Admin: outlets, people and settings
Manage your outlets, departments, people, roles, and escalation settings from the admin console.
Admin is where an organisation sets up Ops: which outlets run it, the departments that organise work, the people who sign in, and the escalation settings that decide who gets emailed when things slip. It lives in the console sidebar under Admin config.
Admins get the full section. All four tabs are open to the org-wide Maska admin and to anyone holding the Ops admin role. Managers reach it too, but scoped: a manager can open Outlets, Departments, and People, and on the People tab they see and manage only the staff at their own outlets (details under People). Only org Settings stays admin-only — a manager who navigates there is sent back to Outlets.
The page has four tabs: Outlets, Departments, People, and Settings. The button in the top-right corner changes with the tab — Add outlet, New department, or Add person.
Outlets
The Outlets tab lists every outlet subscribed to Ops as a card showing its name, code, type (Outlet, Production Unit, Warehouse, or Cluster) and city. A dropdown filters between Active, Archived, and All — an archived outlet always carries an explicit Archived label, never just a different colour.
Adding an outlet. Click Add outlet. If your organisation already has outlets that aren’t on Ops yet (say, ones set up in Procurement), you first get a chooser with two paths:
- Link an existing outlet — pick an outlet you already have from the list. Linking subscribes it to Ops straight away.
- Create a new outlet — fill in a Name, a short Code (e.g. KMK), a Type, and an optional City, then click Add outlet. If the code is already taken you’ll see “Another outlet already uses this code” inline.
Any outlet added from Ops is subscribed to Ops automatically — there is no opt-out at creation.
The Ops switch. Each card carries an Ops on / Ops off switch. Turning it off unsubscribes the outlet from Ops — it stops running checklists and drops off this list (it comes back through Link an existing outlet). Clusters can’t run checklists, so their switch is locked.
Edit, archive, restore. Edit changes the outlet’s name, code, type, or city. Archive hides the outlet from the active list after a confirmation — its Ops subscription and history stay intact, and Restore brings it back any time.
Departments
Departments are the chips that organise checklists and ad hoc tasks — the same chip an admin sets here appears on tasks in the Builder and on staff rows. The tab shows one card per department (its emoji, name, and short label) plus a New department tile.
Clicking a card opens the department drawer, where you can edit the Name, an optional Short label (e.g. BKY), the Emoji, and a Tint for the chip. The drawer also offers Archive, which retires the department without deleting its history.
People
The People tab is the searchable roster of everyone with Ops access. Search matches name, phone, or email; a dropdown filters Active, Archived, or All. Each row shows the person’s name, a Manager badge where it applies, their role and outlet posting, and their department chips (“All departments” when they aren’t limited to any). As with outlets, an archived person carries an explicit Archived label.
What a manager sees here. An admin sees the whole organisation. A manager sees a scoped roster: only people posted at the manager’s own outlets, under a persistent caption “Showing staff at your outlets”. If none are assigned yet, the tab reads “No staff assigned to your outlets yet” rather than looking empty. Managers and other admins who happen to share one of your outlets still appear in the list — so your headcount reads true — but their rows are read-only to you: the edit and archive controls are disabled, with a tooltip explaining a manager can only change staff. A manager can add and edit staff (see below); only an admin manages manager- and admin-tier people.
Adding a person
Click Add person. A New / Bring existing toggle at the top of the dialog picks the path:
- New — enter their name and phone. Email is required only when the role you pick is manager-tier (manager or admin), since those roles receive escalation emails; otherwise it’s optional. If the phone or email you type already belongs to someone in your organisation, a banner appears naming who it belongs to and asking if you’d like to bring them instead — and you can’t submit until you either switch to that person or change what you typed. Submitting a genuinely new person reveals a one-time temporary PIN.
- Bring existing — search by name, phone, or email for a colleague who already has a Maska login but no Ops access yet. Rows show a masked phone/email (last 4 digits / first letter — this isn’t a full company directory) plus any other Maska modules they’re already in (e.g. “Procurement · Studio”). Pick one, then set their role, outlets, and departments — they keep their existing PIN, nothing new is shown.
Warning: The temporary PIN (New mode only) is shown once and can never be fetched again. Copy it and share it with the person before you click Done — they’ll sign in with it and be asked to set their own.
The role you pick decides the outlet posting: an org-wide role (like admin) needs no outlet, a staff role needs exactly one, and a manager role takes one or more — a manager can now run several outlets, chosen from a multi-select. Departments are optional — leaving them all unticked means the person covers all departments.
When a manager is adding the person, the outlet choices are pre-filtered to that manager’s own outlets — you can only post someone where you work — and the role is limited to staff. Managers can’t create other managers or admins.
One exception: if the person you’re bringing already holds your organisation’s org-wide admin marker, the role field narrows to admin only — they already reach every module, so Ops won’t let you post them in with a lesser role. (A manager, who can only add staff, never sees these people in the bring-existing list at all.)
Add person is the only way to bring someone onto Ops — there’s no separate onboarding-link flow to send instead.
Editing a person
Click any roster row to open the Edit person drawer. From one place you can change their name, phone, email, role, outlet posting, and departments, and reset their sign-in PIN. The outlet posting is a multi-select — a manager can be posted at several outlets — and it clears when you change the role, since each role has its own outlet rule; a manager or staff role needs at least one outlet before you can save, and Save tells you if it’s empty. Reset PIN generates a new temporary PIN, revealed once with a Copy button — the same warning as above applies. Only the fields you actually changed are saved; if one part of a save fails, the drawer stays open and tells you which part, so you can retry just that.
A manager editing here can only touch staff posted at their own outlets, and the outlet choices are limited to those outlets. A manager can’t change someone to a manager or admin role, can’t reset a manager’s or admin’s PIN, and can’t archive them — those rows are read-only to a manager. A manager also can’t move a staff member out to an outlet they don’t run, or strip an outlet the staff member holds that the manager doesn’t.
Two guards protect you from locking yourself out:
- You cannot archive your own account — the archive button is disabled on your own row.
- In the drawer, you cannot change your own role or reset your own PIN.
Archiving and reactivating
The archive button at the end of each row deactivates a person after a confirmation — they lose access and drop off the active roster, but their history stays intact. Filter to Archived and use the restore button to Reactivate them with their old role and departments.
Roles and permissions
Ops ships with three roles, assigned per person on the People tab:
- staff — the phone-first staff app: the Today board, logs, and maintenance reporting. See Your day in Ops.
- manager — the Ops Console: monitoring, checklist building, escalations, and reports — all scoped to their assigned outlets (a manager can hold one or several). A manager also manages the staff at those outlets from the People tab, but not org Settings.
- admin — everything a manager has, plus Admin config.
Each role also carries a fine-grained permission set behind the scenes (per area — checklists, tickets, logs, petty cash, reports, people — at levels from view-only up to full control); the defaults above are what those sets grant. There is no screen for editing a role’s permissions yet.
Note: The org-wide Maska admin marker sits above all of this. Someone marked as an organisation admin in Maska is an Ops admin automatically — they need no Ops role at all, and their access doesn’t depend on the role matrix. That’s why you may see full-console access for a person whose roster row shows no ops role.
Settings
The Settings tab configures the two-hop owner-escalation email flow for overdue tasks:
- Manager escalation — Notify the manager after: how many minutes past its deadline a task must be before an escalation opens and the outlet’s on-call manager is emailed.
- Owner escalation — an opt-in second hop. Switch on Escalate to the owner and set Notify the owner after: if the manager still hasn’t acted after that many minutes (counted from when the manager was first notified), the organisation owner is emailed too.
Both windows take whole minutes (1 or more); click Save changes to apply. Only the owner can change these settings — the save is rejected for anyone else. For what happens after an escalation opens — tiers, the queue, resolving and waiving — see Escalations.
Replaying the onboarding tours
Under Settings > Help, the Take the tour buttons replay the guided console tours (checklists, live tasks, escalations, your cluster and search) whenever you want a refresher — for example after a new feature lands. Staff have the same replay on their Me tab as Take the tour again.