Roles, permissions and feature access
Understand why two people can see different menus or perform different actions in the same workspace.
Three checks decide what you can do
A role groups permissions such as viewing a project, creating a payment or verifying a delivery. A user can have more than one role; the assigned permissions determine the available actions. Viewing a page does not automatically allow editing, approving, exporting or deleting its records.
The company must also have access to the feature through its plan, trial, purchased add-on or a grant. Buying an add-on does not give every user permission to use it. Finally, the record must allow the action: an already paid payment cannot be approved again. Some workflows also check project assignment or an organization setting.
Workspace access, role permissions, feature access and record rules all need to allow the action.
Choose a role for the work, then check its actions
The supplied role templates include Admin, Contractor, Supervisor, Accountant, Project Manager, Site Engineer, Store Manager, Procurement Officer, HR/Payroll Manager, Finance Manager and Viewer. Administrators can maintain custom roles. Treat a template as a starting point: your company may have changed it, and module-specific project restrictions are not identical everywhere.
For example, a procurement officer may prepare a PO while a separate approver authorizes it. A store manager may verify a delivery while finance records the payment. Keep those responsibilities clear rather than assuming that a job title grants every related action. See Users and role settings.
| Team responsibility | Work to enable and review |
|---|---|
| Owner or workspace administrator | Company rules, users, roles and billing; review powerful actions deliberately. |
| Project manager / site engineer / supervisor | Planning, daily records and quality work; check project-specific restrictions in each module. |
| Procurement officer / store manager | Supplier records and orders, or receipts, reservations and issues; separate order approval where needed. |
| Accountant / finance manager | Payment entry or approval, costs, client billing and reports according to granted actions. |
| HR/payroll manager / contractor lead | Workforce records, assignments, attendance and wage review as permitted. |
| Viewer | Read the permitted records without assuming create or approval rights. |
Internal users and portal contacts are different
Admin has broad workspace authority. Give a narrower role when someone needs only one extra action. A labourer or contractor directory record is not automatically a login account. Likewise, a Client directory entry does not create portal access.
Client portal access is tied to the assigned project and shared content. Vendor portal access is tied to the vendor and enabled scopes, such as viewing orders or submitting rates. Platform administrators use a separate administration area across companies; making someone a company Admin does not give them platform-admin access.
After an access change, refresh your page or sign in again if the old menu remains. If a task is still blocked, send the administrator the page, action and message shown, not your password or portal token.