Skip to content
waputuGet started
← Back to support and search

Account and team

Understand roles and facility permissions

Separate account roles, facility grants and state-system authorization.

For owners and admins · Reviewed September 9, 2026

Before you start

  • Know which tasks each teammate actually performs.
  • Treat Waputu permissions and NMS2S integration access as separate controls.

Where to click

  1. 1Team
  2. 2Facilities
  3. 3Labels or Sublots
  4. 4Settings
  5. 5Review regularly
Illustrated navigation sequence. Exact controls appear in the numbered instructions below.

Step-by-step instructions

  1. 1Team

    Review each active user and assigned role. Owners and admins handle sensitive settings and team access. Viewer access is read-only.

  2. 2Facilities

    Limit grants to the locations needed for the role. An allowed role does not automatically authorize every facility.

  3. 3Labels or Sublots

    Operational users can prepare production work when their role and facility scope allow it. A viewer cannot create sublots or save production label jobs.

  4. 4Settings

    Reserve integration and company configuration for authorized privileged users. Confirm MFA protection before changing access.

  5. 5Review regularly

    When duties change, remove unnecessary grants and disable accounts that no longer need access.

What success looks like

Users have the minimum role and location access needed; server checks enforce the scope even if someone changes a URL.

If something goes wrong

A button is missing or disabled

Check role, facility grant and installation capabilities before assuming the feature is broken.

State access changed

A Waputu grant cannot override NMS2S access restrictions. Review the integration identity separately.

Still need help?

Send the workspace, facility, safe error and approximate time. Keep credentials and private activation links out of the message.

Contact supportSearch another guide