Access, plans and administration

How access works

Two independent gates decide what you can do in echoMike: your permissions, and your organisation’s plan.

ExplainerAll usersOrganisation administrators

Almost every “why can’t I see that?” question in echoMike has one of two answers, and they have nothing to do with each other. Either you lack a permission, which is about you, or your organisation’s plan doesn’t include the feature, which is about the account. Telling them apart is most of the work, so echoMike deliberately uses different words and different screens for each.

Three things decide what you can do

  1. Which organisation you belong to. Everything is scoped to one organisation, and you cannot switch between organisations inside echoMike — your membership is fixed by whoever added you.
  2. Your permissions. Twenty-one named permissions, each unlocking a specific area. These are set per person.
  3. Your organisation’s plan. Starter, Pro, Business or Enterprise, which decides which whole features exist for anyone in the organisation.

Both gates have to pass. Holding Manage org certificates does nothing if the plan doesn’t include organisation certificates, and being on Business doesn’t help if nobody has given you the permission.

Permissions are named

A permission is a single named capability, like Manage safety or View files. They aren’t ranked, and holding one never implies another — Review job forms and Review safety documents are separate, and holding one does not let you review the other kind of document.

Every permission and exactly what it unlocks is listed in the permissions reference.

Organisation admins hold everything

If your organisation role is admin, you pass every permission check automatically. The individual permission toggles on an admin’s record are ignored entirely — echoMike doesn’t consult them.

This is worth knowing when you’re testing access. An admin cannot experience what a Surveyor sees, so “it works for me” from an admin proves nothing about anyone else.

A role — Manager, Surveyor, Viewer, or one your organisation created — is a named set of permissions. Assigning a role is a convenience: it copies that set onto the person.

That copy is the part people get caught by:

  • Editing a role does not change anyone already assigned to it. echoMike stores the resulting list of permissions on each person, not a pointer back to the role. Change the Manager role today and existing Managers keep exactly what they had. You have to reassign them.
  • The role name shown in the dropdown is worked out backwards. echoMike compares the person’s permissions against each role and shows the one that matches exactly. Toggle a single extra permission and the dropdown switches to Custom — nothing broke, the set simply no longer matches a named role.
  • The three built-in roles are read-only. To make a variant, duplicate one and edit the copy.

To assign or change someone’s role, see add people, teams and assign a role.

Billing is separate, and admin-only

The Manage finance permission covers quotes, purchase orders and invoices — the money you bill your clients. It has nothing to do with your echoMike subscription.

Your subscription, seats and storage live at /organization/billing and are restricted to organisation admins. There is no permission that grants it; this is deliberate, so that an organisation which has run out of seats always has someone able to fix it.

The five ways echoMike says no

Which one you see tells you what to ask for.

What you seeWhereWhat it meansWhat to do
A sidebar item simply is not thereLeft sidebarYou lack the permission that gates it. Trash needs Restore deleted items; Reviews needs Review job forms or Review safety documents; Audits needs View audit logs and the Audit log plan feature.Ask an admin for that permission
A tab is missing from a page you can openSafety, Settings, a job or a projectThe same check, one level down. Safety → Documents needs Manage safety or Review safety documents; a job’s Billing tab needs Manage finance; a job’s Logs tab needs Manage flight logs.Ask an admin for that permission
A card with a shield icon reading Access DeniedA page you opened by link or URLA page-level guard rejected you. The line underneath is “You don’t have permission to view this page.”Ask for the permission named in the reference
A red toast titled Permission neededImmediately after clicking somethingThe server refused the action. The body names the permission: “You don’t have permission to manage controlled safety documents and notices.”That sentence names exactly what you need
A padlocked card reading Upgrade required, with a View billing and plans buttonA page or a featureNot a permission at all — your organisation’s plan does not include this.An organisation admin changes the plan
The first four are about you. The fifth is about the account.

Screenshot pending

Open /organization/templates while signed in as a user with the Surveyor role. Capture the full-page card: shield icon, 'Access Denied' heading, and the subtitle line.

Screenshot pending

Trigger any capability-gated mutation as a user who lacks that permission — e.g. try to publish a controlled document without Manage safety. Capture the red toast titled 'Permission needed' with the capability sentence visible.

A few refusals that aren’t about permissions at all

These come from billing state rather than either gate, and each carries its own recovery link:

  • No seat available — the organisation is at its active-user limit.
  • Organisation is read-only — existing data is readable, but changes need an active subscription.
  • Plan limit reached — a quota, usually storage, has been hit.
  • Your account isn’t linked to an organization yet — you have signed in but nobody has added you.

Where permissions are set

Permissions live on each person at /organization/employees. Roles are managed at /organization/templates under Permission roles, which itself needs the Edit permissions permission.

Two things are not set there. Organisation membership — who is in the organisation at all — and the organisation admin role are both managed outside echoMike, in your identity provider. Select your organisation’s name at the top of the sidebar to open that profile.

If something is still missing after you’ve been granted access, reload echoMike — permissions are read when the app starts.

Last reviewed 28 July 2026 · verified against 18e3cb4