Skip to main content

Roles and permissions

Everything about people is managed on the "Team" page.

Roles​

RoleBadgeWhat they can do
OwnerOwnerThe account that owns the organization. Can never be demoted or removed.
AdminAdminFull control within the org: manages members, roles, passwords and master data. Holds every permission implicitly.
MemberMemberThe default. Read-write on the org's project data — day-to-day logging works out of the box, no grants needed.
Project adminN projectsA member with full control of specific projects — granted per project from Team → Project admins or at invite time.

Safety rails, enforced server-side: the owner can't be demoted or removed, you can't demote or remove yourself, and an org can never be left without at least one admin.

Granular permissions​

Admins can grant members extra, scoped capabilities from Team → "Permissions" on any member. The modal is scope-first: pick Org-wide ("applies across every project") or a single project ("org-wide grants still apply on top"), then flip toggles.

Two permissions gate real product areas today:

  • "Manage mechanic jobs" — create, edit, assign and close jobs on the Mechanics page, and edit the mechanics settings, categories and job templates. Members without it see the job board read-only.
  • "Manage events" — manage event crew, travel and crew templates.

The modal also offers quick-grant presets — additive bundles for common profiles: Mechanic, Race engineer, Team manager.

:::info Members can already do the day-to-day ICRX is deliberately not admin-locked for everyday work: any member can log laps and measurements and curate the org's own categories and tracks. Granular permissions add control where teams asked for it (jobs, crew) — more areas will move under granular control over time. :::

Adding people​

Two paths from Team → "Add a team member":

  • "Create account" — email + role + generated password; works instantly, no email server needed. Ideal at the circuit.
  • "Invite link" — a link valid 14 days; the invitee signs in (or signs up) with the invited email and accepts. If the emails don't match, the accept button is disabled with a clear message. Pending invites can be copied or revoked from the Team page.

Password resets are also admin-driven: Team → "Password" sets a new one you hand over ("Password updated. Share it with …").

Was this page helpful?