Log+Key

Documentation Users

Managing roles and permissions

Create your own roles and grant permissions: the role management in the settings, the permission matrix, the three standard roles User, Admin and Owner, and every permission at a glance.

A role is a bundle of permissions. Every person gets one or more roles, and the permissions of those roles decide which areas they see in the navigation, which buttons they are offered and what they may do at the terminal. Log+Key comes with three standard roles – User, Admin and Owner – and since the October 2026 release you create your own roles yourself and grant each permission individually. Everything this documentation says about “admins” or “users” describes the standard roles; your own roles can differ as much as you like.

Where you manage roles

Open Settings and scroll to the section Role Management. It lists all roles of your organisation, the button Add Role and the button Manage permissions, which opens the permission matrix.

Role management lives in the settings.

This section is available to people with the permission Configure Roles and Permissions – among the standard roles, only the Owner has it.

Creating a role

  1. Click Add Role and enter a name, for example “Schichtleitung” (shift lead).
  2. Confirm with Add. Log+Key opens the permission matrix right away, where the new role appears as its own column – without a single permission yet.
A new role only needs a name – the permissions follow in the matrix.

Granting permissions

Manage permissions opens the matrix: one row per permission with a short explanation, one column per role. Tick or untick the boxes and click Save at the bottom; Back leaves the page without saving. Permissions take effect immediately, including for people who are signed in right now.

Every role is a column, every permission a row.

Two tips from practice:

  • Never remove Configure Roles and Permissions from your own role – Log+Key warns about it because you would lock yourself out.
  • Permissions called “manage” include viewing. A role with Manage Objects does not need View Objects on top.

The complete matrix with every permission:

All permissions at a glance – the ticks show the default assignment plus the demo role Schichtleitung.

Assigning roles

A person gets their roles in the user form – when being created or via Edit – in the Roles field. The field appears as soon as at least one access type (browser or terminal) is enabled and lists every role of your organisation. A person can hold several roles at once.

The Roles field lists every role of the organisation – including the ones you created yourself.

The three standard roles

  • User – the everyday work with objects: see, take, return, take over and exchange objects, comments and return deadlines in the browser, print receipts, conduct inventories, read the history, maintain their own profile.
  • Admin – everything a User can do, plus administration: create, edit, archive and assign objects, email receipts, signatures and the extended views at the terminal, create and complete inventories, users, contacts, types, locations, tags and settings.
  • Owner – everything an Admin can do, plus role management and Billing & Subscription. The Owner is the person responsible for the contract with Log+Key.

The table below shows which standard role holds which permission. A new role starts empty – the quickest way is to orient yourself on a standard role and tick only what you really need. The demo role “Schichtleitung” in the screenshots, for example, may book objects for others, send receipts and see all take-outs at the terminal, but cannot manage master data.

Every permission at a glance

The default assignment (✓ = granted) of the three standard roles, grouped by area:

Objects

PermissionAllows …UserAdminOwner
View Objectssee all objects, but not edit, take or return them✓–✓
Manage Objectscreate, edit and delete objects and link tags–✓✓
Take/Return Objectstake out and return objects✓✓✓
Only Own Objectssee only one’s own objects in the browser–––
Archivearchive objects–✓✓
Dearchivemake archived objects usable again–––
Object Exchangeperform an object exchange✓✓✓
Object Assignmentbook takes and returns for other people–✓✓
Object Assignment on Details Pagea simple assignment directly on the detail page––✓
Object Transferstake over objects someone else holds✓✓✓

Take-out and return in the browser

PermissionAllows …UserAdminOwner
Signatures in Browseroffer a signature when taking and returning✓✓✓
Signatures Required in Browserrequire a signature in the browser–––
Return Deadline in Browserset a return deadline when taking✓✓✓
Take/Return Commentcomment on takes and returns✓✓✓
Edit Custom Fieldschange custom fields during take and return, if configured✓✓✓
Custom Fields Must Be Confirmedconfirm custom fields in a dialog at the terminal–––
Print Receiptsprint receipts✓✓✓
Send Email Receiptssend PDF receipts by email–✓✓

Terminal

PermissionAllows …UserAdminOwner
Signatures in Terminaloffer a signature at the terminal–✓✓
Signatures Required in Terminalrequire a signature at the terminal–––
Return Deadline in Terminalset a return date at the terminal–✓✓
Terminal Commentcomment at the terminal✓✓✓
All Taken in Terminalthe “All taken” view at the terminal–✓✓
All Objects in Terminalthe “All objects” view at the terminal–✓✓
External Signaturesuse an external tablet for signatures–––

Inventory

PermissionAllows …UserAdminOwner
Manage Inventoriescreate, conduct and complete inventories–✓✓
Conduct Inventoriesconduct inventories, but not create or complete them✓–✓
View Inventoriesview inventories only––✓

History

PermissionAllows …UserAdminOwner
View Historysee the history✓✓✓
Device Informationshow device information–✓✓
Add Signature Retroactivelyadd a signature to history entries later–✓✓
Archive Commentcomment when archiving–✓✓
User Entries in Historyshow additional entries about sign-in and user management (two separate permissions)–✓✓

Administration

PermissionAllows …UserAdminOwner
View Typesshow types in the object list and inventory––✓
Manage Typescreate, edit and delete types–✓✓
Edit Tagssee the tag overview and edit tags–✓✓
Manage Userscreate, edit and delete users, reset PINs and passwords–✓✓
Edit Own Profileedit one’s own profile✓✓✓
PIN Authorization Activeswitch PIN prompts and PIN fields on or off✓✓✓
Manage Contactscreate, edit and delete contacts–✓✓
View Contactssee contacts––✓
Manage Settingsopen and change the settings–✓✓
Configure Roles and Permissionscreate roles and grant permissions – careful not to lock yourself out––✓
Manage Locationscreate, edit and delete locations–✓✓
Customize Table Displayarrange table columns for oneself✓✓✓
Manage Subscription and Planopen Billing & Subscription and change the subscription––✓

What permissions change in the interface

  • Navigation: areas appear only with the matching permission – Users with Manage Users, Contacts with View Contacts or Manage Contacts, Types with Manage Types, Locations with Manage Locations, Tags with Edit Tags, Settings with Manage Settings, Billing & Subscription with Manage Subscription and Plan.
  • Buttons and actions: Add, Edit, Archive and Assign object hang on the corresponding permissions; without Manage Objects the object list has no Add button.
  • Terminal: the views All taken and All objects and the switches for signature and email receipt in the confirmation dialog only appear with the respective terminal permissions.

Still have questions?

We’re happy to help.

Write to us — Philip or Chiara will reply personally.