Safety Hub permissions overview
Safety Hub controls access on two independent axes: what a user can do (capability) and what records they can see (visibility). This article explains both axes, lists every permission in each module pack, and covers the Accountable Executive and Safety Manager visibility bypass.
How the two-axis model works
Every Safety Hub user needs two things to fully work with a record:
A capability permission — granted in FSP, determines which actions are available (edit, assign, configure, delete).
Safety Team membership — configured inside Safety Hub, determines which records are visible.
These two axes are independent. A user with the Manage Safety Reports permission but no team assignment can see no reports. A team member without Manage Safety Reports can see their team's reports but cannot edit them. Grant both to give a user full access to their team's work.
Visibility exceptions: Accountable Executive and Safety Managers
The Accountable Executive (exactly one per operator) and any designated Safety Managers receive a read-only visibility bypass. They can see every record across the entire operator — regardless of which Safety Teams they belong to. They are also always available as assignees on any record.
This bypass applies to visibility only. To edit or manage records, they still need the relevant capability permissions.
FSP administrators do not automatically get cross-team visibility. An FSP admin who is not also designated as a Safety Manager sees only records on teams they belong to.
SMS capability permissions — 12 FSP permissions
SMS permissions live in the FSP Roles editor at Settings → Users → Roles & Permissions → Edit Role → Permissions tab, under the Safety Hub section. FSP administrators implicitly hold all 10.
UI label | Internal identifier | What it unlocks |
Access Safety Hub |
| Entry gate — required to sign in at all |
Comment |
| Post internal and public comments on safety reports only (not hazards or corrective actions) |
Manage Safety Reports |
| Edit reports, change status, assign to team or member |
Manage Hazards |
| Create/edit hazards, change risk ratings, link reports |
Manage Corrective Actions |
| Create/edit corrective actions, assign, upload attachments |
Manage Documents |
| Create, edit, publish, and archive documents and folders |
View Analytics |
| See the Analytics dashboards (Open Loop Items, Performance Assessment, Repeat Events) |
Configure FRAT |
| Build FRAT forms, edit risk thresholds, manage mitigations |
Delete Records |
| Destructive deletes (FRAT assessments, CA attachments, folders, W&B records); requires the relevant Manage permission too |
Manage Safety Hub Settings |
| Full access to Settings (Safety Team, SMS, FRAT tabs). Does not grant cross-team visibility |
Suggested role bundles
The guide recommends these starting-point bundles. You configure them as FSP roles.
Bundle | Permissions | Typical users |
Collaborator | + Comment | Chief Pilot, Base/Dispatch Manager |
Safety Team Member | + Manage Reports/Hazards/CAs + View Analytics | Day-to-day SMS work within team scope |
Safety Manager / Admin | All 10 | Full configuration + docs + deletes; designate as Safety Manager for visibility bypass |
Safety Officer flag (visibility prerequisite)
Before you assign someone as Accountable Executive, Safety Manager, or Safety Team member, their FSP user record must be flagged as a Safety Officer. Safety Hub reads this flag from FSP every time a people picker opens.
If the flag is absent, the person does not appear in any picker inside Safety Hub. Removing the flag in FSP automatically removes them from all AE, SM, and team slots.
You set this flag in FSP — not inside Safety Hub. See the "Configure the Safety Team" article for step-by-step instructions.
Where to assign permissions
Permissions are in FSP — not inside Safety Hub itself.
In FSP, go to Settings → Users → Roles & Permissions.
Select the role you want to edit, then open the Permissions tab.
Scroll to the Safety Hub section (10 permissions).
Check the permissions you want to grant, then save.
For per-user overrides (without changing the base role), use the Role Override modal on the individual user's FSP record.
For a full walkthrough of setting up the Safety Team structure, see the "Configure the Safety Team" article. For first-time setup including enabling the modules, see the "Getting started with Safety Hub" article.