Managing Roles and Permissions
The Roles page lets admins control exactly what staff and property members can do in MyWatchtower. Permissions come only from roles — per-user permission editing has been removed, so to change what someone can do you change their role (or build a new one).
Getting to the Roles page

- Step 1: Go to Settings in the left navigation.
- Step 2: Select the Roles tab. It is visible only if your role can add and edit Users.
How the role editor works
Open a role and its permissions appear as plain-language category cards — one card per area of the app (Guests, Vehicles, Entry Records, and so on). On each card you choose an access level:
- No access — the role does not see this area.
- Can view — read-only.
- Can manage — view, add, and edit.
- Full control — everything the area offers, including deleting.
- Custom — pick individual permissions when no preset fits.
A role is a named collection of these choices, and editing a role updates everyone who holds it immediately.
Community (staff) roles
The default community roles are Super Admin, Admin, Supervisor, Gate Attendant, Resident, and Pending Resident.
- Super Admin is view-only for the community: you can open it to see what it grants, but only JEKA staff can assign it, and no one at the community can edit it. Roles that hold every permission are labeled All permissions.
- Admin always keeps its user-management permissions, so admins can't lock themselves out of the Roles page.
The hierarchy and the grant ceiling
Staff roles form a ranked list, and rank is enforced everywhere roles appear:
- You can only assign or change roles below your own — rows at or above your tier are locked, and role pickers across the app disable them.
- When building or editing a role, you can only grant permissions you yourself hold; everything else is locked.
The list can be reordered, and new roles join at the bottom of the hierarchy — see Reorder the Role Hierarchy.
Property roles
Property roles define what people can do at their own property. The defaults are Owner, Manager, and Resident — the former Tenant role has been retired, and everyone who held it is now a Resident. For what each role does and how the property hierarchy is ordered, see Property Roles Explained.
Creating, cloning, and deleting roles
- New role — see Create a Custom Role.
- Clone — see Clone a Role.
- Renaming — default roles keep their names (Gate Attendant is the exception — it, like custom roles, can be renamed).
- Deleting — only non-default roles below your own tier can be deleted, and never while someone still holds them.
Viewing your own role
You can open your own role read-only at any time — a quick way to see exactly what you can and can't do. You just can't change it.
Best practices
- Prefer cloning and editing roles over asking for one-off exceptions — individual permission overrides no longer exist.
- Keep the hierarchy meaningful: a role's position determines who can grant it.
- Before removing a permission from a role, remember the change hits everyone holding that role immediately.
- If you need a Super Admin change, contact JEKA support — it cannot be done in the community.