Roles and permissions
This page is for the owner deciding who in the office gets which access, and for anyone evaluating how HaulApp protects a company’s data. After reading it you can match each person to a role and know what they will and will not see.
How roles work
Section titled “How roles work”A role is a named set of things a person may do in HaulApp. Every person belongs to a company through a membership, and the membership carries one or more roles.
- A person can hold several roles. A small office often gives one person both Dispatcher and Billing / Reviewer.
- A person can belong to more than one company, with different roles in each. They work in one company at a time.
- HaulApp checks the role on the server for every request. Hiding a button is a convenience; the server check is what enforces access.
- When a role does not allow something, HaulApp answers as if the page does not exist. It does not reveal that the record is there.
The roles
Section titled “The roles”Owner / Admin
Section titled “Owner / Admin”Runs the company in HaulApp. An owner can do everything the other office roles can, plus:
- Connect QuickBooks, turn on accounting writes, and switch automatic invoice submission on or off. See QuickBooks Desktop.
- Investigate an invoice whose QuickBooks outcome is unknown.
- Create and revoke API clients under Settings → Developer, for example the credential that imports your WATMS history.
- Settle how imported WATMS records map onto HaulApp records.
Dispatcher
Section titled “Dispatcher”Runs the day. A dispatcher can:
- Create and change jobs, job quotes and orders.
- Build and change dispatch plans during the day; assignments reach drivers as they are made.
- Add and change customers, sites, suppliers, materials, trucks, drivers and subcontractors.
- Import tickets.
- Read invoices.
A dispatcher cannot review charges, prepare invoices, see payables or reports, or open the QuickBooks screens.
Billing / Reviewer
Section titled “Billing / Reviewer”Turns verified work into money. A billing reviewer can:
- Review tickets and the charges they produce.
- Prepare invoices.
- Work with payables, the amounts HaulApp owes commission recipients.
- Read reports.
- Map, review, approve and queue invoices, bills, customers and vendors for QuickBooks, and cancel or investigate bills, customers and vendors.
- Read orders, customers, sites, materials and trucks.
A billing reviewer cannot dispatch trucks or change jobs, orders, trucks or reference data. They cannot connect QuickBooks or turn on accounting writes.
Driver
Section titled “Driver”Uses the driver app on a registered phone or tablet. A driver can:
- Acknowledge the assignments dispatch sends.
- Record loads and what happens on them.
- Share the truck’s position while working.
A driver never sees the office screens.
Service identities
Section titled “Service identities”Two access levels exist for software, not people. You choose them when an owner creates an API client under Settings → Developer:
- Dispatch gives a program the dispatcher’s access. The WATMS import uses it.
- Telematics ingest lets a GPS tracker service submit truck positions and nothing else.
An API client can never hold the Owner / Admin role.
What each role can do
Section titled “What each role can do”| Action | Owner / Admin | Dispatcher | Billing / Reviewer | Driver |
|---|---|---|---|---|
| Create and change jobs, job quotes and orders | Yes | Yes | No | No |
| Run dispatch plans | Yes | Yes | No | No |
| Change customers, sites, materials, trucks, drivers | Yes | Yes | No | No |
| Import tickets | Yes | Yes | No | No |
| Review tickets and charges | Yes | No | Yes | No |
| Prepare invoices | Yes | No | Yes | No |
| Read invoices | Yes | Yes | Yes | No |
| Payables and reports | Yes | No | Yes | No |
| Queue records for QuickBooks | Yes | No | Yes | No |
| Connect QuickBooks and turn on writes | Yes | No | No | No |
| Create API clients | Yes | No | No | No |
| Accept assignments and record loads | No | No | No | Yes |
Your data stays in your company
Section titled “Your data stays in your company”Every record in HaulApp belongs to exactly one company. One company’s customers, tickets, invoices and settings are never visible to another company.
- When you sign in, HaulApp works out which company you are acting for from your own memberships on the server. A request cannot name a company you do not belong to.
- Every read and every change is filtered to that company before HaulApp touches the data.
- If anything about the company does not line up, HaulApp refuses the request rather than guessing.
- HaulApp’s automated tests set up two companies side by side and check that lists, counts, totals and linked records never cross between them.
Not supported yet
Section titled “Not supported yet”- The Customer (read-only) role exists but grants no access today. Customers cannot sign in to see their own jobs or invoices.