Fleet software access control, down to a single vehicle

Two apps, one permission question
Who is this person, which assets may they open, and what are they allowed to change. Yipii IoT answers it with roles and visibility scope. Yipii Mobility adds job roles and a record of every edit.
A role per person
Four of them in Yipii IoT: Admin, Manager, Viewer and Driver. The role decides what someone can do once they are in.
Visibility scope
Point a person at all assets, at one or more asset groups, or at named vehicles. All assets is the default, so narrowing is a choice you make.
A sidebar that fits the job
Yipii Mobility works from seven job roles and hides the menu items a role cannot reach, so a mechanic never scrolls past a billing screen.
An audit log that keeps everything
Creates, updates and deletes across more than 30 record types, with the value before and the value after. Kept indefinitely by default.

Four roles, and nobody has to share a login
Everyone on your account gets their own login and one of four roles. An Admin can do anything, users and billing included. A Manager runs the fleet day to day on the live map and in reports, sets alerts and draws geofences, but cannot touch billing or add people. A Viewer reads and changes nothing. A Driver gets a phone-shaped view of one vehicle. Role changes take effect immediately, and there is no cap on how many people you invite, because only tracked assets count towards your plan.
- Admin is the only role that adds people or opens billing
- Manager runs the map, the reports, the alerts and the geofences
- Viewer reads dashboards and finished reports, and edits nothing
- Driver sees one vehicle, its trips and its own scores
- Invite by email, and disable a leaver without erasing their history
Three ways to decide which vehicles a person opens
A role says what someone can do. Scope says what they can do it to. You set the scope when you send the invitation, and you can change it afterwards without touching the role.
All assets
The default when you invite someone. Right for the two or three people who run the whole operation, wrong for almost everybody else.
Asset groups
Point a person at one or more groups: a depot, a department, a contract. When the work changes you move a van between groups and their access follows, instead of editing the person.
Individual assets
Name the vehicles one at a time. Most often paired with the Driver role, where one person maps to one van and the list stops there.
Some people should never hold a login. A customer who wants to watch one delivery gets a live share tracking link instead, which stops working at an expiry you set when you create it.
Share one vehicle with somebody outside the account
The garage in Qormi has your van in for a gearbox and wants the service history and the photos. They should not be holding a login to your fleet for that. In Yipii Mobility you invite them by email against that one asset, choose how far they can go, and set the date the invitation runs out.
View
Read-only. The asset details, the photos and the basic information on that record, and nothing else the account holds.
Edit
View plus writes on the asset itself. They can update its fields and add photos, which is usually as far as an outside garage needs to go.
Manage
Edit plus the records hanging off the asset: work orders, inspections and the other sub-resources attached to it.
One page lists every invitation you have sent with its status against it: pending, accepted, declined, expired or cancelled. Resend pushes the email out again to somebody who mislaid it, and cancel takes back an invitation nobody has accepted yet. The honest part is that cancel only reaches an invitation before somebody accepts it, so put an expiry date on anything temporary as you send it rather than leaving it on Never. That date is what closes the door once the work is finished.
Invitations and live share tracking links do different jobs, and it is worth keeping them apart. A link shows one asset's live position on a map to a person with no Yipii account and no login, with the tracker IMEI and your account identifiers stripped out before the position goes anywhere. An invitation goes to a named email address, is accepted by the person you sent it to, and opens the asset record rather than the map. Send a link when a customer wants to watch a van move. Send an invitation when a mechanic needs to work on one.
Included with Yipii Mobility, the add-on that extends your IoT account. One subscription covers everything in the app, so no feature here is sold on its own. What Yipii Mobility includes

Seven job roles, and a sidebar that changes with them
Yipii Mobility starts from job titles rather than permission checkboxes: Admin, Fleet Manager, Office Staff, Reports Only, Mechanic, Inspector and Driver. The sidebar hides whatever a role cannot reach, so a mechanic opens the app on work orders, parts and diagnostics and never scrolls past a procurement screen. The dashboard moves with the role too, and an Inspector lands on inspections and time entries where a Fleet Manager lands on the whole fleet. Only an Admin can change who holds which role.
- Admin holds user management, billing and settings
- Mechanic works in work orders, parts, diagnostics and recalls
- Inspector reaches inspections and time tracking, and stops there
- Reports Only reads the dashboard and the asset list
- Menu items a role cannot reach never appear in the sidebar
Included with Yipii Mobility, the add-on that extends your IoT account. One subscription covers everything in the app, so no feature here is sold on its own. What Yipii Mobility includes

Every change, with the value before and the value after
When someone edits a work order in Yipii Mobility, the log keeps the fields that actually changed, the old value, the new value, who did it and when. Creates and deletes store the full record. It covers more than 30 record types across assets, maintenance, drivers and time, inventory, compliance, users and automations. Entries are kept indefinitely by default, because rotating them out is destructive and we would rather not make that easy.
- Creates, updates and deletes across more than 30 record types
- An update stores only the fields that changed, old value and new
- Filter by user, record type, record ID, action or date range
- CSV export of the filtered list, streamed with no row limit
- Admins and fleet managers see everything, other roles only what they could already open
What fleet software access control will not do
Reads are not logged
The audit log records writes: creates, updates and deletes. Opening a record and reading it leaves no entry, so the log cannot tell you who looked at a driver file last Tuesday.
There is one exception you can switch on. Read-audit for a sensitive entity, normally documents, runs through DocumentAccessLog and has to be enabled deliberately.
There is no custom role builder
The role sets are fixed. Four in Yipii IoT, seven in Yipii Mobility, and no screen where you assemble an eighth out of individual permissions.
What you can change is which assets a person sees, which is where most requests land anyway. If a fixed role genuinely does not fit a job you have, say so on the call and we will tell you plainly whether it is on the roadmap.

The strictest version of this runs on a school bus
School transport is the hardest permission job we handle, because the people watching the map hold no account and work for nobody. A share link is still a permission grant, so it carries the same three decisions a login does: what it shows, who may open it, and when it stops working. Point one at a route and it reaches that one position. Everything else the account holds sits behind a login it does not have. The parent-facing walk-through, and what to put in the notice you give them, is on the school transport page.
- A link is scoped to one route or asset, never to the account behind it
- Four access modes, from an open URL to an approved list plus a code
- Days, hours and an expiry decide when the link works at all
- Every open is logged, with the email where the mode collects one
Frequently asked
Yes. Invite them as a user in Yipii IoT and restrict their visibility to an asset group holding the vehicles they run, or name those vehicles individually. They log in and see only those: the rest of your fleet does not appear on their live map, in their reports or in their alerts. An asset group is usually the better choice, because when the contract changes you move a van in or out of the group instead of reopening the person. If the subcontractor should not hold a login at all, send a tracking link with an expiry instead.
Yes, in Yipii Mobility. The audit log records creates, updates and deletes across more than 30 record types, from work orders and inspections to parts, purchase orders, documents, users and automations. An update stores the fields that actually changed with the old value and the new one, alongside who made the change and when. Filter by person, record type, action or date range, then export the filtered list to CSV with no row limit. Entries are kept indefinitely by default. The honest gap: reads are not logged, so opening a record leaves no entry unless you enable read-audit for sensitive documents. Yipii IoT keeps a separate activity log, which only Admins can open.
No. The role sets are fixed at four in Yipii IoT and seven in Yipii Mobility, and there is no screen where you assemble a role out of individual permissions. In practice most of what operators ask us for is about which vehicles a person should see rather than which buttons they should have, and that part is fully adjustable through asset groups. If one of the fixed roles genuinely does not match a job in your business, tell us and we will say whether it is on the roadmap instead of pretending otherwise.
There is no fixed user limit on any plan. Invite as many people as the operation needs, because only the number of tracked assets counts towards your plan. Give everyone their own login and let nobody share. It matters more than it sounds, because a shared login is the reason an audit log stops being able to answer who did something. When someone leaves you can disable them, which keeps their history intact, or remove them permanently.
In Yipii IoT only Admins can open the activity log. A Manager, a Viewer or a Driver cannot see what anybody else did, and cannot see the list of people on the account. Yipii Mobility opens it a little wider: admins and fleet managers see the whole audit log for the account, and every other role sees only entries for records they could already open. Clearing entries is not something you do from the interface. A GDPR purge goes through our support team, deliberately, so nobody removes an inconvenient afternoon on their own.
Yes, through an asset invitation in Yipii Mobility. You send it to their email address against that one asset and choose what they can do with it. View is read-only on the asset details and photos, Edit lets them update fields and add photos, and Manage adds the records hanging off the asset such as work orders and inspections. Set an expiry date as you send it, because cancel only takes back an invitation nobody has accepted yet. The invitations page lists everything you have sent with its status against it, pending, accepted, declined, expired or cancelled, and you can resend the email to somebody who mislaid it. If all they need is to see where the vehicle is, send a live share tracking link instead: that shows a position on a map and never opens the record.
The rest of the picture
The Mobility permission matrix, role by role, is written out in the roles and permissions guide, and the full list of audited record types sits in the audit log guide.
Inviting someone on the IoT side, and scoping them to a group or a named vehicle, is stepped through in the user management guide in the Yipii IoT docs.
