Skip to content
Vehistra
Documentation navigation

Users and permissions

Every employee has their own account. That makes every change attributable to a user – see the audit log below.

Prepared roles

Vehistra ships with seven roles. They can be adjusted, and further roles can be created.

| Role | Intended for | | ---------------- | ------------------------------------------ | | Administrator | Full access including administration | | Staff | Reading plus reporting damages and mileage | | Dispatch | Assigning vehicles and drivers | | Fleet management | Operational leadership of the fleet | | Workshop | Workshop orders and damages | | Administration | Documents, insurance, reports | | Executive | Overview and reporting |

Permissions

Permissions are fine-grained and follow the workflows, not the screens. For a damage, for instance, there are separate permissions to create, edit and close it; for vehicles additionally to retire and to register or deregister them.

Important: permissions are enforced in the services, not only by hidden buttons. Anyone without a permission cannot trigger the action by another route either.

Grant only what is needed. Someone who only reports damages needs no access to user administration.

Deactivating accounts

An account is deactivated, not deleted – that keeps past changes attributable.

Passwords

Passwords are stored with PBKDF2-HMAC-SHA256 and 210,000 iterations. There is no reset by email; an administrator resets a forgotten password in the user administration.

Audit log

The audit log records who changed what and when. It is neither visible nor modifiable for regular staff, and even an administrator cannot alter entries afterwards.

This is not a tool to monitor staff but the answer to “why does this say something different than last week?”.