Roles and Permissions
Brikly uses a role-based access model to control what each team member can see and do. There are four roles, each with a different level of access.
The four roles
Owner
The Owner is the person who created the workspace. There is one Owner per workspace. Owners have full control over everything - billing, team management, site configuration, and all operational features.
Admin
Admins are trusted team members who can manage day-to-day operations across the workspace. They have almost the same access as the Owner, including managing billing and the subscription. They manage members and viewers, but they cannot make someone an admin, change an admin's role, remove an admin or transfer ownership.
Member
Members are the core operational users - chefs, kitchen managers, and procurement staff who work with recipes, invoices, and costings daily. They can create and edit operational data, connect and sync integrations, and submit bills to your accounting software. They cannot disconnect an integration, change workspace settings or manage other users. Only owners and admins can add, edit or remove a site.
Viewer
Viewers have read-only access. They can see recipes, costings, and reports but cannot create, edit, or delete anything. They can see whether each integration is connected, but cannot connect, sync or test one, and cannot submit bills to your accounting software. This role is ideal for stakeholders who need visibility without the ability to make changes.
Permission table
| Action | Owner | Admin | Member | Viewer |
|---|---|---|---|---|
| Workspace & Billing | ||||
| Manage billing and subscription | Yes | Yes | - | - |
| Transfer workspace ownership | Yes | - | - | - |
| Delete workspace | Yes | - | - | - |
| Team Management | ||||
| Invite members and viewers | Yes | Yes | - | - |
| Change a member's or viewer's role (between member and viewer) | Yes | Yes | - | - |
| Remove members and viewers | Yes | Yes | - | - |
| Invite an admin, or make someone an admin | Yes | - | - | - |
| Change an admin's role or remove an admin | Yes | - | - | - |
| Resend or cancel an invitation for an admin | Yes | - | - | - |
| Site Management | ||||
| Add / edit / remove sites, including switching one on or off | Yes | Yes | - | - |
| Configure site settings | Yes | Yes | - | - |
| Change opening hours and add or remove closed dates | Yes | Yes | - | - |
| Suppliers | ||||
| Add / edit suppliers | Yes | Yes | Yes | - |
| Delete suppliers | Yes | Yes | - | - |
| View suppliers | Yes | Yes | Yes | Yes |
| Ingredients | ||||
| Add / edit ingredients | Yes | Yes | Yes | - |
| Delete ingredients | Yes | Yes | - | - |
| View ingredients | Yes | Yes | Yes | Yes |
| Recipes & Dishes | ||||
| Create / edit recipes | Yes | Yes | Yes | - |
| Delete recipes | Yes | Yes | - | - |
| View recipes and costings | Yes | Yes | Yes | Yes |
| Invoice Processing | ||||
| Upload invoices | Yes | Yes | Yes | - |
| Review and confirm invoices | Yes | Yes | Yes | - |
| Submit bills to accounting software | Yes | Yes | Yes | - |
| Delete invoices | Yes | Yes | - | - |
| View invoice history | Yes | Yes | Yes | Yes |
| Reports | ||||
| View reports and dashboards | Yes | Yes | Yes | Yes |
| Export data | Yes | Yes | Yes | - |
| Integrations | ||||
| Connect or reconnect integrations | Yes | Yes | Yes | - |
| Sync, test and change integration settings | Yes | Yes | Yes | - |
| Disconnect integrations, including Gmail and SwitchBot | Yes | Yes | - | - |
| View integration status | Yes | Yes | Yes | Yes |
StaffBrik's payroll sync is the exception to the integrations rows above: the Keep in sync with Xero setting and the Payroll changes tab are for owners and admins only. See Importing from Payroll.
A few other StaffBrik actions are for owners and admins only:
- StaffBrik settings - members can see them, and can add and edit staff roles, but only owners and admins can change the settings themselves. See Configuring StaffBrik.
- Linking a Xero record to an existing team member in the Sync Xero wizard. Members can still import new people.
- Kiosks - pairing a kiosk, seeing the Kiosk devices list in Settings > Locations, unpairing a kiosk (from Settings or on the tablet itself), and setting or removing staff kiosk passcodes. See Kiosk Devices.
- Withdrawing an open shift. Members can post, edit and convert open shifts, but only owners and admins can withdraw one.
- Team App access levels - only an owner can give someone owner access, and only an owner or admin can give someone manager access. See Access Levels.
- Team App access and web accounts - turning someone's Team App access on or off, and linking or unlinking their web account. See Team App Access and Web Account.
- Deleting pay rates. Members can schedule and edit rates. See Scheduling and Changing Rates.
- Deleting working patterns. Members can add and edit them.
- Replacing shifts in Copy Week - the Replace shifts already on that week option. Members can still copy a week. See Copy Week.
- Applying a new break policy to shifts ahead, as part of changing StaffBrik settings. See Break Policy.
- Giving back approved time off when logging an absence on booked holiday. Any manager can give back days still pending. See Sickness on Booked Time Off.
- Chat channels and Team App settings on the web - creating channels, managing their members, renaming and archiving them, and the Team App's logo, colour and group setting. See Chat and Channels.
Viewers can see StaffBrik but change nothing: for example, they do not see Add Time Off, or Edit on an employee's holiday balance.
A few SafetyBrik actions are for owners and admins only too:
- Opening hours and closed dates in Settings > Locations. Members and viewers can see them. See Opening Hours and Closed Dates.
- Mark closed today, and its Undo, on the SafetyBrik dashboard and Checklists page. See Closed days.
- Cancelling a one-off checklist. See One-off checklists.
- Turning a checklist off or back on.
- Deleting SafetyBrik records such as checklist templates and equipment. Members can create and edit them.
When a Brik is still being set up
CostingBrik, StaffBrik, SafetyBrik and StockBrik each have a short setup the first time they are opened. Owners, admins and members are taken through it. Setup is not something a viewer can do, so a viewer who opens one of these Briks before its setup is finished sees a short note instead:
Your team is still setting up CostingBrik. Ask an owner or admin to finish it.
The note has a link back to Home. Everything that is ready, such as Home, Settings and any Brik that is already set up, works as normal. Once the setup is finished, the viewer sees the Brik like everyone else.
MenuBrik's setup is for owners and admins only. Members and viewers see MenuBrik as usual while it is being set up.
Inviting users
To add a team member to your workspace:
- Go to Settings > Team.
- Click Invite Member.
- Enter the person's email address.
- Select a role from the dropdown. Admins can invite members and viewers; only an owner can invite an admin.
- Click Send Invite.
The invitee receives an email with a link to join the workspace. Once they accept, they appear in the team list with the role you assigned.
Invitations expire after 7 days. If the invite is not accepted in time, you can resend it from the Team settings page. Only an owner can resend or cancel an invitation for an admin.
Changing a user's role
Owners can change anyone's role except their own. Admins can move members and viewers between those two roles. Only an owner can make someone an admin or change an admin's role. To change a role:
- Go to Settings > Team.
- Find the user in the list.
- Click the role dropdown next to their name.
- Select the new role.
- The change takes effect immediately.
Downgrading an Admin to Member removes their ability to manage the team, change sites and disconnect integrations. Downgrading anyone to Viewer removes their ability to change anything, including connecting, syncing or testing integrations and submitting bills. Make sure this is intentional before making the change.
Best practices
- Use the principle of least privilege - assign the minimum role needed for each person's responsibilities.
- Keep the Owner role secure - only the business owner or a senior director should hold this role.
- Use Viewer for stakeholders - investors, accountants, or managers who need to see reports but should not change operational data.
- Assign Admin sparingly - one or two Admins alongside the Owner is usually sufficient.