Skip to main content

Safety Hub permissions overview

Safety Hub permissions overview

Safety Hub controls access on two independent axes: what a user can do (capability) and what records they can see (visibility). This article explains both axes, lists every permission in each module pack, and covers the Accountable Executive and Safety Manager visibility bypass.


How the two-axis model works

Every Safety Hub user needs two things to fully work with a record:

  1. A capability permission — granted in FSP, determines which actions are available (edit, assign, configure, delete).

  2. Safety Team membership — configured inside Safety Hub, determines which records are visible.

These two axes are independent. A user with the Manage Safety Reports permission but no team assignment can see no reports. A team member without Manage Safety Reports can see their team's reports but cannot edit them. Grant both to give a user full access to their team's work.

Safety Team Settings showing Accountable Executive, Safety Managers, Safety Team Inbox, and team structure


Visibility exceptions: Accountable Executive and Safety Managers

The Accountable Executive (exactly one per operator) and any designated Safety Managers receive a read-only visibility bypass. They can see every record across the entire operator — regardless of which Safety Teams they belong to. They are also always available as assignees on any record.

This bypass applies to visibility only. To edit or manage records, they still need the relevant capability permissions.

FSP administrators do not automatically get cross-team visibility. An FSP admin who is not also designated as a Safety Manager sees only records on teams they belong to.


SMS capability permissions — 12 FSP permissions

SMS permissions live in the FSP Roles editor at Settings → Users → Roles & Permissions → Edit Role → Permissions tab, under the Safety Hub section. FSP administrators implicitly hold all 10.

FSP Roles & Permissions editor — Safety Hub and Flight Data Monitoring permission sections

UI label

Internal identifier

What it unlocks

Access Safety Hub

canAccessSafetyHub

Entry gate — required to sign in at all

Comment

canSafetyComment

Post internal and public comments on safety reports only (not hazards or corrective actions)

Manage Safety Reports

canManageSafetyReports

Edit reports, change status, assign to team or member

Manage Hazards

canManageSafetyHazards

Create/edit hazards, change risk ratings, link reports

Manage Corrective Actions

canManageSafetyCorrectiveActions

Create/edit corrective actions, assign, upload attachments

Manage Documents

canManageSafetyDocuments

Create, edit, publish, and archive documents and folders

View Analytics

canViewSafetyAnalytics

See the Analytics dashboards (Open Loop Items, Performance Assessment, Repeat Events)

Configure FRAT

canConfigureSafetyFRAT

Build FRAT forms, edit risk thresholds, manage mitigations

Delete Records

canDeleteSafetyRecords

Destructive deletes (FRAT assessments, CA attachments, folders, W&B records); requires the relevant Manage permission too

Manage Safety Hub Settings

canManageSafetyHubSettings

Full access to Settings (Safety Team, SMS, FRAT tabs). Does not grant cross-team visibility

Suggested role bundles

The guide recommends these starting-point bundles. You configure them as FSP roles.

Bundle

Permissions

Typical users

Collaborator

+ Comment

Chief Pilot, Base/Dispatch Manager

Safety Team Member

+ Manage Reports/Hazards/CAs + View Analytics

Day-to-day SMS work within team scope

Safety Manager / Admin

All 10

Full configuration + docs + deletes; designate as Safety Manager for visibility bypass


Safety Officer flag (visibility prerequisite)

Before you assign someone as Accountable Executive, Safety Manager, or Safety Team member, their FSP user record must be flagged as a Safety Officer. Safety Hub reads this flag from FSP every time a people picker opens.

If the flag is absent, the person does not appear in any picker inside Safety Hub. Removing the flag in FSP automatically removes them from all AE, SM, and team slots.

You set this flag in FSP — not inside Safety Hub. See the "Configure the Safety Team" article for step-by-step instructions.


Where to assign permissions

Permissions are in FSP — not inside Safety Hub itself.

  1. In FSP, go to Settings → Users → Roles & Permissions.

  2. Select the role you want to edit, then open the Permissions tab.

  3. Scroll to the Safety Hub section (10 permissions).

  4. Check the permissions you want to grant, then save.

For per-user overrides (without changing the base role), use the Role Override modal on the individual user's FSP record.

For a full walkthrough of setting up the Safety Team structure, see the "Configure the Safety Team" article. For first-time setup including enabling the modules, see the "Getting started with Safety Hub" article.

Did this answer your question?