Skip to main content

Projects separate fleets

A project is the top-level container. Every piece of operational data in the platform belongs to exactly one project — every vehicle, component, defect, warranty claim, measurement and inspection report. This is what allows one installation to serve several fleets without them ever seeing each other’s data. The separation is enforced on every request, and a user working in one project cannot reach another project’s records at all. A project has a name, an optional description, and an active flag.

Access is granted per project

Users do not have global permissions. Access is granted as a role within a specific project, and a user can hold different roles in different projects — or no access at all to a project they are not assigned to. A user can also hold several roles in the same project. When they do, their capabilities are the sum of those roles. Someone who is both a Warranty Manager and an Inspector can do everything either role allows.

The roles

Roles are deliberately narrow. Each grants one clearly defined set of capabilities rather than a general seniority level, and they are combined to describe a real job.

Superusers

Superuser is a global flag on the user account itself, not a grant within a project. It allows administering the platform as a whole — creating projects, managing user accounts — and it applies everywhere rather than to one fleet. The practical distinction:
  • Project Admin is complete authority inside one project, granted per project.
  • Superuser is platform-wide, set on the account, and is what creates projects in the first place.