Roles and permissions
Sicket uses roles to decide what each user can view and manage.
Organization admins
Section titled “Organization admins”Organization admins manage the organization account.
They can usually:
- manage buildings
- manage users
- invite tenants and landlords
- invite observers where the plan allows
- review QR self-join requests
- manage billing and plan settings
- view analytics
- create staff content such as announcements, news posts, banners, and knowledge base entries
- create incidents and contractor cases
Landlords
Section titled “Landlords”Landlords manage assigned buildings.
They can usually:
- view assigned buildings
- handle tickets for assigned buildings
- review join requests for assigned buildings
- invite tenants where allowed
- create building communications where allowed
- view analytics for assigned buildings
- manage incidents and contractor cases where allowed
Observers
Section titled “Observers”Observers are read-only building stakeholders.
They can usually:
- view assigned building dashboards
- view tickets, incidents, people, announcements, news, knowledge base entries, and analytics for assigned buildings
- view staff-safe context needed for oversight
They cannot:
- respond to tickets
- add internal notes
- change ticket status
- create announcements, news posts, incidents, contractor cases, or knowledge base entries
- invite users
- change building, billing, or organization settings
Tenants
Section titled “Tenants”Tenants use Sicket for their own building.
They can usually:
- create tickets
- view their own personal tickets
- view community tickets in their building
- read building announcements
- read building news posts
- search the knowledge base
- read published building incidents
- give resolution feedback on resolved tickets
- manage their own account settings
Platform admins
Section titled “Platform admins”Platform admins manage Sicket itself. They are not part of normal building operations and should not receive tenant-facing operational notifications.
Permission source of truth
Section titled “Permission source of truth”The backend enforces permissions. The dashboard may hide buttons for clarity, but hidden buttons are not the security boundary.