Administration5 min read

Users & Roles

Livestork uses a role-based access control system. Each user is assigned a role that determines what they can view, create, edit, and delete across the platform.

Role overview

Livestork has seven built-in roles. Roles are set per user per organisation; a person cannot have different roles on different modules within the same organisation.

org_admin

Full access to every module and permission in the organisation, including user management, settings, and billing. The first account in an organisation is always org_admin.

Best for: Organisation owner or the person ultimately responsible for the platform.

farm_manager

Broad operational and commercial access: batches, inventory, procurement, sales, HR, assets, and read access to finance. Cannot manage users, roles, or organisation-level settings.

Best for: Farm manager or general operations lead running day-to-day business.

site_supervisor

Full control at the site level: daily logs (including approval), health and mortality recording, deliveries, purchase requests, and asset/maintenance visibility. Narrower than farm_manager on procurement and finance.

Best for: Site or unit supervisor overseeing one location's daily operations.

field_staff

Write access to daily log entries, health and mortality recording, weight and performance recording, and expense claims. Cannot approve daily logs or manage procurement beyond raising a request.

Best for: Farm hand or field worker recording day-to-day activity.

accountant

Full access to procurement finance: vendor financials, purchase order approval, supplier invoices and payments, and full general ledger access. Read-only on farm operations.

Best for: Finance officer, accountant, or bookkeeper.

vet

Full access to health, vaccination, medication, and quarantine records, plus read access to batches and production. No access to finance or procurement.

Best for: Veterinarian or animal health specialist.

viewer

Read-only access to farm operations, inventory, and procurement. Cannot create, edit, or delete any records, and cannot view financial data.

Best for: Investor, auditor, or external consultant who needs visibility without edit rights.

Note

Custom roles are available on plans that include custom role management, under Settings > Roles. If your plan doesn't include it and none of the seven built-in roles fits a team member, choose the closest match and contact support to discuss your requirements.

Permission matrix

The following table summarises access by module and role:

Moduleorg_adminfarm_managersite_supervisorfield_staffaccountantvetviewer
Daily LogsFullFullApproveCreateReadReadRead
Health & MortalityFullFullFullCreateNoneFullRead
Feed & InventoryFullFullRead/AdjustReadAdjustNoneRead
ProcurementFullFullCreate requestCreate requestApprove PONoneRead
SalesFullFullCreate/ConfirmNoneNoneNoneNone
Accounts PayableFullReadNoneNoneFullNoneNone
Accounts ReceivableFullFullReadNoneNoneNoneNone
General LedgerFullNoneNoneNoneFullNoneNone
Users & RolesFullNoneNoneNoneNoneNoneNone
SettingsFullNoneNoneNoneNoneNoneNone

Inviting users

Only org_admin role users can invite new team members. There is no limit on the number of users in a Livestork organisation.

  1. 1

    Navigate to Administration > Users

    Click "Administration" in the left sidebar, then "Users". This page lists all active users in your organisation.

  2. 2

    Click "Invite User"

    The Invite User button is in the top right corner of the Users page. Only org_admin role users can invite new members.

  3. 3

    Enter the email address and select a role

    Type the email address of the person you are inviting and select the appropriate role from the dropdown. Review the role descriptions before selecting.

  4. 4

    Send the invitation

    Click "Send Invitation". Livestork sends an email to the address with a secure one-time link. The link is valid for 72 hours.

  5. 5

    The user accepts and sets their password

    When the invitee clicks the link, they are prompted to set their password. After that, they have immediate access based on their assigned role.

Invitation link expiry

Invitation links expire after 72 hours. If a team member did not receive the email or the link expired, you can resend the invitation from the Users page by clicking the three-dot menu next to their pending entry.

Changing a user's role

To change a user's role, navigate to Administration > Users, find the user, click the three-dot menu on their row, and select Edit Role. Select the new role and click Save. The change takes effect immediately; the user's next page load will reflect the new permissions.

Note

Role changes are recorded in the audit log under Administration > Audit Log. The entry shows who changed the role, from what to what, and when.

Removing users

To remove a user's access, navigate to Administration > Users, find the user, and click Deactivate from the three-dot menu. Deactivated users cannot log in but their records (audit trail entries, data they created) are preserved.

Deactivated users do not count toward any user limits and can be reactivated by an org_admin at any time.

Best practices

  • Assign the minimum required role. Give each user the role that covers their actual responsibilities. Avoid giving everyone org_admin access.
  • Have at least two org_admin users. If the only org_admin leaves, you will need to contact support to restore access. Maintain a backup org_admin account.
  • Deactivate leavers promptly. When a team member leaves, deactivate their account immediately to prevent unauthorised access.
  • Review the user list quarterly. Check Administration > Users every quarter to identify inactive users or users whose roles no longer match their responsibilities.
What happens to records when a user is deactivated?
All records created or modified by a deactivated user remain fully intact. Their name appears in audit trails with a "[Deactivated]" tag. Any workflows or approvals they were assigned to will be flagged as unassigned; an org_admin will need to reassign those items.