This article covers the administrative side of UAS Dashboard: the role model, creating units, adding users, the difference between a user account and a pilot record, agency-wide settings, Microsoft single sign-on, and the reminder emails.
Almost everything here lives under Administration in the sidebar — the Users and Admin entries, which appear once you are a Unit Admin or above. Admin is split into three tabs: Operations, Integrations, and Organization.
Two deployment models, two admin experiences. On the shared platform at
app.uasdashboard.comyour agency is an account, and the account owner — a Global Admin — manages branding and org settings. On a dedicated Enterprise instance there are no accounts: the instance is the agency, and a System Admin holds the application-level controls. Where the two differ, this article says so.
What each role can do
There are five roles, and they are strictly hierarchical — each one includes everything below it. In order: Pilot, Supervisor, Unit Admin, Global Admin, System Admin.
| Capability | Pilot | Supervisor | Unit Admin | Global Admin | System Admin |
|---|---|---|---|---|---|
| View dashboards, flights, pilots, equipment, reports | ✓ | ✓ | ✓ | ✓ | ✓ |
| Record equipment custody; mark a pilot unavailable | ✓ | ✓ | ✓ | ✓ | ✓ |
| Create and edit flights, pilots, drones, schedule, training | — | ✓ | ✓ | ✓ | ✓ |
| Upload documents, log maintenance, export PDF reports | — | ✓ | ✓ | ✓ | ✓ |
| Manage equipment inventory and unit proficiency settings | — | — | ✓ | ✓ | ✓ |
| Manage user accounts and assign roles | — | — | ✓ | ✓ | ✓ |
| Edit unit details; grant cross-unit calendar access | — | — | ✓ | ✓ | ✓ |
| See data across all units; assign any role | — | — | — | ✓ | ✓ |
| Create units, agency branding, integrations, TFR refresh | — | — | — | — | ✓ |
Everything a Unit Admin does is scoped to their own unit: they can add, edit, and delete users there, but not move a user to another unit or touch a Global Admin. The audit log follows the same shape — pilots and supervisors see only their own activity, unit admins see their unit, global admins see all units. This matrix is also in the product, on the Users screen under What can each role do?
System Admin is not assignable on the shared platform. A Global Admin there can grant Global Admin, Unit Admin, Supervisor, and Pilot. System Admin is reserved for the platform operator. On an Enterprise instance a System Admin can grant every role including their own.
Creating and configuring units
A unit is the boundary the whole product scopes to — flights, pilots, equipment, calendars, and user visibility all hang off it. A small agency runs fine with one unit; a large one might have Air Support, Patrol, and Bomb Squad.
Creating a unit is a System Admin action (Admin → Organization → Units → Add New Unit). New accounts on the shared platform arrive with one unit already in place, named Operations. A unit has these fields:
- Unit Name — what appears everywhere else in the app.
- Unit ID — set at creation and fixed afterward.
- Status — Active, Pending, or Inactive.
- Approved Deployment Types — DFR, Field Deployments, or both.
- Notes.
To edit a unit, open Units and use the pencil icon. Unit Admins can edit their own unit; Global Admins can edit any. The eye icon opens the read view: flight and pilot counts, program managers with contact details, equipment and current custody, documents, and charts.
Two settings are per-unit but configured elsewhere. Proficiency and night-currency windows default to the org-wide policy under Admin → Training & Currency, and a unit overrides them only once someone explicitly saves unit-level values. The equipment assignment model — daily check-out/check-in, long-term assignment, or hybrid — is set from the Equipment page.
Adding users and managing access
Open Administration → Users. Two buttons create accounts: Add User, and From Pilot to pre-fill the form from a pilot record that has no login yet.
The form asks for employee number, first and last name, email, role, and unit. You never type a password: a temporary one is generated and emailed, and the user must choose their own on first sign-in. If email is not configured on the instance, that temporary password is shown on screen once so you can relay it.
To change someone later, use the pencil icon — role, unit, Account Status (Active or Disabled), and a Reset password button that issues a fresh temporary password. A few guardrails are enforced by the system rather than by convention:
- You cannot delete your own account.
- You cannot delete the last Global Admin.
- On the shared platform the account owner cannot be removed or demoted below Global Admin.
- Deleting a user requires typing their email address to confirm.
Deleting a login is permanent, but narrow. It removes the person's ability to sign in. Their pilot record, flight history, and audit entries are untouched. If you only want to stop access — for someone on leave, or to reduce billable seats on the shared platform — set Account Status to Disabled instead.
Two access controls sit outside the role model. Business booking is a per-person toggle on the user form, granted by a Global Admin, that lets a non-admin create quotes and invoices and book jobs. Cross-unit calendar access is granted from the Schedule page's Calendar Access dialog, for shift coverage. On the shared platform, the Team page is the account owner's view of the same people, alongside the account name and billing contact.
Users and pilot records — why there are two
A user is a login: an email, a password, a role, a unit. A pilot is a personnel record: certifications, currency, flight attribution, roster status. They are separate objects that get linked. Most of the time you do not have to think about it, because the product keeps them in step:
- Adding a pilot who has an email address creates a matching login — Supervisor for a manager, Pilot for a plain pilot. A pilot with no email gets a record but no login.
- If a login with that email already exists, it is linked to the new pilot record rather than duplicated.
- Going the other way, the person-plus icon on the Users screen creates a pilot or manager record from an existing user and links the two.
The Managers page is a filtered view of pilot records whose role includes manager, each carrying a manager level of unit or department. That level is a roster designation, not a permission level — what someone can do in the app is decided by their user role in the table above.
Agency settings, branding, and dashboard charts
Open Admin → Organization. On the shared platform this tab belongs to the Global Admin; on an Enterprise instance, to the System Admin.
Agency Branding is worth setting on day one:
- Agency title — the short name in the sidebar, 60 characters or fewer.
- Agency name — the full legal name printed as the header on PDF reports and exports.
- Agency state — a two-letter code that enables state-specific compliance features, such as AB 481 reporting for California.
- Agency logo and Sign-in background — PNG, JPG, SVG, WEBP, or GIF, under 500 KB and 3 MB respectively. A square logo works best.
With the ab481 feature on, the Organization tab also carries three AB 481 cards — AB 481 Program Costs (recurring line items by category, funding source, year, and amount), AB 481 Planned Acquisitions (what the agency intends to buy next year), and AB 481 Annual Statement (the internal-audit summary and any policy violations with their corrective actions). All three are Global Admin, and all three feed the annual report; see AB 481 annual reporting.
The same tab holds Units of Measurement (imperial or metric agency-wide, overridable per user in My Account), Training & Currency policy, Schedule Types, and the Business Suite master switch, which turns the client/quote/invoice tools off for an org that does not want them without discarding the data.
Choosing the home dashboard charts
Home Dashboard Charts controls what everyone sees on the home page. Add a chart from the dropdown, drag rows to reorder, set each to half or full width, and pick colors — multi-series charts get one picker per series, with a reset arrow to return to theme colors. Changes save agency-wide, so the layout you choose is the one your whole program sees. Report Charts does the same for the Program Charts section of the Reports page, and DFR Charts for the DFR page.
Microsoft single sign-on
Enterprise instances can authenticate against the agency's own Microsoft 365 / Entra ID tenant. Sign-in is invite-only: a Microsoft account works only if a user with that email already exists on the instance. SSO never creates accounts.
Setup is a short job for the agency's IT department. In the Entra admin center, register a single-tenant app, add a Web redirect URI of https://<agency>.uasdashboard.com/api/auth/callback/microsoft-entra-id, create a client secret, and send the directory (tenant) ID, application (client) ID, and secret value to whoever operates the instance. No admin-consent step is normally needed — the app requests only openid, profile, and email. Once those values are in place, the login page shows Sign in with Microsoft and a Single sign-on card appears in Admin.
Enforcement is optional and separate. Admin → Single sign-on → Require Microsoft sign-in disables web password sign-in for everyone except System Admins — the deliberate break-glass so an Entra outage can never lock the whole agency out. The login page then shows only the Microsoft button, with a small "Administrator sign-in" link revealing the password form. Enforcement covers web sign-in only; the mobile app still uses passwords, so it will not strand pilots in the field.
Verify before you enforce. Sign out and complete a Microsoft sign-in yourself first. The toggle can only be turned on while SSO is actually configured, and if the environment values are ever removed, enforcement stops applying automatically.
Notifications and reminders
Admin → Notifications & Reminders is where compliance stops depending on someone remembering. Every reminder is off until you enable it. There are six:
| Reminder | Fires when | Can notify |
|---|---|---|
| Flight proficiency | Pilot is out of flight proficiency | Pilot, Unit admin |
| Night currency | Pilot is out of night currency | Pilot, Unit admin |
| Mandated recurrent training | Pilot is overdue for department-mandated training | Pilot, Unit admin |
| Part 107 expiration | Before a pilot's Part 107 recurrency lapses | Pilot, Unit admin |
| Aircraft registration expiration | Before an aircraft's FAA registration expires | Unit admin, Global admin |
| COA / COWA expiration | Before an airspace authorization expires | Unit admin, Global admin |
Each enabled rule gets recipient checkboxes and a timing value between 1 and 365 days. For the three currency rules that number means "remind at most every N days while the pilot is out"; for the three expiration rules, "remind N days before". The windows the currency rules measure against come from Admin → Training & Currency, not this screen.
The second card records COAs and COWAs — type, name, authorization number, issue and expiry dates, notes. Nothing reminds you about an authorization you have not entered. The Part 91 COA and waiver guide covers the distinction between the two. Changing reminder settings requires Global Admin; everyone else sees the screen read-only.
Frequently asked questions
Can a Unit Admin add users to a different unit?
No. A Unit Admin's user management is confined to their own unit. They cannot create a user in another unit, move an existing user out of theirs, or edit anyone holding the Global Admin role. If you need someone who works across units, give them Global Admin. If they only need to cover another unit's calendar, use the Calendar Access dialog on the Schedule page, which grants calendar visibility without data access.
Why does a pilot I added already have a login?
Because pilot records and logins are kept in step automatically. Adding a pilot who has an email address creates a matching user account, emails a temporary password, and links the two records. Managers get Supervisor and plain pilots get Pilot. A pilot added without an email address gets a personnel record only, since there would be nothing to sign in with.
What happens to a person's flights if I delete their account?
Nothing. Deleting a user removes only the login. Their pilot record, every flight attributed to them, and their audit log entries remain exactly as they were. This is deliberate — an aviation record that could be erased by deleting a personnel account would not survive an audit. The recordkeeping guide covers what that means in practice.
Is Microsoft SSO available on the shared platform?
No. Microsoft sign-in is an Enterprise instance capability, because it authenticates against your agency's own Entra ID tenant and is configured in that instance's environment. The shared platform ignores those settings entirely. The same is true of vendor log-sync integrations, live video, the public transparency portal, DFR, and hazard reporting.
Who can change agency branding?
It depends on the deployment. On the shared platform, branding belongs to your account and the Global Admin who owns it makes the change, from either Admin → Organization or the Team page. On an Enterprise instance, branding is the whole instance's identity and only a System Admin can change it. Either way the change is live immediately — no redeploy required.
Where to go next
If you are still standing the program up, getting started covers first-run setup and the home dashboard. Once your units and users exist, set the policy the reminders enforce in training and currency, then use reports and exports to turn the resulting data into documents you can file.