Skip to content
Retailium Help Center home

Roles and access

Almost every feature in this manual behaves differently depending on your role. This article is the reference the others point back to. You do not need to memorize it: just know it exists, and that "you may not see this" usually traces back to here.

One person, one role

Every person in the platform holds exactly one role. There is no way to give one person an extra permission outside their role; changing what someone can do means changing their role, which an administrator does. Your role also decides where you land after signing in: most roles land on the dashboard, while a store associate lands directly on the incident submission form.

The roles at a glance

RoleWho they areWhat they mainly do
Platform AdministratorRetailium staffManage customer organizations. View-only on all case and incident data.
AdministratorYour organization's adminManage users, labels, and all data across the organization.
SupervisorCase managerOversee every case in the organization; assign investigators; approve decisions.
External Manager / Internal ManagerManagers over a subset of case workSame duties as a Supervisor, but only over the categories they hold.
InvestigatorField investigatorCreate and edit their own assigned cases.
ORC AnalystAnalytical supportReview and analyze case data; no editing.
Store CoordinatorStore-level field roleCreate and edit incidents, cases, and entities. Organization-wide (not territory-scoped).
Regional / District Asset Protection Manager (RAPM / DAPL)Field AP leadersTrack incidents, maintain the store registry, conduct assessments, and file accidents within their territory; manage BOLOs. No case access.
AuditorCompliance reviewerRead-only across all cases and incidents for oversight.
External PartnerLaw enforcement or agency partnerRead-only on cases explicitly shared with them.
ViewerStakeholderRead-only on specific cases they are granted.
Store AssociateStore-floor staffFile incidents and accident reports, and read their own stores' incidents: nothing else.

How access is scoped

Access is decided by four things that stack on top of each other.

Your organization's feature entitlements set the outer boundary. Your organization is entitled to some or all of four product areas (Incidents, Accidents, Cases, and Store Assessment), and you reach an area only when both your role allows it and your organization is entitled to it. Entitlements only ever withhold; they never grant a role more than it would otherwise have. Withholding an area also withdraws what depends on it: for example, without Cases there is no Case Ops Board, case dashboards, or Report Builder; without Incidents there is no Incident Heat Map. Platform administration, the store registry, notifications, search, the Lens chats, and your own profile are never withheld this way, so an organization can never be locked out of managing itself. Only Retailium sets entitlements; your administrators see the effect but cannot change them.

Your role decides which feature areas exist for you at all within what your organization has. An investigator can reach cases and BOLOs but not the reporting dashboards; an auditor can view but never edit; a store associate reaches only its intake forms and its own stores' incident list.

Territory scopes the two field asset-protection roles. Regional and District Asset Protection Managers see only the stores and incidents inside their assigned territory. Territory can be assigned by region, district, area, or individual store. An incident outside their territory is not merely hidden: opening it, exporting it, or searching for it is refused, and the refusal reads the same as "no such record." An incident with no store linked to it is invisible to these roles entirely.

Labels (the "Chinese Wall") scope case data, described next.

The Chinese Wall: how case data is compartmented

Case data sits behind a compartment system the platform calls the Chinese Wall. Its purpose is to keep one investigative team from seeing another team's cases.

Cases are organized into compartments called categories, shown as labels in the product: named, colored tags an administrator manages and assigns to both cases and users. (The same tag is called a category when assigned to a person and a label when placed on a case; they are one shared set of names.) Every case must carry at least one label. You can see a case only if you share at least one category with it, on top of any relationship requirement your role adds.

A person's categories are an access control, not a convenience. Assigning or removing someone's categories changes which cases they can reach. Removing someone's last category takes their case access away entirely.

  • Above the wall: Administrators, Supervisors, and Auditors see every case in the organization, whatever its categories.
  • Category-wide: External and Internal Managers see every case in the categories they hold, whether or not they are assigned to it. They do not bypass the wall: with no categories they see nothing.
  • Walled: Investigators, ORC Analysts, Viewers, and Store Coordinators see a case only when it is in a category they hold and they own it, are the assigned investigator, or are an accepted collaborator.
  • Invitation only: External Partners see only cases explicitly shared with them, and never see the most sensitive activity types (surveillance, controlled buys, arrests, warrants).
  • No case access: Regional and District Asset Protection Managers do not see cases at all.

The wall fails closed. A user who holds no categories sees no cases at all: including cases they personally own or are assigned to. Holding no category is an empty case list, not a fallback to your own work. Only the roles that bypass the wall entirely (Administrator, Supervisor, Auditor) are unaffected.

A change to someone's categories takes effect at their next sign-in refresh, because the category list is read from their session.

What happens when a match crosses the wall

When the platform notices that a person, vehicle, or address on your case also appears on a case in a category you cannot reach, it does not simply show you that case. If you cannot access the other case, you see only that a "locked" match exists, with a way to request access to that one specific case. Meanwhile the owner and assigned investigator of the other case are notified that a match occurred: they decide whether to share more. Each side sees only what it could already open: the other side's entity and case identity are withheld.

Your own settings are always yours

The wall governs case and organization data, not your personal settings. Your timezone, date format, and time format belong to you and follow you regardless of role or organization. Nobody, at any level, can see or change another person's display settings. See Your profile and display preferences.