Permission Reference
This section is a complete reference for every permission available in SecurityTrax. Use it to understand what each permission controls, what access levels are available, and how to configure groups for common roles.
How permissions work
SecurityTrax uses a layered permission system. Permissions are granted at three levels:
- Company — the baseline for all users in the company.
- Location — overrides that apply to users at a specific office location.
- Group — role-based grants assigned to users at locations (e.g., "Tech - Install", "Billing Clerk").
The most permissive layer wins. If any layer grants access, the user has it. There are no explicit deny rules — the absence of a grant is the deny.
In practice, groups are the primary tool for day-to-day permission management.
Access levels
Each permission supports one or more access levels:
| Level | What it means |
|---|---|
| View | See the data or page. |
| Create | Add new records. |
| Modify | Edit existing records. |
| Delete | Remove records. |
| Yes | A simple on/off toggle (used for role flags, restrictions, and feature access). |
Some permissions support all four VCMD levels. Others are Yes-only toggles — you either have the permission or you don't.
Permission categories
The permission editor organizes permissions into these top-level sections (shown in this order). This reference documents the same permissions; where an editor section combines more than one group, the links below point to each part.
- Administration — Organization, content management, equipment catalog, accounting settings, licenses, and system integrations.
- Customers — Customer record access, page sections, confidential fields, financial features, central station providers, and visibility restrictions.
- Leads — Lead record access, page sections, confidential fields, and lead-specific features.
- Reports — Access to the reports section and individual report types.
- Company Wide Pages — consolidated company-wide pages for Accounting, Tickets, and Work Orders. These permissions don't grant access to any additional information — they only open the consolidated page. The records shown there are still gated by the per-customer permissions in the Customers section.
- Roles & Restrictions — Role designations (tech, sales rep, lead rep), assignability flags, time-off scheduling, inventory access, and user-profile restrictions.
- Schedulers — Scheduling for sales and tech appointments, both on the scheduler pages and directly on customer and lead records.
- SecurityTrax Intelligence — AI-powered assistant, assists, and automations.
Confidential fields
Permissions marked with a lock icon control access to sensitive data (SSN, credit card numbers, bank accounts, etc.). These fields are hidden by default after initial entry. Only grant confidential field permissions to users who need to see the data — typically billing staff and management.
Restrictions
Restriction permissions work in reverse — enabling them limits what a user can do. For example, "Only View If Marked As Sales Rep" restricts the user to seeing only customers where they are the assigned sales rep. The All-Access group is automatically exempt from all restrictions.
Common role examples
Here are typical permission configurations for common roles:
Office Manager: Administration Page, most Content Management permissions, User Accounts, Permission Groups, all Customer and Lead permissions except confidential fields.
Billing Clerk: Customers (View), Billing Information, Invoices, Payments, Payments Processing, Credit Card Details, Bank Account Details, Company Accounting, Receivables.
Sales Representative: Is A Sales Representative, Can Have Sales Appointments Assigned, Customers (View/Create/Modify), Leads (full), Contact Information, Sale Information, Notes & Tickets, Messages.
Technician: Is A Technician, Can Have Work Orders Assigned, Customers (View), Installation & Equipment Information, Equipment, Notes & Tickets, Work Orders, View Personal Inventory.
These are starting points — adjust based on your company's needs and workflows.