How to Configure User Roles and Permissions in Samsara - Solution for Guru

Skip to main content
Table of Contents
< All Topics
Print

How to Configure User Roles and Permissions in Samsara

Quick Summary

As a fleet grows, so does the list of people who need some level of access to Samsara – GPS Fleet Tracking Software, from dispatchers who only need to view vehicle locations to admins who manage billing and safety. This guide explains how Samsara’s role-and-tag system works, walks through the default administrative roles, and shows how to build a custom role, invite a user, and restrict that user to a specific location or asset group. Getting this configuration right keeps sensitive data restricted to the people who need it while giving everyone else exactly the access their job requires.


Why Do User Roles and Permissions Matter in Samsara?

Every organization running Samsara eventually has more than one person logging into the dashboard, and not everyone needs the same level of access. A safety manager reviewing dashcam footage has different needs than a dispatcher tracking live vehicle locations, and neither of them should necessarily see payroll or billing information. Samsara addresses this by letting administrators build a tailored account for every user, combining a role that defines what a person can do with a tag that defines where they can do it.

Getting this configuration right early pays off as the organization scales. Instead of manually deciding access for every new hire, a well-structured set of roles and tags lets administrators onboard a new dispatcher or safety coordinator in minutes, with permissions that automatically match their position rather than requiring them to start from scratch each time.

It also reduces risk on the other end of the employment lifecycle. When someone changes teams or leaves the company, a clear role structure shows administrators exactly which access they need to revoke, rather than leaving them to guess what a departing employee can still see or edit.


What Are the Two Ways Samsara Controls User Access?

Samsara separates the question of what a user can do from the question of where they can do it, and understanding that split makes the rest of the configuration much easier to reason about.

Control TypeWhat It GovernsExample
User RolesWhich actions and features a user can view or editA Safety role that can edit dashcam settings but not billing
TagsWhich specific assets, drivers, or locations a user can accessA Texas tag limiting a user to only that warehouse’s vehicles

Combining the two is what makes Samsara’s access model flexible. A Safety role paired with a Texas tag, for instance, lets a regional safety manager view and edit safety features only for vehicles and cameras tagged Texas, without ever seeing data from any other location in the organization.


What Are Samsara’s Default Administrative Roles?

Before building a custom role, it is worth knowing what Samsara offers out of the box, since the default roles cover a large share of common use cases without any extra configuration.

RoleLevel of Access
Full AdminComplete write control over the entire organization, including the ability to manage other users’ roles and access
Standard AdminFull control over the organization except for financial data such as billing, invoicing, and licensing
Read Only AdminCan view all devices and data within the assigned access level but cannot make changes
Maintenance, Safety, and similar limited rolesScoped to specific feature areas, such as vehicle maintenance or driver safety, with edit rights limited to that area

Roles and permissions marked as Highly Privileged, which typically include Full Admin and similar high-access roles, require either multi-factor authentication or single sign-on before users can use them. This adds an extra layer of protection to accounts that could cause the most damage if compromised.


How Do You Invite a New User and Assign a Role?

Adding a new administrative user to Samsara takes just a few steps, and the role assigned during this process determines their access from the moment they accept the invitation.

  1. Select the Settings icon at the bottom of the Fleet menu to open dashboard settings
  2. Go to Organization, then Users & Roles, and select + Invite User
  3. Enter the new administrator’s email address and assign a role from the dropdown
  4. Optionally select Temporary Account and set an expiration date for contractors or short-term users
  5. Assign a tag if the user needs a reduced level of access instead of full organizational visibility
  6. Save the invitation; the new user receives an email prompting them to accept and set up their account

It is worth noting that only administrators with sufficient access, such as Full or Standard Admins, can invite new users, and they can only extend a role and access level similar to their own, which keeps lower-level admins from accidentally granting themselves broader permissions.


How Do You Create a Custom Role With Granular Permissions?

Default roles cover many situations, but larger or more specialized fleets often need a role that does not match any of Samsara’s built-in options exactly. Custom roles solve this by letting an admin pick permissions feature by feature.

How Do You Name and Configure a New Role?

From Organization > Users & Roles > Roles, select + Add Role and enter a descriptive name, such as Regional Dispatcher or Southwest Safety Lead. From there, enable View or Edit permissions for each section of the dashboard, or expand a section to select individual permissions for even finer control. Samsara includes a search bar within the permissions list, so typing a keyword such as privacy, driver, or safety quickly surfaces the relevant toggles instead of scrolling through the full list.

How Do You Duplicate and Modify an Existing Role?

Rather than building every custom role from scratch, it is often faster to copy one that is close to what is needed. Open the more-actions menu next to any existing role, select Duplicate, rename the copy, and adjust the permissions from there. This also makes it possible to modify a default Samsara role, which cannot be edited directly, by duplicating it first and changing the copy instead.


How Do You Use Tags to Limit Access by Location or Asset?

Tags are what turn a role’s permissions into a scoped level of access. Instead of a Safety role automatically applying to every vehicle and camera in the organization, a tag such as a specific warehouse, region, or vehicle group narrows that role down to only the assets carrying that tag. This is particularly useful for organizations with multiple locations or business units because teams can reuse the same role definition across every region, while the tag determines which part of the fleet each user can see.

Setting up tag-based access starts with creating the tags themselves at the organization or asset level, then assigning the appropriate tag when inviting or editing a user, right alongside the role selection. Administrators can limit a user to a single tag or, in more complex organizations, assign multiple role-and-tag combinations to cover several areas of responsibility.

Consider a fleet that operates warehouses in Texas and Arizona. Rather than creating separate Safety roles for each state, an admin can build one Safety role and pair it with a Texas tag for one manager and an Arizona tag for another. Both managers have the exact same set of permissions, but each can access only the vehicles and cameras tagged to their own location. This keeps the role list short even as the number of locations grows.


How Do You Assign Multiple Roles to a Single User?

Some users legitimately need more than one type of access, and Samsara allows multiple roles to be layered onto a single account rather than forcing a single all-or-nothing choice. A common example pairs a Read Only Admin role covering the entire organization with a Maintenance role scoped to a single region, giving that person visibility into everything while limiting their edit rights to one area.

  1. Open the user’s profile from Organization > Users & Roles
  2. Select + Add Role and choose the additional role to assign
  3. Assign a tag to the new role if it should be scoped rather than organization-wide
  4. Confirm that each assigned tag is only used once across the user’s roles, since Samsara requires unique tags per role assignment
  5. Save the changes

How Do You Edit or Remove a User’s Role Later?

Access needs change as people move between teams or leave the organization, and Samsara makes updating an existing user’s access straightforward from the same Users & Roles screen used to invite them.

  • Go to Organization > Users & Roles and locate the user in the list
  • Select the more-actions menu next to their name
  • Choose Edit to change their role, access level, or assigned tag
  • Choose Delete next to a specific role to remove just that role from the user, or delete the entire account if they no longer need access
  • Save the changes to apply them immediately

For organizations onboarding or offboarding many users at once, Samsara also supports bulk upload to add new administrators or update the roles and tags of existing ones, which saves considerable time compared to editing accounts one at a time.


What Security Settings Should You Pair With Role Permissions?

Role and tag configuration controls what a user can see and do, but it works best alongside account-level security settings, especially for the most privileged accounts. Since Highly Privileged roles require multi-factor authentication or single sign-on, enabling one of these methods organization-wide before assigning Full Admin or similarly broad roles closes an obvious security gap. Even a well-scoped role provides little protection if someone can compromise the account with just a password.


Conclusion

A thoughtfully configured set of roles and tags is what keeps Samsara – GPS Fleet Tracking Software usable and secure as an organization grows past a handful of dashboard users. Starting with the default roles, layering in custom roles and tags only where the built-in options fall short, and pairing high-privilege accounts with multi-factor authentication covers the vast majority of fleets without unnecessary complexity. Organizations planning a larger rollout, or looking to align Samsara’s access model with other CRM and operational software already in use, can turn to Solution for Guru, a CRM and software implementation consultancy that helps businesses configure platforms like Samsara so permissions, data, and workflows stay consistent across every system they run.


Frequently Asked Questions

What is the difference between a user role and a tag in Samsara?

A role defines what a user can do, such as viewing safety footage or editing maintenance records, while a tag determines which specific vehicles, drivers, or locations fall under that role. Most administrative users end up with a combination of both, since a role alone does not limit which assets it covers.

Can more than one person share the same custom role?

Yes. A custom role is designed to be reused across as many users as needed. Once it is created and saved, it appears in the role dropdown for every future invitation, and existing users can also be switched onto it, which keeps permissions consistent across everyone doing the same job.

Do I need to set up multi-factor authentication for every Samsara user?

It is required for roles and permissions marked Highly Privileged, such as Full Admin, but not necessarily for every account. Many organizations choose to require multi-factor authentication or single sign-on organization-wide anyway, since it adds a meaningful layer of protection regardless of a given user’s specific role.