Role-Based Permissions

This page outlines the permission model used in ASL.
Access to information and functionality is determined by the role assigned to each authenticated user. The permission system ensures that only authorised individuals can view, modify or manage asset-related data.

ASL distinguishes between public access, technician-level access and organisation-level administrative access.

Public Viewer

A user scanning a QR tag without being logged in receives limited, read-only access.
Public Viewers may:

  • View non-sensitive asset information
  • View basic installation details
  • Access general asset history without restricted data

Public Viewers cannot add, edit, or request changes to records.

Verified Technician

Technicians are users associated with a verified company.
Technicians may perform operational tasks depending on the company’s approved trade categories.
A Verified Technician may:

  • View full asset history for the company’s authorised trade categories
  • Add new service records (installation, repair or maintenance)
  • View previous work performed by their own organisation or others
  • Represent their company when submitting service documentation

Technicians cannot modify historical records, manage other users or adjust company settings.

Company Administrator (Admin)

The Admin role is assigned to designated users within a verified company.
Admins hold extended privileges and are responsible for the internal administration of the organisation on the ASL platform.

An Admin may:

  • Manage the company profile and organisational information
  • Invite, approve and deactivate users within the company
  • Assign technician roles to new or existing users
  • Confirm that users are authorised to work within the company’s approved trade categories
  • Manage service provider settings and act as the primary contact point for verification matters

Admins cannot alter service records directly, but they may request corrections through the formal process.

Permission Enforcement

Permissions are enforced at both user and company level:

  • A technician’s allowed actions depend on the company’s verified trade categories
  • Users cannot perform actions outside their role
  • Service records remain immutable except through the official correction request procedure
  • Admins manage users but do not gain expanded editing rights over recorded data

This ensures a consistent and auditable documentation environment across all organisations within ASL.