A role is a bundle of permissions. Every person gets one or more roles, and the permissions of those roles decide which areas they see in the navigation, which buttons they are offered and what they may do at the terminal. Log+Key comes with three standard roles – User, Admin and Owner – and since the October 2026 release you create your own roles yourself and grant each permission individually. Everything this documentation says about “admins” or “users” describes the standard roles; your own roles can differ as much as you like.
Where you manage roles
Open Settings and scroll to the section Role Management. It lists all roles of your organisation, the button Add Role and the button Manage permissions, which opens the permission matrix.
This section is available to people with the permission Configure Roles and Permissions – among the standard roles, only the Owner has it.
Creating a role
- Click Add Role and enter a name, for example “Schichtleitung” (shift lead).
- Confirm with Add. Log+Key opens the permission matrix right away, where the new role appears as its own column – without a single permission yet.
Granting permissions
Manage permissions opens the matrix: one row per permission with a short explanation, one column per role. Tick or untick the boxes and click Save at the bottom; Back leaves the page without saving. Permissions take effect immediately, including for people who are signed in right now.
Two tips from practice:
- Never remove Configure Roles and Permissions from your own role – Log+Key warns about it because you would lock yourself out.
- Permissions called “manage” include viewing. A role with Manage Objects does not need View Objects on top.
The complete matrix with every permission:
Assigning roles
A person gets their roles in the user form – when being created or via Edit – in the Roles field. The field appears as soon as at least one access type (browser or terminal) is enabled and lists every role of your organisation. A person can hold several roles at once.
The three standard roles
- User – the everyday work with objects: see, take, return, take over and exchange objects, comments and return deadlines in the browser, print receipts, conduct inventories, read the history, maintain their own profile.
- Admin – everything a User can do, plus administration: create, edit, archive and assign objects, email receipts, signatures and the extended views at the terminal, create and complete inventories, users, contacts, types, locations, tags and settings.
- Owner – everything an Admin can do, plus role management and Billing & Subscription. The Owner is the person responsible for the contract with Log+Key.
The table below shows which standard role holds which permission. A new role starts empty – the quickest way is to orient yourself on a standard role and tick only what you really need. The demo role “Schichtleitung” in the screenshots, for example, may book objects for others, send receipts and see all take-outs at the terminal, but cannot manage master data.
Every permission at a glance
The default assignment (✓ = granted) of the three standard roles, grouped by area:
Objects
| Permission | Allows … | User | Admin | Owner |
|---|---|---|---|---|
| View Objects | see all objects, but not edit, take or return them | ✓ | – | ✓ |
| Manage Objects | create, edit and delete objects and link tags | – | ✓ | ✓ |
| Take/Return Objects | take out and return objects | ✓ | ✓ | ✓ |
| Only Own Objects | see only one’s own objects in the browser | – | – | – |
| Archive | archive objects | – | ✓ | ✓ |
| Dearchive | make archived objects usable again | – | – | – |
| Object Exchange | perform an object exchange | ✓ | ✓ | ✓ |
| Object Assignment | book takes and returns for other people | – | ✓ | ✓ |
| Object Assignment on Details Page | a simple assignment directly on the detail page | – | – | ✓ |
| Object Transfers | take over objects someone else holds | ✓ | ✓ | ✓ |
Take-out and return in the browser
| Permission | Allows … | User | Admin | Owner |
|---|---|---|---|---|
| Signatures in Browser | offer a signature when taking and returning | ✓ | ✓ | ✓ |
| Signatures Required in Browser | require a signature in the browser | – | – | – |
| Return Deadline in Browser | set a return deadline when taking | ✓ | ✓ | ✓ |
| Take/Return Comment | comment on takes and returns | ✓ | ✓ | ✓ |
| Edit Custom Fields | change custom fields during take and return, if configured | ✓ | ✓ | ✓ |
| Custom Fields Must Be Confirmed | confirm custom fields in a dialog at the terminal | – | – | – |
| Print Receipts | print receipts | ✓ | ✓ | ✓ |
| Send Email Receipts | send PDF receipts by email | – | ✓ | ✓ |
Terminal
| Permission | Allows … | User | Admin | Owner |
|---|---|---|---|---|
| Signatures in Terminal | offer a signature at the terminal | – | ✓ | ✓ |
| Signatures Required in Terminal | require a signature at the terminal | – | – | – |
| Return Deadline in Terminal | set a return date at the terminal | – | ✓ | ✓ |
| Terminal Comment | comment at the terminal | ✓ | ✓ | ✓ |
| All Taken in Terminal | the “All taken” view at the terminal | – | ✓ | ✓ |
| All Objects in Terminal | the “All objects” view at the terminal | – | ✓ | ✓ |
| External Signatures | use an external tablet for signatures | – | – | – |
Inventory
| Permission | Allows … | User | Admin | Owner |
|---|---|---|---|---|
| Manage Inventories | create, conduct and complete inventories | – | ✓ | ✓ |
| Conduct Inventories | conduct inventories, but not create or complete them | ✓ | – | ✓ |
| View Inventories | view inventories only | – | – | ✓ |
History
| Permission | Allows … | User | Admin | Owner |
|---|---|---|---|---|
| View History | see the history | ✓ | ✓ | ✓ |
| Device Information | show device information | – | ✓ | ✓ |
| Add Signature Retroactively | add a signature to history entries later | – | ✓ | ✓ |
| Archive Comment | comment when archiving | – | ✓ | ✓ |
| User Entries in History | show additional entries about sign-in and user management (two separate permissions) | – | ✓ | ✓ |
Administration
| Permission | Allows … | User | Admin | Owner |
|---|---|---|---|---|
| View Types | show types in the object list and inventory | – | – | ✓ |
| Manage Types | create, edit and delete types | – | ✓ | ✓ |
| Edit Tags | see the tag overview and edit tags | – | ✓ | ✓ |
| Manage Users | create, edit and delete users, reset PINs and passwords | – | ✓ | ✓ |
| Edit Own Profile | edit one’s own profile | ✓ | ✓ | ✓ |
| PIN Authorization Active | switch PIN prompts and PIN fields on or off | ✓ | ✓ | ✓ |
| Manage Contacts | create, edit and delete contacts | – | ✓ | ✓ |
| View Contacts | see contacts | – | – | ✓ |
| Manage Settings | open and change the settings | – | ✓ | ✓ |
| Configure Roles and Permissions | create roles and grant permissions – careful not to lock yourself out | – | – | ✓ |
| Manage Locations | create, edit and delete locations | – | ✓ | ✓ |
| Customize Table Display | arrange table columns for oneself | ✓ | ✓ | ✓ |
| Manage Subscription and Plan | open Billing & Subscription and change the subscription | – | – | ✓ |
What permissions change in the interface
- Navigation: areas appear only with the matching permission – Users with Manage Users, Contacts with View Contacts or Manage Contacts, Types with Manage Types, Locations with Manage Locations, Tags with Edit Tags, Settings with Manage Settings, Billing & Subscription with Manage Subscription and Plan.
- Buttons and actions: Add, Edit, Archive and Assign object hang on the corresponding permissions; without Manage Objects the object list has no Add button.
- Terminal: the views All taken and All objects and the switches for signature and email receipt in the confirmation dialog only appear with the respective terminal permissions.
Related guides
- Setting user roles – assigning roles, location access
- Adding users
- Settings and Users
- Billing & Subscription – what the Owner sees in addition