Security clearances

Security clearances in MyGeotab manage a user's access to features and data. They determine what a user can view and interact with.

Security clearances control what users can see and do in MyGeotab. They are key to managing user access, ensuring data security, and maintaining compliance.

Clearances are assigned to users in the User Edit feature, but managed using the Clearances page. The Standard Security Clearances sheet gives a short description of each clearance for reference.

MyGeotab offers six standard security clearances:

  • Administrator: Provides access to all data and features.

  • Supervisor: Cannot manage groups, clearances, and users, and cannot change global system settings.

  • Default user: Primarily used for asset tracking.

  • Drive App user: For drivers who use the Drive App for HOS (Hours of Service).

  • View Only: Can view all data but cannot make changes.

  • Nothing: Cannot access any features.

To add or update clearances, from the main menu, navigate to People > Clearances.

Assigning clearances to an existing account

Assigning a new clearance to an existing user account overwrites their previous clearance and updates their user access.

  1. Navigate to People > Users & Drivers in the main menu.
  2. Select one or more users to edit.
  3. Under the User tab, use the Security Clearance dropdown menu to select the clearance you want to add to the user's account.
    The Edit User page showing the Security clearance field.
  4. Click Save.
Security clearances are updated immediately.

Custom clearances

Custom clearances allow you to tailor user access to your specific user roles.

If the six default clearance types available in MyGeotab do not meet your needs, you can create custom clearances to match user access settings to your user roles. Custom clearances are created by adding sub-clearances under the existing default clearance types. This is done on the Security Clearance Edit page.

Once added, a custom clearance becomes available in the Security Clearance dropdown on the User Edit page. It can then be applied to users, but it must be assigned before it takes effect.

Creating custom clearances

Create custom clearances to match user access settings to your user roles.

  1. Navigate to People > Clearances in the main menu.
  2. Select a parent clearance from the list.
    Note: Parent clearances do not need to be one of the six default clearances available. You can also create a sub-clearance from an existing sub-clearance.
  3. On the Security Clearance Edit page, click the Add Sub-Clearance button.
    The Security Clearance Edit page showing the option to add a Sub-Clearance.
  4. Enter a Name for the sub-clearance.
  5. Select the features this clearance can access.
    A sample Security Clearance Edit page.
  6. Click Save.
Your new custom clearance will now be available to select when adding or editing users.

Clearances for HOS

Configure security clearances in MyGeotab for HOS-related features in Geotab Drive.

The Drive App user default clearance provides access to HOS, asset inspection, and messaging features by default. To limit a user's access to specific features, create a sub-clearance under the Drive App user clearance and remove the clearances that do not apply to the driver's role.

Note:

Using HOS features results in additional charges if the device is not on the GO Plan. To avoid additional charges, remove the Administer HOS Logs and View HOS Logs clearances for the driver.

HOS-only access

For drivers who only need HOS features, remove the following clearances:

  • Administer Asset Inspection Logs
  • View Asset Inspection Logs
  • Send Messages
  • View Messages

Inspection-only access

For drivers who only need Asset Inspection features, remove the following clearances:

  • Administer HOS Logs
  • View HOS Logs
  • Send Messages
  • View Messages

Asset Inspection access can be further refined based on the driver's role. To restrict specific inspection actions, remove any of the following sub-clearances:

  • Mark Asset Inspection Logs as Certified
  • Mark Asset Inspection Logs as Repaired
  • Perform Asset Inspection Inspections

Messaging-only access

For drivers who only need messaging features, remove the following clearances:

  • Administer HOS Logs
  • View HOS Logs
  • Administer Asset Inspection Logs
  • View Asset Inspection Logs

Driver ID-only access

For drivers who only need to log in to identify themselves as the vehicle operator, remove the following clearances:

  • Administer Asset Inspection Logs
  • Administer Trailers
  • Exceptions Report
  • Launch Custom Reports or Add-Ins
  • Mark Asset Inspection Logs as Repaired
  • Manage Add-In Data
  • View Add-In Data
  • Send Messages
  • View Asset Inspection Logs
  • View HOS Logs
  • View Messages
  • View Trailers
  • View Routes

Allowing drivers to ignore automatically generated logs

To allow drivers to ignore automatically generated HOS logs that they have claimed, add the Ignore HOS logs clearance to their security clearance. Drivers are required to add an annotation before ignoring a log. An ignored log no longer counts towards HOS availability, but still appears during roadside checks.