πŸ‘₯ CORPORATE FLEETS Β· RBAC Β· AUDIT LOG

Separate access for dispatchers, accounting, and management β€” without sharing the admin password

cloudGPS provides role-based access for your corporate fleet. Each sub-user only sees their assigned vehicles and geofences, performs only the allowed actions, and nothing else. The audit log records who changed what and when. Reports can be delegated β€” without handing out your credentials.

Why a single shared login is a risk

In a typical fleet the monitoring system login circulates in a group chat β€” dispatchers, accounting, the manager, sometimes drivers. Someone deletes a vehicle, someone leaves for a competitor β€” and there's no way to tell who. cloudGPS solves this with per-user sub-accounts, restrictions, and an audit log.

badge

Built-in roles

Dispatcher, accountant, technician, manager β€” each with a sensible default permission set. They can be cloned and adjusted to fit your policy: a single role for the whole dispatch team.

location_off

Object-level restrictions

A sub-user only sees the vehicles assigned to them. The rest of the fleet does not exist for them. Useful when a fleet is split across branches or contractors.

map

Geofence restrictions

You can scope the console to a map β€” for example, only the city or region the user is responsible for. Data outside the geofence isn't shown, even if a vehicle crosses into that area.

history

Audit log

Every login, settings change, object deletion, or command sent is recorded with IP, time, and user. Reconstructing who changed what is a couple of clicks away.

forward_to_inbox

Delegated reports

Configure automated reports to accounting, the CEO, or the customer β€” without giving them console access. Template, frequency, and file format stay under your control.

vpn_key

2FA and password policies

Two-factor authentication for admins, mandatory password rotation every N days, no password reuse. The minimum any serious fleet's security team will expect.

Who it's for

Any fleet of 20+ vehicles with a team of more than three people already needs access separation.

support_agent Dispatch operations

Multiple dispatchers per shift, each managing their own group of vehicles. One shouldn't see another's, but the shift lead needs to see all of them.

  • One sub-user per dispatcher
  • Restrictions by vehicle group or branch
  • Log of commands sent to drivers
  • Shift lead sees subordinates' actions

account_balance Accounting and finance

They need mileage, fuel, and maintenance data for the books. Full access to the map and driver commands is unnecessary.

  • Reports-only access, no edit permissions
  • Excel/CSV export for accounting systems
  • Automated monthly reports by email
  • Audit trail of financial-data access

visibility Management and customers

A CEO or an external customer (for example, the tenant of your fleet) wants the big picture without intervening in operations.

  • "Read-only" mode with a dashboard
  • Restrictions per contract
  • Periodic summaries without logging in
  • API access via a scoped token

How it works

A sub-user is created in 30 seconds. Permissions and scopes are flexible, but presented behind clear templates for the administrator.

Pick a role

From the built-in list: dispatcher, accountant, technician, manager, read-only. Each role is a set of action permissions (map view, command sending, report access, vehicle editing).

Assign access scope

Pick the specific vehicles, groups, or geofences the sub-user can work with. Everything else does not exist for them β€” not even in search.

Create the login

Email and a one-time password for the first sign-in. The sub-user sets their own password and β€” optionally β€” enables 2FA via an authenticator app.

Operate and oversee

The sub-user sees only what's allowed in their console. The admin gets a full audit log with filters by user, vehicle, event type, and time.

cloudGPS vs shared login / basic access

Most competitors offer at most "admin" and "operator" without object-level restrictions. cloudGPS provides a full role model with geofence-level scopes.

Feature cloudGPS Single shared login Basic "admin/operator"
Per-employee loginYesNoYes
Built-in roles (dispatcher, accountant, technician)YesNoOften only 2 roles
Access restrictions to specific vehiclesYesSees everythingOften no
Geofence restrictionsYesNoneNone
Audit log with filtersYesAuthor unknownBasic log
Delegated reports by email without loginYesNoRare
2FA and password policiesYesOne password for everyoneNot always
API with sub-user scoped tokenYesNoNo

Roles and access FAQ

Everything that comes up around security and team-access organization.

How many sub-users can I create?
On the Business and Premium plans β€” unlimited. The basic plan has a limit (typically 3–5 sub-users per account). The exact policy is in your contract or can be confirmed before rollout.
What does a restricted sub-user actually see?
Only assigned vehicles β€” nothing else. They don't appear in search, on the map, or in any report. Geofence restrictions work the same way: data outside the allowed area simply isn't shown, even if a vehicle drives into it.
Can I create a custom role?
Yes. Built-in roles are templates that can be cloned and edited: enable or disable individual permissions (command sending, report export, geofence editing, and so on). Custom roles can be applied to several sub-users at once, just like standard ones.
What gets written to the audit log?
Sign-ins/outs, settings changes, object creation/deletion, commands sent to drivers, report exports, and financial-data access. Every entry records the user, IP, UTC timestamp, and the "before/after" values. The log is retained for at least 12 months.
Can access be limited by time (business hours only)?
Yes. A sub-user can have a schedule: "allowed 8:00–20:00 Mon–Fri, denied otherwise". Sign-in attempts outside the schedule are recorded as incidents and can trigger admin alerts.
How does report delegation work?
You create a report template (period, vehicles, metrics, file format), set the schedule (daily/weekly/monthly), and a list of recipient emails. cloudGPS generates the report and sends the file as an attachment. The recipient reads the report but has no console access.
Is the system GDPR-compliant?
Yes. The audit log is a minimum requirement for incident investigation. A sub-user can request data export or deletion. Data is stored in certified data centers (EU β€” Hetzner). A DPA is signed on request.

Request a free demo

We'll show how to configure roles, access scopes, and the audit log for your fleet.
We respond within 24 business hours.