AssetBolt has four roles. Every member of an organization holds exactly one.
Owner - full access to everything.
Admin - full access to everything.
Technician - can read everything, and can manage the operational records: devices, digital assets, licenses, accessories, consumables, components, people, teams, locations, vendors, maintenance, categories, asset requests, and action items.
A Technician cannot manage custom fields, the audit log, reports, organization settings, members, or API keys.
Auditor - read-only access to everything. No changes at all.
In today's permission model, Owner and Admin grant the same set of permissions. Both have full access to every resource.
The distinction between them exists at the organization level, not in what they're allowed to do inside AssetBolt.
Permissions are checked on the server for every request. The navigation menu also hides links you can't use, but that's a convenience - hiding a link is not what stops the action. The server is what enforces it.
Every change is written to an append-only audit log: who did it, what changed, and when. Device creates, updates, deletes, check-outs, check-ins, and status changes are all captured, along with the old and new values. This recording happens on every plan, whether or not your plan can view it.
Viewing the audit log requires a Pro plan or higher. Find it under Settings → Audit log, filtered by action, entity type, or date range. Each device also has its own History tab showing just that device's trail; it follows the same plan requirement.
On Core, the Audit log link stays visible in Settings, but opening it shows an upgrade prompt instead of the log.