User control: what to demand from a CMMS
What to demand from a CMMS in terms of access control: profiles, document visibility, traceability, and why per-user pricing breaks everything.
Updated on 6 min read
- Permissions
- Security
- Traceability
- Comparison
User control gets little attention when comparing maintenance systems, and it’s one of the few things you can’t fix afterward. If the permissions architecture can’t do what you need, no configuration will save it.
Here’s the list of what to demand, and why each point matters.
1. Each role should have its own interface, not the same one with things hidden
A field technician, someone doing planning, and a client tracking their breakdown don’t need the same screen with different permissions: they need different screens.
In GMAO Cloud there are three: the web backend for administrators, the technician app for those doing the work, and client access for those receiving the service.
The difference shows up in adoption. A technician given a stripped-down version of the admin panel takes twice as long doing everything.
2. Profiles, and teams with a supervisor
Within each interface, which modules each person sees and what they can edit.
And something that gets overlooked until the staff grows past ten people: technicians grouped into teams with a supervisor, so each manager sees their own work instead of a list of three hundred open orders. A list you can’t take in isn’t information, it’s noise.
3. Document-by-document visibility
The control that saves the most work and gets asked about the least in a demo.
Every document in the document manager has its own visibility: whether the client sees it, whether the technician sees it, whether the supplier sees it, and whether it requires validation.
That turns a decision that repeats every week — what do I show this person — into a configuration setting. And when a supplier stops working with you, their access is revoked: the documentation stays yours and they stop seeing it, without moving a single file.
4. The client sees their own, and only their own
Scoped to their sites, their assets, their orders and their incidents.
And it’s worth knowing the limits, which in GMAO Cloud are product decisions, not shortcomings: the client can’t change an order’s status — it’s deliberately disabled — and their app doesn’t work offline; full offline mode is reserved for the technician app.
You can also control which statuses are visible to them and which stay internal, and mark the ones that shouldn’t trigger notifications.
5. Suppliers, as full-fledged users
With their own scope, receiving the work orders that correspond to them and logging times, materials, documentation and signatures. They can have their own associated warehouses and their own agreed price per item.
If they work outside the system, the history has gaps exactly where the most expensive interventions are.
6. Traceability: who did what
A record of creation, modification and deletion, with user and date. In a dispute over whether a document was delivered or a piece of data was changed, that separates fact from opinion.
And soft deletion, not hard deletion: what’s removed by mistake can be recovered.
7. A departing user shouldn’t be deleted
A case that always comes up and is worth having sorted out before it happens.
If you delete the account of a technician who leaves the company, every order they closed, every checklist they filled in and every signature they collected loses its author — and with it, its value as evidence.
The right move is to revoke access and keep the user. The work stays attributed to whoever did it, and reports for previous periods stay correct.
8. And the point that breaks everything else: per-user pricing
It looks like a pricing matter and it’s actually a permissions architecture matter.
If registering a new technician, a seasonal worker, a subcontractor or a client costs money, the decision stops being a technical one. And then the predictable thing happens: accounts get shared.
As soon as two people log in with the same user, three things break at once:
- Per-technician reports stop meaning anything.
- The history stops being valid as evidence, because you can’t tell who did what.
- The permissions system becomes decorative, because real access is whoever borrowed the password.
In GMAO Cloud, licenses are unlimited across all three plans. Whatever system you’re looking at, run the numbers with your staff size three years from now, and with clients and subcontractors included.
9. Access should be rollable out in stages
A practical requirement that only shows up during rollout: you don’t open everything on the same day.
The sensible approach is to start with the in-house team, follow with suppliers, and leave clients for when there’s already content worth showing — an empty portal generates more calls than it prevents. And within clients, open access to a pilot one first: their questions will tell you which documents need to be marked visible, which you won’t get right on the first try.
For that to be possible, the system has to let you register one access point without implying that all the others open too, and let you change a document type’s visibility without reviewing existing ones one by one.
10. Access shouldn’t depend on who configured what
Systems that have been running for years always show the same problem: permissions granted ad hoc, case by case, that nobody remembers the reason for.
The way to avoid it is working with profiles, not individual exceptions. When someone needs something their profile doesn’t provide, the right question is whether the profile is poorly defined, not whether that exception can be added.
A note on data protection
A word of caution, because this is territory where over-promising happens often.
What can be described are the controls: access by profile, configurable document visibility, action logging, recoverable deletion and revocation of third-party access. What can’t be claimed is that a piece of software guarantees compliance with any regulation: legal classification isn’t made by a program.
Be wary of anyone selling a certification where they should be describing a control.
How to test it in a demo
Three questions that get answered poorly afterward:
What exactly does a client see? Ask to see it through their access, not through a screenshot.
What happens when someone leaves the company? If the answer is “the account gets deleted,” there’s a problem with the history.
How much does it cost to add twenty more people? And a hundred clients.
If you want to see it with your own roles, you can request a demo.