Each account in Oribi WorkpassID has one or more permission groups assigned. A permission group determines what a user may see and do in the portal and the app. By combining permission groups wisely, you give employees exactly the access they need - no more and no less.
This article explains which permission groups exist, what each group can do, and how best to use them.
How do permission groups work?
Permission groups are cumulative: when you assign multiple groups to an account, the user receives the sum of all permissions. An employee with both Planning and Operations: Access can therefore add workers and manage passes.
Note: Two permission groups must never be combined with other groups:
App Only - intended exclusively for app access, without portal access
Reports for external parties - intended exclusively for external clients
Combining these groups with other permissions leads to unexpected behaviour and is not supported.
Project visibility
Not every permission group automatically grants access to all projects. There are two models:
Model |
Permission groups |
Explanation |
|---|---|---|
All projects automatically visible |
Organisation management, Administration, Financial Administration |
These users always see all projects in their organisation. |
Only assigned projects |
All other permission groups |
The user must be added to a project as a team member in order to see it. |
This is an important difference: a Planning user, for example, sees only the projects to which they are linked, whereas an Administration user can automatically view all projects.
Two-step verification (2SV)
Some permission groups always require two-step verification, regardless of the organisation setting:
Organisation management
Project management
Enrolment manager
Organisation reports
For all other permission groups, the organisation's 2SV setting applies. If the organisation has made 2SV mandatory, this applies to all users. If 2SV is not mandatory, it is optional for these groups.
For all accounts
Regardless of the permission group assigned, every user can:
Change their own password
View their own account details
Change the portal language
Manage their own 2SV settings
Management and organisation
Organisation management
The most extensive permission group for day-to-day management. Organisation managers are the “administrators” of your organisation in WorkpassID.
Create and edit accounts, and change other users' passwords
View and edit all projects (automatically visible)
Create and archive new projects
Add team members to projects
Manage project security settings
Manage subcontractors (add, edit, view the log)
Set password policy
Manage the denylist
Set exemptions for companies on projects
Manage organisation settings and reports
View the dashboard and manual
Place digital signatures (own and on behalf of others)
Run system diagnostics
2SV: Always required.
Project visibility: All projects automatically visible.
Project management
Intended for employees who create projects and manage project settings, but do not need to administer the entire organisation.
View and edit projects (assigned projects only)
Create and archive new projects
Add team members to projects
Manage project security settings
Set password policy
View forms
2SV: Always required.
Project visibility: Only projects the user has been added to.
Organisation reports
A limited role, specifically for access to reports at organisation level.
View organisation reports
2SV: Always required.
Project visibility: Not applicable (no project access).
Administration
Administration
Suitable for employees who need insight into all project data but do not need to change anything.
View all projects (automatically visible)
Tabs: General, Team members, Workers, Signed forms, Log, Visitors
View person-days
View forms
View the manual
View company project information
2SV: Follows organisation setting.
Project visibility: All projects automatically visible.
Financial Administration
Similar to Administration, but specifically focused on financial information. Has no access to signed forms.
View all projects (automatically visible)
Tabs: General, Team members, Workers
View person-days
View forms
View the manual
View company project information
2SV: Follows organisation setting.
Project visibility: All projects automatically visible.
Planning
The Planning permission group is intended for employees who add workers and visitors to projects.
View projects (assigned projects only)
Tabs: General, Team members, Workers, Signed forms, Log, Visitors
Add workers (CAO (Dutch collective labour agreement) and incidental)
Register visitors and create new visitor passes
Create new companies
View reports
View the dashboard and manual
Place digital signatures
View company project information
2SV: Follows organisation setting.
Project visibility: Only projects the user has been added to.
Operations (construction site roles)
The Operations roles are intended for employees on the construction site. These roles are built hierarchically: each higher role includes all permissions of the role below it.
Operations role hierarchy
Role |
Includes permissions of |
Additional capabilities |
|---|---|---|
Operations: Safe |
— |
Safety module, view projects |
Operations: Access |
Operations: Safe |
Manage passes, register visitors, view attendance |
Operations: Fair |
Operations: Access |
Register and edit workers, add incidental staff, digital signatures |
Operations: Safe
The basic role for construction site employees. Provides access to the safety module.
View projects (assigned projects only)
Use the Safe module
View company project information
Run system diagnostics
2SV: Follows organisation setting.
Project visibility: Only projects the user has been added to.
Operations: Access
Builds on Operations: Safe and adds access management.
All permissions of Operations: Safe
Use the Access module
Create and manage passes
Register visitors and create visitor passes
View attendance
View the visitors tab
2SV: Follows organisation setting.
Project visibility: Only projects the user has been added to.
Operations: Fair
The most extensive construction site role. Builds on Operations: Access.
All permissions of Operations: Access
Use the Fair module
Register and edit workers
Add incidental workers
Place digital signatures
2SV: Follows organisation setting.
Project visibility: Only projects the user has been added to.
Operations employee (being phased out)
This is the original, combined construction site role that grants access to all three modules (Safe, Access, Fair). This role is being gradually replaced by the three Operations roles above.
Existing accounts with this role continue to work, but for new accounts we recommend using the specific Operations roles. This way, you give employees only the permissions they actually need.
2SV: Follows organisation setting.
Project visibility: Only projects the user has been added to.
App Only
Intended exclusively for users who only use the WorkpassID app and do not need access to the portal.
Access to the WorkpassID app
No access to the portal
Important: Never combine this role with other permission groups.
2SV: Follows organisation setting.
Assessor
The Assessor permission group is intended for employees who carry out assessments and tasks.
Carry out assessments
View and manage tasks
View the dashboard
View company project information
2SV: Follows organisation setting.
Project visibility: Only projects the user has been added to.
Enrolment manager
The Enrolment manager permission group is intended for managing subcontractor enrolments (OA). This role has a global scope for editing enrolments, regardless of project membership.
View and edit subcontractor enrolments
View company project information
2SV: Always required.
Project visibility: Global access to enrolments (not tied to project membership).
ACP
The ACP permission group is specifically intended for ACP organisations and provides limited, read-only access.
Create passes
View attendance
2SV: Follows organisation setting.
Project visibility: Only projects the user has been added to.
Reports for external parties
Intended for external clients who only need insight into attendance data.
View attendance (read-only)
Important: Never combine this role with other permission groups.
2SV: Follows organisation setting.
Safety permission groups
The Safety permission groups grant access to the V&G Bouwer and Toolbox modules.
Safety manager
Manages Safety templates and has full access to the Safety modules.
Access to V&G Bouwer and Toolbox
Manage and create templates
Manage Safety plans and documents
2SV: Follows organisation setting.
Safety coordinator
Uses the Safety modules for day-to-day work at project level.
Access to V&G Bouwer and Toolbox
Manage Safety plans
View attendance
2SV: Follows organisation setting.
MediaHub permission groups
The MediaHub permission groups grant access to the MediaHub module, which lets you create and manage digital booklets and documentation.
MediaHub Admin
Full administrative access to the MediaHub module.
Manage sections and books
Configure MediaHub settings
2SV: Follows organisation setting.
MediaHub Author
Intended for employees who create content in MediaHub.
Create, edit and publish books
2SV: Follows organisation setting.
Overview: management role hierarchy
Role |
Includes |
Explanation |
|---|---|---|
Organisation management |
Everything below + manage accounts, organisation settings |
Full organisation manager |
Project management |
Create, edit, archive projects, manage team members |
Only on assigned projects |
Administration |
View all projects (read-only) + signed forms |
Automatically all projects |
Financial Administration |
View all projects (read-only) |
Automatically all projects, without signed forms |
Organisation reports |
Organisation reports only |
No project access |
Permissions matrix
The table below provides an overview of the key capabilities per permission group.
Permission group |
View projects |
Edit projects |
Create projects |
Manage team members |
Add workers |
Manage passes |
View attendance |
Register visitors |
Carry out assessments |
View forms |
Manage accounts |
Organisation settings |
Reports |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Organisation management |
Yes |
Yes |
Yes |
Yes |
No |
No |
No |
No |
No |
No |
Yes |
Yes |
Yes |
Project management |
Yes |
Yes |
Yes |
Yes |
No |
No |
No |
No |
No |
Yes |
No |
No |
No |
Administration |
Yes |
No |
No |
No |
No |
No |
No |
No |
No |
Yes |
No |
No |
No |
Financial Administration |
Yes |
No |
No |
No |
No |
No |
No |
No |
No |
Yes |
No |
No |
No |
Planning |
Yes |
No |
No |
No |
Yes |
No |
No |
Yes |
No |
Yes |
No |
No |
Yes |
Assessor |
No |
No |
No |
No |
No |
No |
No |
No |
Yes |
No |
No |
No |
No |
Operations: Safe |
Yes |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
Operations: Access |
Yes |
No |
No |
No |
No |
Yes |
Yes |
Yes |
No |
No |
No |
No |
No |
Operations: Fair |
Yes |
No |
No |
No |
Yes |
Yes |
Yes |
Yes |
No |
No |
No |
No |
No |
Operations employee |
Yes |
No |
No |
No |
Yes |
Yes |
Yes |
Yes |
No |
No |
No |
No |
Yes |
App Only |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
Enrolment manager |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
ACP |
No |
No |
No |
No |
No |
Yes |
Yes |
No |
No |
No |
No |
No |
No |
Organisation reports |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
Yes |
Reports for external parties |
No |
No |
No |
No |
No |
No |
Yes |
No |
No |
No |
No |
No |
No |
Safety manager |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
Safety coordinator |
No |
No |
No |
No |
No |
No |
Yes |
No |
No |
No |
No |
No |
No |
MediaHub Admin |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
MediaHub Author |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
No |
Note on the table: The Safety and MediaHub permission groups provide access to their own modules, which is not shown in the columns above. The Enrolment manager has access to managing subcontractor enrolments, which also falls outside this matrix. The "Add workers" column for Operations: Fair refers only to incidental workers; the Planning role can add both CAO and incidental workers.
Frequently asked questions
Can I combine multiple permission groups?
Yes, permission groups are cumulative. The exceptions are App Only and Reports for external parties - these must not be combined with other groups.
Who can assign permission groups?
Only users with the Organisation management permission group can create accounts and assign permission groups.
What is the difference between Administration and Financial Administration?
Both roles provide read-only access to all projects. The difference is that Administration also has access to the Signed forms tab, whereas Financial Administration does not.
Should I still use "Operations employee"?
This role is being phased out. We recommend using the specific Operations roles (Safe, Access or Fair) for new accounts. Existing accounts with the old role will simply continue to work.
Do you see other permission groups in the application? These are internal and cannot be assigned by organisation managers.