> ## Documentation Index
> Fetch the complete documentation index at: https://docs.alvys.com/llms.txt
> Use this file to discover all available pages before exploring further.

# User Roles in Alvys

> Explains the eleven built-in Alvys user roles, their hierarchy, default permissions, and how role assignment differs from customizing individual user access.

<Note>
  Every Alvys user is assigned exactly one role that defines their default permissions, determines what they can see and do, and establishes their level of authority. Alvys roles are arranged in a strict hierarchy.
</Note>

## Overview

Every user who logs into Alvys is assigned exactly one role (sometimes called a user type or access profile). A role is a predefined profile that determines a user's default set of permissions, including what they can see, what actions they can take, and which other users they can manage. Roles are the foundation of access control in Alvys and establish each user's baseline permissions at the time of account creation.

Roles can be further customized on a per-user basis after the account is created. A role's position in the hierarchy reflects its level of authority and determines which users a given user is permitted to manage.

<img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/e18160d887e4.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=b25934f96bd2fb4d31fbb8150b9e4a55" alt="Sample Image displaying roles" width="718" height="458" data-path="images/help/e18160d887e4.png" />

*The full roles list as it appears in Settings → Organization → Users.*

## Where to Find It

User roles are managed from **Settings → Organization → Users**. Navigate there from the Settings menu. Each user row displays the role currently assigned to that account.

When creating or editing a user, the role is selected from a dropdown list in the user form.

## Key Concepts

### Roles and Permissions: How They Work Together

A role and a permission are two different things. A role is a named profile, such as Dispatcher or Biller, assigned to a user when their account is created. Each role comes with a default set of permissions that reflect the typical responsibilities of that job. A permission is a specific capability, such as **"Generate Invoice"** or **"View Customer Rate"**, that controls a user's access to a particular action or piece of data.

Think of it this way: a role is a job title, and permissions are the keys on that person's keychain. The role determines which keys they start with. Users with the **"Set Permission"** permission can then add or remove individual keys without changing the person's role.

<img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/d745597e5aba.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=0e26f5f72c7d4ff80cad508c8ca8ac01" alt="Image illustrating individual permission toggles alongside a role assignment." width="1024" height="559" data-path="images/help/d745597e5aba.png" />

*Image illustrating individual permission toggles alongside a role assignment.*

Some permissions control what a user can view (read-only access), while others control what they can do (create, edit, or delete). For example, **"View Customer Rate"** lets a user see the rate charged to a customer, but **"Edit Customer Rate"** is required before they can change it. When in doubt, assign view-only access first and expand from there.

When an admin adds a permission to your account, the change takes effect immediately. You stay signed in, and a banner appears at the top of the screen letting you know your access was updated. Select **Refresh** whenever it is convenient to reload the page and see the new options.

When a permission is removed, or when your role is changed, you are signed out for security. Sign back in to continue with your updated access.

A role is not the same as a permission set. A role provides a user's default permissions at the time of account creation, but those permissions can be individually added or removed at any point afterward. Two users sharing the same role may have different active permissions if their configurations have been customized after role assignment.

### Hierarchy

A role's position in the hierarchy controls who that user can manage — not how much access the role has. Higher-level roles generally have broader default permissions, but not always. The clearest example is Admin and Partner Admin: Admin sits above Partner Admin in the hierarchy, but Partner Admin starts with the broader default permission set. Other roles are built around specific job functions and include specialized permissions regardless of where they sit.

A user's hierarchy position governs their management reach: users can only manage or modify the permissions of users who sit below them in the hierarchy. For example, a Dispatcher cannot modify an Office Admin's account settings or permissions.

## How to Use It

For step-by-step instructions on assigning roles when creating or editing a user account, see [How to Add and Manage Users in Alvys](/en/help/administration/how-to-add-and-manage-users-in-alvys).

## Settings & Permissions

### Admin

The Admin role is the highest role available to company users. This role is intended for company owners, directors of operations, and administrators who need near-complete system access.

Admins are responsible for managing the full user lifecycle, including creating, editing, and deactivating users, as well as configuring carriers, customers, and companies. They have the authority to manage load operations end-to-end, access financial reports, configure pay plans, and control team-wide settings and integrations.

<img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/44c67fbfe5eb.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=ff0d5f5031bddb1d7ab6c399361cc103" alt="Screenshot of the Admin role in Settings, Organization, Users." width="887" height="187" data-path="images/help/44c67fbfe5eb.png" />

*Screenshot of the Admin role in Settings → Organization → Users.*

By default, Admin users are granted comprehensive access, excluding a small set of the most sensitive permissions. These are intentionally withheld to safeguard data, though an Admin maintains full authority to enable them for themselves or others as required.

<Info>
  💡 Best practice: Reserve the Admin role for the fewest people necessary, ideally the company owner and one backup manager. Use the Office Admin or Operation Manager role for day-to-day supervisory work.
</Info>

### Partner Admin

The Partner Admin is a primary administrator role, typically assigned to the owner of the company or general managers. Partner Admin users receive full permissions and operate with nearly the same level of access as Admin, but they rank below Admin in the hierarchy. A Partner Admin cannot promote another user to Admin, because users cannot be assigned a role that sits higher in the hierarchy than their own.

<img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/5c3e615935dd.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=db883ec7277002a51004ab1f4cbd1586" alt="Screenshot of the Partner Admin role in Settings, Organization, Users." width="679" height="166" data-path="images/help/5c3e615935dd.png" />

*Screenshot of the Partner Admin role in Settings → Organization → Users.*

### Operation Manager

The Operation Manager role is designed for middle management and senior operations staff who oversee dispatchers, loads, carriers, and customers. It is positioned between Admin and Office Admin in the hierarchy.

This role is the appropriate choice for trusted supervisors such as operations managers, fleet managers, and terminal managers whose primary responsibilities include overseeing daily dispatch and load operations, managing carriers and customers, reviewing financial summaries and reports, and monitoring driver and asset activity.

<img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/5c3e615935dd.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=db883ec7277002a51004ab1f4cbd1586" alt="Screenshot of the Operation Manager role in Settings, Organization, Users." width="679" height="166" data-path="images/help/5c3e615935dd.png" />

*Screenshot of the Operation Manager role in Settings → Organization → Users.*

### Office Admin

The Office Admin role is designed for users who coordinate and manage general office procedures and policies. This role's default permissions focus on managing user accounts, companies, assets (trucks, trailers, drivers), load templates, and marketplace access.

Office managers, administrative managers, or back-office coordinators are the intended users for this role.

<img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/c8d3b0fa1851.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=2f0c6b39bf4a64e9e3797e193d438a04" alt="Screenshot of the Office Admin role in Settings, Organization, Users." width="671" height="182" data-path="images/help/c8d3b0fa1851.png" />

*Screenshot of the Office Admin role in Settings → Organization → Users.*

Primary goals and actions for Office Admin users:

* Maintain carrier and customer records
* Manage rates (customer and carrier)
* Add new users and adjust permissions for lower-level staff
* Work with load templates
* Monitor asset, driver, and safety data
* Access the marketplace to view, book, and bid on loads

Default permissions include: **"Pay Owner Operator"**, all Rate permissions, **"Add User"**, **"Set Permission"**, **"Edit Carrier"**, **"Activate Carrier"**, all Customer and Company Management permissions, **"Edit Asset"**, **"View Load Templates"**, **"Manage Load Templates"**, all Marketplace permissions, all Asset View permissions, all Safety View permissions, **"View Driver Rates"**, and **"Edit Driver Rates"**.

This role does not include access to financial reports, settlement permissions, or the ability to pay drivers. Office Admins can add users and adjust permissions, but only for users at a lower hierarchy level than themselves. They cannot promote another user to Office Admin or any higher role.

### Dispatcher

Dispatcher is the primary load management role. Dispatchers are the operational backbone of freight operations; they create and manage loads, assign carriers and drivers, and coordinate pickups and deliveries.

This role is intended for freight dispatchers, load planners, load coordinators, and driver managers.

<img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/e124c8554b14.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=556e28687af336636a91bf0f69964d73" alt="Screenshot of the Dispatcher role in Settings, Organization, Users." width="669" height="163" data-path="images/help/e124c8554b14.png" />

*Screenshot of the Dispatcher role in Settings → Organization → Users.*

Primary goals and actions for Dispatcher users:

* Create, assign, and track loads
* Book carriers and manage carrier relationships
* Manage customers and companies
* Override stop statuses when needed
* Use load templates for repeating lanes
* Access the load marketplace
* Monitor drivers, trucks, and trailers
* View accident, claim, and roadside inspection records

Default permissions include: All Rate permissions, **"Add Accessorials"**, **"Edit Miles"**, **"Dispatch"**, all Load Operation permissions, **"Edit Carrier"**, **"Activate Carrier"**, all Customer and Company Management permissions, **"View Load Templates"**, **"View Driver Rates"**, **"Edit Driver Rates"**, all Marketplace permissions, all Asset View permissions, and all Safety View permissions.

Dispatchers do not have access to billing, invoicing, pay stubs, financial reports, or user management. The **"Dispatch"** permission is included in this role by default, but it can also be enabled on other roles such as Sales Agent or Data Entry.

### Biller

The Biller role is designed for users who handle invoicing, settlements, carrier payments, and financial reporting. Billers have the broadest set of financial permissions among non-admin roles.

This role is intended for billing clerks, accounts receivable specialists, accounts payable clerks, payroll specialists, and transportation accountants.

<img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/cb50095c2106.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=31852329b3925cb477c392cea4512079" alt="Screenshot of the Biller role in Settings, Organization, Users." width="674" height="168" data-path="images/help/cb50095c2106.png" />

*Screenshot of the Biller role in Settings → Organization → Users.*

Primary goals and actions for Biller users:

* Generate and manage customer invoices
* Process driver and owner-operator payments
* Manage pay stubs and pay plans
* Approve payable items
* Create and manage carrier statements
* Run financial reports (summary, detailed, statement list, statement items, and driver year-to-date)
* Roll back, void, and override transactions when corrections are needed
* Export financial data

Default permissions include: **"Pay Owner Operator"**, **"Add Accessorials"**, **"Billing"**, **"Export"** (integration-gated), **"Edit Miles"**, all Rate permissions, **"Modify E-Check Fee"** (integration-gated), **"Generate Invoice"**, **"Override Invoice"**, **"Rollback Transaction"** (integration-gated), **"Void Transaction"** (integration-gated), **"View Paystubs"**, **"Fuel Report"**, **"Toll Report"**, all Load Operation permissions, **"Edit Carrier"**, **"Activate Carrier"**, all Customer and Company Management permissions, **"Edit Asset"**, **"View Load Templates"**, **"Edit Paystubs"**, **"View Summary Financial Report"**, **"View Detailed Financial Report"**, **"View Statement List Report"**, **"View Statement Items Report"**, **"View Driver YTD"**, **"View Driver Rates"**, **"Edit Driver Rates"**, **"Pay Driver"**, **"Approve Payable Items"**, **"Create Carrier Statement"**, **"Edit Invoice Customer As"**, and all Asset View permissions.

### Sales Agent

The Sales Agent role is designed for users who manage customer and carrier relationships, negotiate rates, and support load booking. Sales Agents have a permission set similar to Dispatchers, with full visibility into customer and carrier rates.

This role is intended for sales agents, freight brokers, logistics sales representatives, account executives, and business development representatives.

<img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/3364578912c0.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=0d913dd7f508778ae048778c473a7805" alt="Screenshot of the Sales Agent role in Settings, Organization, Users." width="674" height="163" data-path="images/help/3364578912c0.png" />

*Screenshot of the Sales Agent role in Settings → Organization → Users.*

Primary goals and actions for Sales Agent users:

* Create and manage loads for their accounts
* Book carriers and manage carrier relationships
* Create and manage customers and companies
* Work with load templates for repeating business
* View and edit driver rates

Default permissions include: **"Pay Owner Operator"**, all Rate permissions, **"Edit Miles"**, **"Dispatch"**, all Load Operation permissions, **"Edit Carrier"**, **"Activate Carrier"**, all Customer and Company Management permissions, **"View Load Templates"**, **"View Driver Rates"**, and **"Edit Driver Rates"**.

This role does not include Billing, Invoicing, any financial report permissions, Marketplace access, Safety View permissions, or any payment permissions.

### Data Entry

The Data Entry role is designed for users who create loads, enter shipment data, and handle tender intake. This role has a targeted permission set centered on load creation and basic operations.

This role is intended for data entry clerks, administrative assistants, load builders, and EDI coordinators.

Data Entry is the only non-admin role that includes **"Participate In Tender"** by default, reflecting its use in processing incoming EDI tenders from trading partners.

<img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/abf3a91d0e9e.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=43c922251c62bbf2196c2d2937cc20d7" alt="Screenshot of the Data Entry role in Settings, Organization, Users." width="678" height="164" data-path="images/help/abf3a91d0e9e.png" />

*Screenshot of the Data Entry role in Settings → Organization → Users.*

Primary goals and actions for Data Entry users:

* Enter and maintain carrier, customer, and company records
* Build loads using templates
* Set up and maintain rate records
* Create and participate in tenders

Default permissions include: All Rate permissions, **"Edit Carrier"**, **"Activate Carrier"**, all Customer and Company Management permissions, **"Edit Miles"**, **"Add Accessorials"**, all Load Operation permissions, **"Edit Asset"**, **"Participate In Tender"**, **"View Load Templates"**, **"View Driver Rates"**, **"Edit Driver Rates"**, and all Asset View permissions.

Data Entry users cannot dispatch loads, override stop statuses, access billing, manage users, or view safety and maintenance records. Despite its position in the hierarchy, the Data Entry role has a substantial permission set covering load creation, carrier management, and customer management.

### Safety

The Safety role is designed for compliance and safety personnel who monitor fleet safety, manage assets, and review safety reports. This is a specialized, narrow-access role.

This role is intended for safety managers, DOT compliance officers, fleet safety coordinators, and risk and compliance specialists.

<img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/ffbea38c63de.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=d2d8bb723982e82154ed98a4d6f92bc4" alt="Screenshot of the Safety role in Settings, Organization, Users." width="675" height="172" data-path="images/help/ffbea38c63de.png" />

*Screenshot of the Safety role in Settings → Organization → Users.*

Primary goals and actions for Safety users:

* Monitor vehicle maintenance records
* Review accident and claims records
* Track roadside inspection results
* Generate safety and fuel/toll reports
* Maintain driver and asset records from a compliance perspective

Default permissions include: **"Edit Asset"**, **"Calendar Past Dates"**, **"Fuel Report"**, **"Toll Report"**, all Asset View permissions (**"View Drivers"**, **"View Trailers"**, **"View Trucks"**), and all Safety View permissions (**"View Accidents"**, **"View Claims"**, **"View Roadside Inspections"**, **"View Maintenance Records & Totals"**, **"View Maintenance Amounts"**, **"View Asset Safety Report"**).

Safety users have no access to loads, rates, billing, dispatch, marketplace, customer management, or user administration.

### Driver

The Driver role is for company drivers, owner-operators, contractors, and other personnel who use the Alvys Mobile App. This role provides access to the mobile app and carries no desktop permissions.

By default, the Driver role has an empty permission set. Each driver's permissions should be configured explicitly based on their specific responsibilities. For information on mobile app permissions, see [App Permissions](/en/help/administration/app-permissions).

<Warning>
  ⚠️ Do not create drivers through the Add User form. Driver account creation is handled through the driver setup and mobile app verification process. Always follow the proper driver creation workflow.
</Warning>

<img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/3fc6002b1c4d.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=11a9a3e8e709b16f06851706237072bb" alt="Notion Image" width="1639" height="108" data-path="images/help/3fc6002b1c4d.png" />

<Info>
  💡 Create drivers in the Driver List by entering essential details such as name, address, and mobile phone number. The mobile phone number serves as the unique identifier linking the driver to the Alvys Mobile App. After successful SMS verification, the system automatically creates a user account with the Driver role under **Settings → Organization → Users**.
</Info>

Primary goals and actions for Driver users:

* View and update schedules
* Log trips and manage their driving records
* Update stop statuses on the road via the mobile app
* Submit documents (BOLs, PODs) through the mobile app
* Access pay stubs through the mobile app (if enabled)

Drivers logging into the desktop application will have no access to any module.

## Limits & Behavior

### Role Hierarchy Summary

Admin sits at the top of the hierarchy available to company users, with Partner Admin directly below it; together they provide company-level administrative control. Below those are the operationally focused roles: Operation Manager, Office Admin, Dispatcher, Biller, Sales Agent, and Data Entry. The Safety role provides specialized access for compliance and asset management. The Driver role carries no default permissions and must be explicitly configured. Position in the hierarchy governs management reach only. It does not indicate how many permissions a role receives by default.

A user's position in the hierarchy governs their management reach: users can only manage or modify the permissions of users who sit below them in the hierarchy. For example, a Dispatcher cannot modify an Office Admin's permissions.

<img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/c2680195d817.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=ed017262bca821b51a77d41e7f3210ff" alt="Screenshot of the full role hierarchy chart as displayed in Alvys." width="1408" height="768" data-path="images/help/c2680195d817.png" />

*Screenshot of the full role hierarchy chart as displayed in Alvys.*

### Role Changes Reset Permissions

Changing a user's role resets all of their permissions to the new role's defaults. Because a role change can reduce access, it also signs the user out. They will need to sign back in, and their permissions will reflect the new role's defaults.

### What Permissions Don't Control

Not every access limitation in Alvys is controlled by the permissions panel. Some behaviors are determined by role configuration or feature settings rather than individual permission toggles. Common examples include tab and menu visibility for specific roles, the ability for users to edit their own assignment preferences, required fields on carrier onboarding packets, TONU and load-level rate rules, and office-level load sharing.

<Tip>
  If a user's permissions appear correct but they still cannot access a feature or action, see [Overview of User Permissions](/en/help/administration/overview-of-user-permissions) for a full breakdown, and confirm whether the issue is load-state or office-visibility related before adjusting permissions.
</Tip>

### Multi-Factor Authentication (MFA)

MFA setup is managed by each user individually. Admins and Partner Admins can reset MFA for any user from **Settings → Organization → Users** — this clears all enrolled authenticators and prompts the user to re-enroll at next sign-in.

<Warning>
  ⚠️ A Partner Admin cannot reset another Partner Admin's MFA. Those requests must go through Alvys Support.
</Warning>

## FAQs

**Q:** What is the difference between a role and a permission?

**A:** A role is a predefined profile (such as Dispatcher) assigned to a user at account creation that provides a starting set of default permissions and establishes their place in the hierarchy. A permission is an individual toggle for a specific action, such as **"Edit Miles"** or **"View Customer Rate"**.

**Q:** Can a user be assigned more than one role at a time?

**A:** No. Each user account is assigned exactly one role. If a user performs tasks that span multiple roles, assign the role closest to their primary function and then manually enable the specific permissions they need.

**Q:** What happens to a user's customized permissions if I change their role?

**A:** Changing a user's role resets all their permissions to the new role's defaults. Any previously added or removed permissions are overwritten, so any custom access must be reconfigured after the role change is saved. Changing a role also signs the user out; they sign back in with the new role's access.

**Q:** Why does the Admin role not have Delete or Contracted Lanes permissions by default?

**A:** The Admin role does not include the Delete permissions or the Contracted Lanes permissions in its default set. An Admin can enable any of them, for themselves or for another user, from **Settings → Organization → Users**. Note that the Partner Admin role does include these by default — a role's position in the hierarchy does not determine how many permissions it starts with.

**Q:** What is the primary difference between an Office Admin and an Operation Manager?

**A:** The Office Admin role centers on administrative tasks such as adding new users and managing equipment assets. The Operation Manager role is a supervisory role focused on high-level operational oversight such as reviewing financial summaries and monitoring fleet-wide driver activity.

**Q:** What does the hierarchy position control?

**A:** The hierarchy position determines a user's organizational authority. A user can only manage or modify the permissions of users who sit at a lower hierarchy level than themselves. For example, a Dispatcher cannot modify the account of an Office Admin.

**Q:** Can a user with the Safety role see load and rate information?

**A:** No. The Safety role is limited to compliance, maintenance, and inspection data. It is designed to allow safety officers to perform their duties without exposing commercial or financial information.

**Q:** If a user needs to do both dispatching and billing, which role should I choose?

**A:** Choose the role that represents their primary responsibility. If they need broad financial access, assign Biller and then enable the **"Dispatch"** permission toggle so they can also manage loads.

**Q:** Can an Admin reset MFA for another user?

**A:** Yes — with one exception. An Admin or Partner Admin can open the user in **Settings → Organization → Users** and click **Reset MFA**. This clears the user's enrolled authenticators; they will be prompted to set up MFA again at next sign-in. A Partner Admin cannot reset another Partner Admin's MFA — those requests must go through Alvys Support.

## Go Deeper

* [How to Add and Manage Users in Alvys](/en/help/administration/how-to-add-and-manage-users-in-alvys)
* [App Permissions](/en/help/administration/app-permissions)
* [Overview of User Permissions](/en/help/administration/overview-of-user-permissions)
* [User Permissions Glossary](/en/help/administration/user-permissions-glossary)
* [User Roles & Permissions Collection](/en/help/administration/user-roles-permissions-collection)

## Next Steps

<Info>
  ⏭️ Proceed to [How to Add and Manage Users in Alvys](/en/help/administration/how-to-add-and-manage-users-in-alvys) to understand how to add new users, edit user profiles, assign roles and permissions, and manage user access in Alvys. This includes guidance on keeping user records accurate and ensuring each team member has the appropriate level of access for their responsibilities.
</Info>
