The four roles
Every user has exactly one role, and ConsignTrak has four. They're fixed: you choose which role a person gets, but you can't invent a new role or change what a role is allowed to do. This page helps you pick the right one and explains the limits of each, area by area.
For the everyday summary a new user needs, send them to Who sees what. For every individual permission in one table, see Permissions by role.
Choosing a role
| The person… | Give them | Why |
|---|---|---|
| Sets ConsignTrak up, manages users and settings, or closes the month | Administrator (shown as Admin) | Only Administrators reach Users, Settings, API keys, carrier accounts and period close. |
| Enters and releases orders, receives stock into inventory, looks after customers | Office | Office can do all the daily office work but can't change who has access or how ConsignTrak is set up. |
| Picks, packs, ships, counts and receives on the floor | Warehouse (shown as Warehouse Worker) | Warehouse can move work along on the floor but can't change orders, items or stock levels directly. |
| Works for a supply partner and wants to check their own stock | Supply Partner (shown as Supply Partner User, or Consignor on the Edit page) | Portal only, and only their own partner's records. |
Give each person the least they need. An Administrator can do anything, including locking everyone else out, so keep the number small. Two is right for most warehouses: one is a single point of failure if they're away or locked out.
A person can have only one role. If an office manager also counts stock, make them an Administrator, or give them an Office account for daily work and ask a Warehouse user to do the counts. There's no way to combine Office and Warehouse in one account.
What each role can do, area by area
✅ means the role can do it. A dash means it can't. Supply Partner users are covered separately below, because they never see these screens.
| Area | Administrator | Office | Warehouse |
|---|---|---|---|
| Orders: look at orders | ✅ | ✅ | ✅ |
| Orders: enter, edit, cancel and release | ✅ | ✅ | — |
| Orders: pick, pack and ship | ✅ | ✅ | ✅ |
| Orders: fix a tracking number | ✅ | ✅ | ✅ |
| Receiving: look at receivings | ✅ | ✅ | ✅ |
| Receiving: start a receiving and count it | ✅ | ✅ | ✅ |
| Receiving: quality-check lines and work quarantine | ✅ | ✅ | ✅ |
| Receiving: verify, post to inventory or void | ✅ | ✅ | — |
| Receiving: import a stock transfer spreadsheet | ✅ | ✅ | — |
| Items and stock: look up items, stock, locations | ✅ | ✅ | ✅ |
| Items and stock: create and edit items | ✅ | ✅ | — |
| Items and stock: adjust stock | ✅ | ✅ | — |
| Cycle counts: see counts | ✅ | ✅ | ✅ |
| Cycle counts: do the counting | ✅ | — | ✅ |
| Cycle counts: approve the results | ✅ | ✅ | — |
| Customers: see and edit customers | ✅ | ✅ | — |
| Supply partners: see supply partners | ✅ | ✅ | — |
| Supply partners: add and edit supply partners | ✅ | — | — |
| Documents: see and attach | ✅ | ✅ | ✅ |
| Documents: delete | ✅ | ✅ | — |
| History and reports: item and customer history, activity report, end-of-day shipments | ✅ | ✅ | — |
| Bulk imports of items, customers and contacts | ✅ | ✅ | — |
| Accounting periods: look at periods and reconciliations | ✅ | ✅ | — |
| Accounting periods: close a period | ✅ | — | — |
| Users, Settings, system health | ✅ | — | — |
| API keys and carrier accounts | ✅ | — | — |
A few combinations surprise people:
- Office can't count. Counting is a Warehouse (or Administrator) job; Office approves the results. This keeps the person who counts separate from the person who approves the stock change.
- Warehouse can't post a receiving. The floor counts and checks what arrived; the office posts it into stock after checking it.
- Warehouse can't adjust stock or edit items, even though some phone screens show Edit and Adjust to them. Tapping those ends on Access denied (issue #1516).
- Office sees supply partners but can't add or edit them. Adding a supply partner, or changing its details, is for Administrators.
- Some desktop links show to roles that can't use them, such as New order for Warehouse and Users and Settings for Office. They end on Access denied (issue #1481).
Administrator
Everything Office can do, and everything in the table. On top of that, only an Administrator can:
- add users, change roles, deactivate people and reset their access (see Inviting and managing users);
- change system settings and look at system health;
- issue API keys for other systems;
- add and edit supply partners and their carrier accounts;
- close an accounting period;
- read the event feed that other systems use to follow ConsignTrak (through the API only).
An Administrator can't open the supply partner portal. To see what a partner sees, sign in as a Supply Partner test user.
Office
The daily office role: orders, receiving into stock, customers, items and reports. Office users can't reach Users, Settings, API keys or carrier accounts, can't add or edit supply partners, can't close a period and can't do a cycle count themselves.
Warehouse
The floor role, built for a phone. Warehouse users move work along (pick, pack, ship, receive, check quality, count, fix tracking) but can't change what an order says, what an item is, or how much stock the system holds. They also can't see the customer or supply partner lists, history reports, or the end-of-day shipments report.
Supply Partner
A Supply Partner user belongs to one supply partner and uses only the portal. If they open any other address, ConsignTrak sends them back to the portal. They can:
- see their portal dashboard, their stock and item details;
- see their orders and receivings;
- mark their own direct-ship lines as shipped;
- see and set their item prices;
- download their activity report and monthly statements.
They can also change an item's description, reorder level and unit of measure, but only if that's switched on for their supply partner. It's off unless someone switches it on, and there's no switch on the screens yet (see Portal behaviours with no on-screen switch).
They can't see anything belonging to another supply partner, use any warehouse screen, or have an API key. How the one-partner limit works is on Supply-partner scoping.
How long each role stays signed in
Each role has a fixed session length. The clock starts when the person signs in, and using ConsignTrak doesn't extend it.
| Role | Session length | Why this length |
|---|---|---|
| Administrator | 8 hours | A full office day. |
| Office | 8 hours | A full office day. |
| Warehouse | 2 hours | Floor phones are often shared or left on a bench. |
| Supply Partner | 4 hours | Someone outside the warehouse, checking in occasionally. |
When the time is up, the person's next click takes them to the sign-in page, and anything they hadn't saved is lost. You can't change these lengths from the screens.
If you change someone's role, the new permissions apply on their next click, but their current session keeps the length of the role they signed in with. The new length applies from their next sign-in.
Two-factor authentication
Two-factor authentication asks for a code from an authenticator app after the password. See Two-factor authentication.
- Administrators must set it up only when the warehouse has chosen to require it. That's a server setting made when ConsignTrak is installed, not something on the Settings page. When it's on, an Administrator who hasn't set up two-factor is taken through set-up at their next sign-in.
- Office, Warehouse and Supply Partner users aren't asked for it, and can't turn it on for themselves today (issue #1476).
Ask whoever installed ConsignTrak to require two-factor for Administrators. An Administrator account can change everyone else's access, so it's the one most worth protecting.
On a phone
The role also decides which phone layout a person gets: its home screen and bottom bar. See Who sees what.