Skip to content

User Roles

Siteflo uses role-based access control to determine what each user can see and do. Every user is assigned one role, and each role has a defined set of permissions and property access scope.

Entry-level role for property staff members.

  • Property Access: One assigned property only.
  • Can: View and create incidents at their property.
  • Cannot: Edit, delete, or restore incidents. Cannot mark incidents as critical.

Manages day-to-day operations at a single property.

  • Property Access: One assigned property.
  • Can: View, create, edit, delete, and restore incidents. Mark incidents as critical. View deleted incidents. Access property dashboards and summaries.
  • Best for: Property managers responsible for on-site safety and compliance.

Oversees multiple properties within a region.

  • Property Access: Multiple assigned properties.
  • Can: All incident actions across assigned properties.
  • Best for: Regional managers who need visibility across a portfolio of properties.

Executive-level role with organization-wide access.

  • Property Access: All properties.
  • Can: All incident actions across all properties.
  • Best for: Executives and senior leadership needing full organizational visibility.

Critical Incident Response Team member.

  • Property Access: All properties.
  • Can: All incident actions across all properties. Receives notifications when incidents are marked critical.
  • Best for: Staff dedicated to responding to serious or escalated incidents.

Full system access including user and configuration management.

  • Property Access: All properties.
  • Can: Everything, including user management and role assignment.
  • Best for: IT staff or operations leads responsible for system configuration.

Limited access for third-party organizations such as counseling services or social workers.

  • Property Access: Assigned properties only.
  • Can: View incidents at assigned properties.
  • Cannot: Create, edit, delete, or manage incidents in any way.
  • Best for: Outside organizations that need read-only visibility into incident reports.
PermissionSite StaffSite ManagerRegional SupervisorDirectorCIRT MemberSystem AdminExternal Partner
View incidentsYesYesYesYesYesYesYes
Create incidentsYesYesYesYesYesYesNo
Edit incidentsNoYesYesYesYesYesNo
Delete incidentsNoYesYesYesYesYesNo
Restore incidentsNoYesYesYesYesYesNo
Mark criticalNoYesYesYesYesYesNo
View deletedNoYesYesYesYesYesNo
Manage usersNoNoNoNoNoYesNo

All incident actions are scoped to the user’s property access. Even if a role has the incidents:read permission, the user can only view incidents for properties they are assigned to.

RoleProperties
Site Staff1 assigned property
Site Manager1 assigned property
Regional SupervisorMultiple assigned properties
DirectorAll properties
CIRT MemberAll properties
System AdministratorAll properties
External PartnerMultiple assigned properties