Skip to main content

Roles and permissions

Everything about people is managed on the "Team" page.

Roles

RoleBadgeWhat they can do
OwnerOwnerThe account that owns the organization. Can never be demoted or removed.
AdminAdminFull control within the org: manages members, roles, passwords and master data. Holds every permission implicitly.
MemberMemberThe default. Read-write on the org's project data — day-to-day logging works out of the box, no grants needed.
Project adminN projectsA member with full control of specific projects — granted per project from Team → Project admins or at invite time.

Safety rails, enforced server-side: the owner can't be demoted or removed, you can't demote or remove yourself, and an org can never be left without at least one admin.

Granular permissions

Admins can grant members extra, scoped capabilities from Team → "Permissions" on any member. The modal is scope-first: pick Org-wide ("applies across every project") or a single project ("org-wide grants still apply on top"), then flip toggles.

Two permissions gate real product areas today:

  • "Manage mechanic jobs" — create, edit, assign and close jobs on the Mechanics page, and edit the mechanics settings, categories and job templates. Members without it see the job board read-only.
  • "Manage events" — manage event crew, travel and crew templates.

The modal also offers quick-grant presets — additive bundles for common profiles: Mechanic, Race engineer, Team manager.

:::info Members can already do the day-to-day ICRX is deliberately not admin-locked for everyday work: any member can log laps and measurements and curate the org's own categories and tracks. Granular permissions add control where teams asked for it (jobs, crew) — more areas will move under granular control over time. :::

Adding people

Two paths from Team → "Add a team member":

  • "Create account" — email + role + generated password; works instantly, no email server needed. Ideal at the circuit.
  • "Invite link" — a link valid 14 days; the invitee signs in (or signs up) with the invited email and accepts. If the emails don't match, the accept button is disabled with a clear message. Pending invites can be copied or revoked from the Team page.

Password resets are also admin-driven: Team → "Password" sets a new one you hand over ("Password updated. Share it with …").

Was this page helpful?