Skip to content
Foxx Cyberfoxxcyber/docs

Users & access

Who can sign in, what each role can do, and how certifying authority is granted.

RailCompliant keeps two separate ideas apart:

  • The crew roster is everyone who works on the equipment. Labor, inspections, and crew assignments all attribute to roster people.
  • An account is someone who can sign in. Accounts are unlimited and free — you are billed per locomotive, never per person.

Most of a railroad's roster never needs an account. Give one to the people who file inspections, sign them off, manage the shop, or run the subscription.

Granting an account

An administrator does this from the person's page under Crew. Fill in the App account panel:

  • Login email — where the invitation goes.
  • Role — General or Org admin.
  • Grant certify authority — tick if this person signs off inspections.

Click Grant account & send invite.

If that email already has a RailCompliant login — a contract boiler inspector who works for several railroads, for example — the existing account is linked to your railroad and they are told they now have access. If it does not, a new login is created and they receive a single-use link to choose their own password. That link is valid for 48 hours; if it expires, grant the account again or have them use the password-reset link on the sign-in page.

Nobody ever needs to be given a password. Every account sets its own on first use, and administrators cannot see it.

Roles

General members can do the day-to-day work: add and edit locomotives, rolling stock, parts and stores; open, work and close work orders; log labor, fuel, mileage and service days; record inspections and submit them for signature; create excursions; view the compliance dashboard, the regulations library, exports, and the audit binder.

Org admins can do all of that, plus:

  • Grant, change, and revoke accounts and certifying authority.
  • Publish and unpublish a locomotive's public restoration page.
  • Create and revoke binder share links for FRA inspectors.
  • Certify the volunteer-hours report.
  • Manage billing, if they are also the railroad's owner account.

Certifying authority

Certifying authority is a permission of its own, deliberately separate from role. Doing the work and having the authority to sign for it are different things, and a general member can perfectly well hold sign-off authority while an administrator does not.

This is the permission the approval chain checks. When an inspection is submitted, only a person who holds certifying authority — through their account, not merely the roster marker — can be named as the certifying officer, and only that officer can approve or return it. See Approvals & signatures.

The same permission gates certifying a Form 4 boiler specification and freezing a 6180.49A annual record.

Changing or removing access

From the same panel on a person's page an administrator can change an existing account's Role or its certifying authority, or revoke the account entirely. Revoking removes their access to your railroad; it does not remove them from the roster and it does not touch any work already attributed to them. The person keeps their login if they hold access at another railroad.

Every grant, role change, and revocation is written to your railroad's permanent record history along with who made it.

A person can hold accounts at more than one railroad, which is how itinerant inspectors and welders work. There is no in-app switcher yet — signing in reaches the railroad the account is currently active for. Contact support if you need to move between two.

Related: Crew & qualifications for the roster itself, Billing for the owner account, and Audit binder for share links.

Last updated August 17, 2026