Access, plans and administration
Every permission
Every permission, what each one unlocks, and exactly what breaks without it.
Every permission in echoMike, in the order the toggles appear at OrganizationSettingsTemplatesPermission roles. The Without it column is the behaviour you actually see, which is usually a missing menu item rather than an error.
Organisation admins hold every one of them implicitly — see how access works.
Two names for the same permission
echoMike uses one wording on the toggle and a different one in error messages. Both are correct; they appear in different places.
| On the toggle | In an error message |
|---|---|
| Manage org settings | You don’t have permission to manage organization settings. |
| Manage org certificates | You don’t have permission to manage organization certificates. |
| Review job forms | You don’t have permission to review and sign off operational forms. |
| Manage safety | You don’t have permission to manage controlled safety documents and notices. |
| Approve flight-release overrides | You don’t have permission to approve exceptional flight-release overrides. |
Finance
| Permission | Key | What it unlocks | Without it | Built-in roles |
|---|---|---|---|---|
| Manage finance | finance.manage | Quotes, purchase orders and invoices — the Billing tab on both projects and jobs | Those tabs do not render. Does not affect /organization/billing, which is admin-only. | Manager |
Employees
| Permission | Key | What it unlocks | Without it | Built-in roles |
|---|---|---|---|---|
| Manage employees | employees.manage | Mark people as left, link Sage HR, assign vehicles, set a home location. Adding someone to the organisation happens in your identity provider, not here. | The employee roster is read-only to you | Manager |
| Edit permissions | employees.edit_permissions | Changing other people’s permission toggles, and the Permission roles area under Templates | Permission roles is absent from Templates and you cannot alter anyone’s access | None |
Organization settings
| Permission | Key | What it unlocks | Without it | Built-in roles |
|---|---|---|---|---|
| Manage org settings | org_settings.manage | HQ location, VLOS distance, coordinate systems, cancellation reasons and job templates. Also gates Reports, the CAA audit pack, white labelling, flight-currency rules and the review policy. | Settings → Company, Templates and White labelling all show Access Denied, and Reports disappears from the sidebar | Manager |
| Manage integrations | integrations.manage | Connecting and disconnecting Trimble, Sage HR and ABAX, plus DJI log access for other users | Settings → Integrations shows Access Denied | Manager |
Fleet and maps
| Permission | Key | What it unlocks | Without it | Built-in roles |
|---|---|---|---|---|
| View vehicle tracking | vehicle_tracking.view | Live vehicle positions on the map, and /organization/vehicles | Vehicles is hidden from the Organization submenu and vehicles do not appear on the map | Manager, Surveyor |
| Manage equipment | equipment.manage | Adding and editing drones, batteries and kits, and assigning them to projects and jobs | Equipment is hidden from the Organization submenu | Manager |
| Manage flight logs | flights.manage | Uploading DJI logs, the job Logs tab, and recording a flight clearance on a job you are not the assigned pilot for | The Logs tab never appears. If you are not the assigned pilot, recording a clearance fails. | None |
Operations
| Permission | Key | What it unlocks | Without it | Built-in roles |
|---|---|---|---|---|
| Restore deleted items | trash.restore | The Trash sidebar item — restoring and permanently deleting projects and jobs | Trash is invisible, so deleted work looks permanently gone when it is not | None |
| View audit logs | audit.view | The Audits sidebar item | Audits is hidden. It also needs the Audit log plan feature, so the permission alone is not enough. Despite its hint text, this permission does not gate the job Logs tab — that is Manage flight logs. | Manager |
| Review job forms | forms.review | The Reviews sidebar item, and being selectable as a reviewer for pre-flight, on-site, briefing, post-flight, occurrence and RAMS documents | Colleagues cannot pick you as a reviewer. Reviews is hidden too, unless you also hold Review safety documents | Manager |
| Manage safety | safety.manage | Creating controlled documents and revisions, publishing them, promoting a CAA SkyWise alert, and editing Safety → Settings | Safety → Settings is hidden; Safety → Documents is hidden unless you also hold Review safety documents; Promote does not render on a SkyWise alert | Manager |
| Review safety documents | safety.review | The Reviews sidebar item, approving or requesting changes on controlled-document revisions, and read access to Safety → Documents | Revisions cannot be assigned to you for review | Manager |
| Approve flight-release overrides | safety.override | Authorising a named, expiring exception to a blocking readiness check | Blocking checks offer no override. In Enforced mode the button reads Blocked by N checks and stays disabled. | None |
| Manage org certificates | certificates.manage_org | Organisation-scope certificates for other people, and editing certificate templates | Certificates is hidden from the Organization submenu | Manager |
| View all certificates | certificates.view_all | Seeing everyone’s certificates on the calendar and opening them read-only | You see only your own certificates | None |
| Delete control points | control_points.delete | Deleting control points | Control points can be added but not removed | Manager, Surveyor |
Calendars
| Permission | Key | What it unlocks | Without it | Built-in roles |
|---|---|---|---|---|
| Manage org calendars | calendars.manage_org | Creating shared calendars that appear in every employee’s calendar list | You can only create calendars for yourself | Manager |
Files
The three file permissions stack — Upload & edit files is not much use without View files.
| Permission | Key | What it unlocks | Without it | Built-in roles |
|---|---|---|---|---|
| View files | files.view | The project Files tab, and opening or downloading documents | The Files tab does not render at all | Manager, Surveyor, Viewer |
| Upload & edit files | files.edit | Uploading new files, renaming, and editing file details | Files are read-only | Manager, Surveyor |
| Delete files | files.delete | Permanently removing files from a project | No delete action on files | Manager |
The three built-in roles
Built-in roles are read-only. To make a variant, duplicate one and edit the copy.
| Permission | Manager | Surveyor | Viewer |
|---|---|---|---|
| Manage finance | Yes | No | No |
| Manage employees | Yes | No | No |
| Edit permissions | No | No | No |
| Manage org settings | Yes | No | No |
| Manage integrations | Yes | No | No |
| View vehicle tracking | Yes | Yes | No |
| Manage equipment | Yes | No | No |
| Manage flight logs | No | No | No |
| Restore deleted items | No | No | No |
| View audit logs | Yes | No | No |
| Review job forms | Yes | No | No |
| Manage safety | Yes | No | No |
| Review safety documents | Yes | No | No |
| Approve flight-release overrides | No | No | No |
| Manage org certificates | Yes | No | No |
| View all certificates | No | No | No |
| Delete control points | Yes | Yes | No |
| Manage org calendars | Yes | No | No |
| View files | Yes | Yes | Yes |
| Upload & edit files | Yes | Yes | No |
| Delete files | Yes | No | No |
What an organisation admin adds
Being an organisation admin is not a role in this list. Admins bypass every one of these checks. /organization/billing is the only whole page reserved for them — no permission grants billing access. A few individual controls are admin-only too, such as changing a project’s coordinate system and reassigning someone else’s review.
Custom roles
Custom roles are created at OrganizationSettingsTemplatesPermission roles and can hold any combination of them. An organisation can have up to 100. Remember that assigning a role copies its permissions — see how access works for why editing a role later changes nothing for people already assigned to it.
Last reviewed 28 July 2026 · verified against 18e3cb4