigned) | inherits Manage | inherits Read | inherits Update (assigned) | inherits Read (assigned) | inherits Read |
| Commodity | inherits Manage | inherits Manage | inherits Manage (assigned) | inherits Manage | inherits Read | Create (assigned) | inherits Read (assigned) | inherits Read |
| Active route (live tracking) | inherits Read | inherits Read | inherits Read (assigned) | inherits Read | inherits Read | inherits Read (assigned) | inherits Read (assigned) | inherits Read |
| Planned routes | Manage+Export | Manage+Export | Manage+Export (assigned) | Manage+Export | Manage+Export | Create+Export (assigned) | inherits Read (assigned) | Read+Export |
| Permits | inherits Manage | inherits Manage | inherits Manage (assigned) | inherits Manage | Manage | Create (assigned) | inherits Read (assigned) | inherits Read |
| Permit route review | inherits Manage | inherits Manage | inherits Manage (assigned) | inherits Manage | inherits Manage | Update + Request (assigned) | inherits Read (assigned) | inherits Read |
| Load documents | Manage+Export | Manage+Export | Manage+Export (assigned) | Manage+Export | Manage+Export | Create (assigned) | inherits Read (assigned) | Read+Export |
| Load surveys | inherits Manage | inherits Manage | inherits Manage (assigned) | inherits Manage | inherits Read | inherits Read (assigned) | inherits Read (assigned) | inherits Read |
| People on load | inherits Manage | inherits Manage | inherits Manage (assigned) | inherits Manage | inherits Read | inherits Read (assigned) | inherits Read (assigned) | inherits Read |
Notable narrowings:
- Drivers can update equipment setup but only request schedule changes. Hooking the trailer is a fact you record (Update). Moving pickup from Tuesday to Wednesday is a coordinated decision (Request - dispatch confirms).
- Drivers create permits and documents from the field but don't delete. Anything that needs deletion goes through someone with Manage.
- Permit Coordinators have Manage on permits but not on the load itself. They can't change the schedule or assign equipment. They own the permit, not the operation.
- A Project Manager's access is scoped to the assigned project. Everything they manage (loads, permits, routes, documents) is on that project. Org-wide reach (like reading other projects) comes from their org-wide role, not the PM assignment.
Saved Views
Saved Views (a premium feature) is governed by its own subject, Organization.SavedViews, with the actions read, create, update, delete, and manage. Access doesn't split by the eight roles the way loads and projects do. It splits by the view's tier instead, so it gets its own small grid.
| View tier | Whose list it shows up in | Who can edit or delete it |
|---|---|---|
| Personal | Only the owner | The owner (self-managed) |
| Workspace (org-shared) | Everyone in the org | The creator, or anyone with Manage on saved views (admins) |
- Personal views are self-managed. Any user can create, edit, and delete their own Personal views. They don't need a special role. The tier controls listing, not link access: a same-org teammate with the direct link can open a personal view read-only.
- Workspace views follow a creator-or-manage rule. The person who created the view can edit it, and so can anyone who holds Manage on saved views. Holding create lets a role author its own Workspace views, but not overwrite anyone else's. Admins curate the shared set.
- Authoring a Workspace view requires permission. The Workspace visibility option only appears for users allowed to publish org-shared views.
- Built-in default views (like "All loads") belong to the product: everyone sees them, and nobody in your organization edits or deletes them. Duplicate one to customize it.
- Offload staff cannot reach your views. Platform staff have no read or write access to your organization's Personal or Workspace views.
See Saved Views and Who can see a view for the feature side of this.
"Self" subjects
Every user can read and update their own profile and resource status, regardless of role. This isn't a role grant - it's a built-in identity layer.
| Subject | Every role |
|---|---|
| Your own profile (name, contact) | Read + Update |
| Your own resource status (clocked in, location share) | Read + Update |
You cannot edit anyone else's profile through this layer. Editing other people's profiles requires Manage on Organization.Users (which only Org Admin has).
Composing a custom permission set (per-user overrides)
Your Org Admin can grant additional permissions to a specific user on top of their role. This is useful for one-off cases: "this driver also needs to manage permits because they handle paperwork on the road."
A few rules:
- Overrides only add; they never take away. To remove a capability, change the user's role.
- Overrides are unconditional. They apply to the user across the whole org, not just their assigned items.
- Overrides are not used for self-data (your own profile, your own status). Those are protected at the identity layer.
If you need this, talk to your Org Admin or contact support@letsoffload.com. There's no self-serve UI yet.
Still confused? Try "I want to..." Scenarios - it works backward from goals to roles. Or FAQ & Troubleshooting for common questions.