AssetBolt has four roles. Every member of an organization holds exactly one.
Owner - full access to everything.
Admin - full access to everything.
Technician - can read everything, and can manage the operational records: devices, digital assets, licenses, accessories, consumables, components, people, teams, locations, vendors, maintenance, categories, asset requests, and action items.
A Technician cannot manage custom fields, the audit log, reports, organization settings, members, or API keys.
Auditor - read-only access to everything. No changes at all.
In today's permission model, Owner and Admin grant the same set of permissions. Both have full access to every resource.
The distinction between them exists at the organization level, not in what they're allowed to do inside AssetBolt.
Permissions are checked on the server for every request. The navigation menu also hides links you can't use, but that's a convenience, not the guard. The server is what enforces it.
Every change is written to an append-only audit log: who did it, what changed, and when. Device creates, updates, deletes, check-outs, check-ins, and status changes are all captured, along with the old and new values. This recording happens on every plan, whether or not your plan can view it.
Viewing the audit log requires a Pro plan or higher. Find it under Settings → Audit log, filtered by action, entity type, or date range. Each device also has its own History tab showing just that device's trail; it follows the same plan requirement.
On Core, the Audit log link stays visible in Settings, but opening it shows an upgrade prompt instead of the log.
Core keeps the last 90 days of audit events.
Pro keeps the last 365 days.
Scale keeps the last 7 years (2555 days).
If you downgrade to a plan with a shorter window, AssetBolt keeps the prior plan's longer window readable and exportable for 30 days. After that grace period, the visible window shrinks to the new plan's limit and older events are purged.