Manage users, roles, permissions, and teams
Manage user accounts
View, edit, activate, and deactivate user accounts.
The user profile lists the assets they are responsible for (where they are set as an assignee, alone or alongside others). Each entry links straight to the asset, giving you a quick accountability view of who owns what.
When you manage many users, use the rows-per-page selector at the bottom of the table (10, 20, 50 or 100) to show more at once. Select users with the checkboxes to act on several at once: change their role, or activate/deactivate them in one step. To protect your account, you can't change your own account in bulk, and the system always keeps at least one administrator.
Use the Columns button above the users list to choose which columns appear โ Role, Status, Contact, Last Login, Created, Employee ID, and Shift. Your choice is saved to your account and follows you across devices. By default the table shows Employee ID and Shift and hides the creation date; turn any column back on whenever you need it. The Shift column is available on the Business plan and above (where work shifts are configured), and Employee ID on every plan.
Need to record Unit, Section, Division, or any other organizational detail on a person? On the Business plan you can define your own user fields in Company Settings โ Custom Fields (choose the User entity). They then appear on every user profile for you to fill in โ your structure, your labels, no two companies forced into the same org chart.
Need to give someone access right away without waiting for an invitation email? Choose the Direct create tab on People โ Invite. You set an initial password and provide either an email or a username. The person can sign in immediately โ with their email if you entered one, or with username@your-company-slug plus the password you set (they are asked to change it on first sign-in). Unlike passive members, direct-created users are full login accounts: a user created this way with a username has access even though no email is shown on their row.
Each user can carry an optional Employee ID โ your internal HR or payroll number. It appears on the user's profile and is searchable from the People โ Users list, so you can find someone by their company ID, not just their name or email.
Filter the users list to a single team, or group it by team or by role to see your organization's structure at a glance. When grouping by team, the header shows the team's place in the hierarchy (parent > team). Turn on the optional Team column from the Columns button to see each member's teams inline.
Beside the Employee ID, each person can carry a Job title โ what they actually do: driver, caretaker, supervisor, educator. It is free text, so it fits your own vocabulary, and it is NOT a FreeMaint role: it grants no permission and changes nothing about what the person can see or do. Set it from People โ Users on the profile, or straight from the New driver dialog in Fleet. It then appears on the driver list, on the OSHA 300 injury log, next to qualifications and on the team org chart.
On the People โ Users list, the "No login" badge marks a person who has neither an email nor a username โ a passive / workshop member who cannot sign in. A user created with Direct create who has a username (but no email) can log in, so they are not shown with this badge. If you expected someone to have access but they show "No login", open their profile and add an email, or recreate them with Direct create and give them a username plus a password.
Add team members who do not have a work email โ workshop crews, paper-based workflow, drivers without a system login. Choose the Passive tab on People โ Invite to create them from name and role only. You can still assign work orders, log their time, attach a driver profile, and later edit their role, permissions, or phone from People โ Users without being asked for an email. To give them login access later, just type their email on the edit page and save.
On the People โ Users list, open a user's row menu (the three-dot icon) to manage their password. "Reset Password" emails them a secure link to choose a new one. "Set Password" lets you type a new temporary password yourself and hand it over directly โ the user is asked to change it on first sign-in, and this is the only option for passive or username-only users who have no email. Both require the user-management permission, and you can do the same from a user's profile page.
Each user profile shows a performance card with work orders assigned and completed, completion rate, and assigned/completed tasks for the period you choose (this month, quarter, or year).
Deactivate departed members instead of deleting to preserve work history.
Send invitations
New users join through email invitations with pre-assigned roles.
All three ways of adding someone above accept an optional vendor: the email invitation, the workshop member (no email, no login) and the direct account with a username. Pick one and the account belongs to that vendor from the moment it exists. It then only ever sees the work orders assigned to it, and never a cost, an asset value or a purchase price โ whatever roles it is given later. These accounts are kept out of People > Users by default; switch on "Show vendor accounts" to list them, or open the vendor's own page. You can change or remove the affiliation later from the person's profile. The user import has the same column, "External Vendor (Name)": type the vendor's name and the imported accounts are bound to it. A name that matches nothing fails that row rather than creating an unbound account, and the export writes the column back so an export-edit-reimport round trip keeps the link.
If the email you invite already has a FreeMaint account in another workspace, that's not an error. When they open the invitation they'll be asked to confirm switching into your workspace. If they are the only member of their current workspace (often a leftover trial), it is closed and they join yours; if that workspace has other members or a paid plan, they'll be guided to leave it first or contact support.
If email doesn't arrive (300/day Brevo limit), copy the link and share directly.
If you already have a list of people in a spreadsheet, import them all at once instead of inviting them one by one. Rows that include an email address are sent an invitation to set their own password and appear under People > Invitations. Rows with a username instead of an email become login-capable accounts right away โ the generated password is shown once after the import so you can hand it out. Rows left with neither become passive members (no login) โ useful for workshop crews you only assign work to.
Invitations are tracked in People > Invitations.
Admin and Manager roles cannot be imported โ invite those people individually so they verify their email. Import always creates new people; it never overwrites existing accounts.
12 built-in roles explained
12 roles covering common maintenance structures, plus custom roles.
Match roles to job functions.
Create your own roles
Build roles with any combination of 140+ permissions.
Each role can choose which destination the fourth slot of the mobile bottom bar holds: Schedule, Assets, Parts, Reports, Team or Profile. Leave it on Automatic and the app decides โ Schedule for roles that carry out or plan work, the profile for everyone else. An option is greyed out when the role lacks the permission that screen needs. Takes effect the next time the user signs in.
Clone an existing role and modify it.
140+ granular permissions
Each permission follows ENTITY_ACTION format (e.g., WORK_ORDERS_CREATE).
User permissions = Role permissions + Additional individual permissions.
Important:
Cost/price/financial permissions are restricted to ADMIN and MANAGER by default.
Limit users to specific locations
Department-based access restricts what technicians, requesters and operators can see in FreeMaint to the locations they are assigned to. Useful for multi-site or multi-department organizations where each shop floor team should only see its own work. You can restrict access for individual users or for an entire team at once.
Admins, managers and super admins are never restricted by this toggle. They keep full visibility regardless of assignments.
You can keep the existing "Assigned only" toggle on at the same time. When both are on, a user sees the union: assets/orders inside their department and assets directly assigned to them anywhere.
A member's accessible locations are the combination of their personal assignments and the locations of every team they belong to or lead.
If a role's Data visibility is set to Team scope, the locations granted to that user's teams already widen what they see โ the assets, work orders, requests and preventive maintenance in those locations and their sub-locations โ even when Department-based access is off. You do not have to link each record to the team one by one. The toggle above is what additionally restricts roles that see all company data.
Empty result on a page? If a user has the toggle on but no location assigned, they will see a yellow banner asking them to contact their administrator.
Create and manage teams
Teams group users. Reference: TEAM-1, etc.
In the team form, "Locations this team can access" grants the team one or more locations. Members whose role uses Team scope data visibility then see the assets, work orders, requests and preventive maintenance in those locations, in addition to the records assigned to the team itself. Sub-locations are included automatically, so granting a building covers each of its floors.
A user whose role uses Team scope but who belongs to no team is not restricted at all โ they keep seeing every record their permissions allow. Their detail page flags this so you can add them to a team. The role editor flags it as well, the moment you pick Team scope on a role that would restrict no one.
Each team page shows a performance card with work orders assigned and completed, completion rate, and assigned/completed tasks for the chosen period, so you can compare output across teams.
Organize by function (Electrical Team) or area (Building A Team).
Assign work to teams
Any team member can pick up team-assigned work. When a work order is assigned to the team, all members (the leader included) are notified; status updates go to the assignee and creator to avoid notification overload.
Balance workload across members.
Track employees' certificates, licenses and expiry dates
Record each employee's certificates, authorizations, attestations and licenses with their validity dates, and get alerted before they expire โ so your team always stays compliant.
Admins and managers manage and view the whole register. Any employee can always see their own qualifications on their profile. Adding or editing qualifications requires the Starter plan or above.
A daily check notifies admins and managers 30, 15 and 7 days before a qualification expires. You can turn the alert channels (in-app, push, email) on or off in Notification settings.
From the Qualifications register, each row can be edited or deleted directly โ the pencil and bin icons appear for anyone allowed to manage qualifications. When an employee is deleted, their records leave the register but are NOT destroyed: certification evidence often has to be kept after someone leaves. Pick "Former employees" in the status filter to bring those records back when an auditor asks for them.
Set the reminder window to match your renewal lead time so you never scramble at the last minute.
Customize your experience
Each user can customize language, theme, and notifications.
Switch languages instantly from your profile.
FreeMaint CMMS
ยฉ 2026 FreeMaint. All rights reserved.