Roles & access
Every person in Opzaco has exactly one role. The role decides what they see and what they can do, and it is checked on the server from their account record on every single request — never taken from the device.
The roles
- Worker
- Field crew. Scans QR codes, fills out service forms, submits logs, views their own history, and — if enabled — asks the manual and submits receipts. Nothing else.
- Client
- Read-only. Signs in to the client portal and sees service records for only the assets assigned to them. Cannot change anything.
- Supervisor
- Day-to-day manager. Everything a worker can do, plus properties, assets, forms, the dashboard, all logs, and inviting workers and clients. Cannot deactivate staff.
- Owner
- Account administrator. Full administration of the organization — assets, staff (including deactivation), dashboard, organization settings, AI controls, and billing.
- Platform support
- Opzaco itself. Cross-organization access for troubleshooting. When support switches into your organization that switch is written to your audit trail, as is every photo or document they open — individual page views are not recorded separately.
Who can invite whom
A person can only ever create an account with a role strictly below their own:
- A supervisor can invite workers and clients.
- An owner can invite supervisors, workers, and clients.
- Only Opzaco platform support can create an owner. An owner cannot create another owner.
The shareable QR / link invite can only ever create a worker account. Supervisors, owners, and clients must be invited by email, because those roles need a verified email address.
Roles do not change
There is no “change someone’s role” button in your dashboard. A role is set when the account is created, and nothing in the manager-facing app edits it afterwards — which is the single most effective guard against accounts quietly accumulating privileges over the years.
Role changes are therefore not self-service. Opzaco support can change a role for you from the internal admin console, and every such change is written to your audit trail. Ask them rather than deactivating and re-inviting, which can fail if the person already holds an account on that email address.
Removing access
Deactivating a staff member is an owner-onlyaction. It takes effect on that person’s very next request — every device they are signed in on stops working immediately.
Their past service logs stay exactly where they are, with their name still attached. Records are never rewritten by a staffing change.
Organization isolation
Every query in Opzaco filters by the caller’s organization, which is re-resolved from the database on each request. In practice one client does not see another’s properties, assets, workers, logs, or photos. The only exception is Opzaco platform support, whose switch into your organization is logged — see Security & your data.