Reading this matrix
Section 17.2 introduces the three account tiers (Client, Partner, Enterprise) and their three role levels (superauditor, admin, superadmin), plus a summary of where a tier’s access differs from the general pattern. This section breaks that same information down per individual role, area by area, for all nine roles.
Two things from section 17.2 carry over unchanged here:
- Enterprise superadmin bypasses permission checks entirely and has unrestricted access across the whole platform, regardless of what the tables below show for that row.
- Scope still widens with tier — the “Full” or “Read” access shown below applies only within that role’s own scope (its own account, or its own account plus everything under it).
“Full” means read/write access. “Read” means read-only. “N/A” means the area is not visible in the sidebar for that role at all.
Client tier
| Area | Superauditor | Admin | Superadmin |
|---|---|---|---|
| Dashboard | Read | Full | Full |
| Analytics | Read | Full | Full |
| Stations | Read | Full | Full |
| Locations | Read | Full | Full |
| Private Drivers | Read | Full | Full |
| Authorizations/RFID Cards | Read | Full | Full |
| Tariffs | Read | Full | Full |
| Charging Profiles | Read | Full | Full |
| Load Balancing | Read | Full | Full |
| User Management | Read | Full | Full |
| Map | Read | Read | Read |
| Driver Invoices | View only (no download) | View & download | View & download |
| Subscription Invoices & Plans | Read | Read | Read |
| Manage Clients | N/A | N/A | N/A |
| Manage Partners | N/A | N/A | N/A |
| Public Drivers | N/A | N/A | N/A |
| Company Settings | N/A | N/A | N/A |
Partner tier
| Area | Superauditor | Admin | Superadmin |
|---|---|---|---|
| Dashboard | Read | Full | Full |
| Analytics | Read | Full | Full |
| Stations | Read | Full | Full |
| Locations | Read | Full | Full |
| Private Drivers | Read | Full | Full |
| Authorizations/RFID Cards | Read | Full | Full |
| Tariffs | Read | Full | Full |
| Charging Profiles | Read | Full | Full |
| Load Balancing | Read | Full | Full |
| User Management | Read | Full | Full |
| Map | Read | Read | Read |
| Driver Invoices | View only (no download) | View & download | View & download |
| Subscription Invoices & Plans | Read | Full | Full |
| Manage Clients | Read | Full | Full |
| Manage Partners | N/A | N/A | N/A |
| Public Drivers | N/A | N/A | N/A |
| Company Settings | N/A | Full | Full |
Enterprise tier
| Area | Superauditor | Admin | Superadmin |
|---|---|---|---|
| Dashboard | Read | Full | Full |
| Analytics | Read | Full | Full |
| Stations | Read | Full | Full |
| Locations | Read | Full | Full |
| Private Drivers | Read | Full | Full |
| Authorizations/RFID Cards | Read | Full | Full |
| Tariffs | Read | Full | Full |
| Charging Profiles | Read | Full | Full |
| Load Balancing | Read | Full | Full |
| User Management | Read | Full | Full |
| Map | Read | Read | Read |
| Driver Invoices | View only (no download) | View & download | View & download |
| Subscription Invoices & Plans | Read | Full | Full |
| Manage Clients | Read | Full | Full |
| Manage Partners | Read | Full | Full |
| Public Drivers | N/A | N/A | Full |
| Company Settings | Read | Full | Full |
Notes
- Public Drivers is available only to the single top enterprise role (superadmin) — not enterprise-admin, and not enterprise-superauditor — and only where your tenant has the feature enabled.
- Document 1 also flags an inconsistency in the backend’s internal
role-ordering list:
partner-superauditorandenterprise-superauditorrank above some higher-privilege roles in that list. This does not change the read/write access shown in the tables above — superauditor roles are read-only everywhere — but it may affect other hierarchy-dependent checks, such as which roles can be assigned when editing a user (see section 17.3).