The "Acknowledge alerts" capability deserves a special note: turning it OFF makes a role notify-only. Members still receive alerts for their territory, but they cannot acknowledge — and so cannot stop the escalation. Teams use this for junior roles that should know a room is hot without carrying the responsibility of declaring it handled.
Every role is five yes/no answers. That's the whole model — there are no hidden tiers behind it.
Seniority: the order of roles on this page is a ranking, and member management respects it. Someone whose role can manage the organization may only add, edit, remove or invite members whose role sits at or below their own — a District Manager with org-management can run their people without being able to touch the SVPs or the safety team above them — and can only assign roles at or below their own level. The organization also refuses to remove or demote its last org-managing member, so nobody can lock everyone out.
What a role can't do, it can't half-do: pages render read-only for roles without the matching switch. A local manager who can only acknowledge alerts sees a unit's details as plain facts — no editable fields whose save would be refused anyway — and the page says which capability edits would need.
| Capability | Grants |
|---|---|
| Manage organization | Roles, regions, markets, people, import, escalation, branding |
| Manage locations | Creating and editing stores and their contacts |
| Manage units | Adding, configuring and assigning devices |
| Acknowledge | Responding to an active alert and stopping escalation |
| See everything | Viewing the whole organization rather than only an assigned territory |
New organizations start with six roles — Org Admin, Safety Executive, Regional VP, Safety Manager, District Manager, Local Manager — because a blank page is a worse starting point than a reasonable guess. They are ordinary roles: rename them, change their switches, delete the ones that don't match how you're organized, add your own.
