Team members and roles
Invite people, manage members, build custom roles with permissions, and control who can do what in your organization.
Member Management ("View, invite, and manage members, roles, and invitations for this organization.") is where every person and every permission in your organization lives. Three tabs split it: Members, Roles & Positions, and Invitations.
Members
The Members tab lists everyone in the roster with a counter ("{count} members found") and a Refresh members action. The table shows Name, Email, Roles, Status, and Actions. Status reads Online, Last seen {time}, Never seen, or On leave (with "On leave until {date}" and a "{hours}h {type}" balance hint when relevant). Badges mark Owner, Admin, Member, and Me.
A paginator reads "Showing {start} to {end} of {total} items" with a Members per page selector. Empty states are honest: "No members yet. Invite your first member to get started." with an Invite member button.
The member dialog
Opening a member shows Member Overview ("Manage access, roles, security, and recent check-ins.") with several panels:
- User Info: whether the member is Deactivated.
- Roles: the member's assigned roles under Built-in Roles and your custom roles. Helper text explains what you can change ("You can only edit roles that sit below your highest role.", "You need a higher-ranked role to manage other custom roles.").
- Details: Joined and Last Online.
- Security: Face Check-in Setup Status with Set Up / Not Set Up, the Set up on date, and a Manage Setup action (or "No face check-in setup found for this user.").
- Deletion Request: if the member asked to delete their account, it shows Requested, Reason, and a Business Impact readout (Active Shifts, Recent Time Entries, Pending Approvals) plus an admin-notes field and Reject / Approve.
- Member Management: Remove from Organization, Reactivate Access / Deactivate Access, and Delete Account. A note guards the owner: "Organization owners cannot be deleted manually. Please contact support@shark-force.com."
- Activity: recent check-ins grouped by Location Zone, Face Check-in, and QR Code, each with a status (SUCCESS, SCANNED, FAILED). Empty groups say "No location zone check-ins recorded." and so on.
Each destructive action asks before it runs: Remove Member, Delete Account ("This action cannot be undone and will remove all user data from the system."), Deactivate Account ("The user will not be able to access the system, but their data will be preserved."), and Remove from Organization ("They will lose access to this organization but their account will remain active.").
Roles & Positions
The Roles & Positions tab ("Manage your organization's roles, titles, and departments with a flexible hierarchy.") is where custom roles are built. Roles form a hierarchy you drag to reorder; each role can be a job title, a permission set, or a department.
Building a role
Create Role opens a role with three tabs:
- Display: Role Name, Description, and Role Color.
- Permissions: every permission the role grants, with an All permissions toggle (it only enables permissions your own account has).
- Members: the users assigned to the role, with Add Member to search and assign people. A draft role says "Role not created yet. Save it to create the role, then you can add members to it."
A context menu on each role offers Duplicate Role, Delete Role, and View As {role} ("Preview what this role sees" - a banner lets you browse the app as that role, then Stop viewing as {role}).
The hierarchy rules
Role power flows downward, and the rules are enforced in the UI:
- You can only reorder, duplicate, or delete roles below your highest role.
- You can only assign or edit roles that sit below yours.
- Full Admin Access is a dangerous toggle: enabling it promotes every member on the role to Organization Admin. It asks "Enable Full Admin?" with a warning before it runs.
- View only shows when a role outranks you: "You can only change roles that sit lower than your highest role."
The permission groups
Permissions are grouped by area, each with a plain-English label and description:
| Group | What it covers |
|---|---|
| Administrator | Full Admin Access, Admin Portal Access, Assign Lower Roles to Higher Members. |
| Members | All Members & Invitations, Roles & Positions, Remove Members, and the member-profile tabs (Overview, Attendance, Payroll, Performance, Calendar, Activity). |
| Organization Settings | Update organization profile, branding, and defaults. |
| Check-in | Check-in Tabs (QR / Face / Location Zones), Check-in Systems, Check Members In/Out (audited), Manually Edit Shift (pay-run-locked, audited), View / Enable-Disable / Delete Setups. |
| Shifts | Shifts Tabs, Build & Publish Shifts, Assign Shifts. |
| Reports | Unlock the Reports tab and exports. |
| Finance | Plans & Billing Tabs. |
| Mako | Chat, Company Knowledge, Mako Profile, Mako Notes. |
| Agreements | Assignments, My Signatures (granted to every member by default). |
| Requests | Submit requests (default for all members), View all requests, Approve and handle, Approve own requests, Manage types and policies, Member profile history. |
Invitations
The Invitations tab ("Invite new members to your organization using one of the methods below.") offers three ways in:
- Invite by Email: paste addresses separated by commas, spaces, or new lines, then Send Invites. It reports "Invited
{count}member(s)" and lists failures individually. - Share Invite Code: a code members use to request to join. You can Show invite code, Copy invite code, and Regenerate invite code. A Duration / Expiration setting controls how long it lives, with a warning if you "Set to never expire" ("This is not recommended for security.").
- Import from Spreadsheet: Upload CSV pulls a list of emails; a Confirm & Edit Emails dialog lets you review, add, or remove entries before sending.
Ongoing Invites
An Ongoing Invites panel tracks pending invitations with a status filter (All, Pending, Accepted, Revoked) and a table of Email, Status, Invited By, Invited Since, and Actions. Each row can Re-invite or Revoke; Cancel all clears every pending invitation and regenerates the invite code. All three ask before they run.
Each tab is permission-gated: the roster needs Invite Members, roles need Manage Roles, and invitations need Invite Members. Without them the tab shows a "permission required" message instead of the tools.