Skip to main content
Print

Roles and permissions: what each role can do

By the end of this article you will know which role to give someone, what that role lets them see and change, and where to look when you are not sure whether a role can do a particular thing.

The five roles

Open TeamRoles & Permissions. The cards under Available Roles describe each role in a line; the tables below them are the detail.

  • Admin — full access to every section and every setting. The only role that can change the team, roles, payroll and company settings.
  • Accounting — runs the books: invoices, payments, bookkeeping and expenses. Sees everything else read-only.
  • Manager — runs the day: customers, quotes, jobs, the catalog, routes and vehicles. Works jobs in the field app too, so they can collect a payment and invoice a job on the spot, but they cannot change settings or the team.
  • Technician — works jobs in the field app: their own jobs, quotes, customers and invoices. Never deletes anything, and never sees billing, payroll, reports or settings.
  • Viewer — reads every section and changes nothing. Made for an outside accountant or auditor.

Each employee holds exactly one role, set on the Employees page. These roles are fixed — there is no custom role and no per-company override. If a role does not fit someone, choose the nearest one that does not grant more than you intend: a Viewer who needs to change one thing is a question to ask us, not a reason to make them an Admin.

Reading the permission matrix

Every menu section has two levels, and Edit implies View:

  • View — the section appears in the menu and everything in it is read-only.
  • Edit — the section can be changed. Most sections treat deleting as part of editing.
  • Edit, no delete — the section can be created and corrected but nothing in it removed. Customers and quotes are the two sections where deleting is a separate permission; a Technician can add a customer from the driveway and fix a phone number, and can never remove a customer, a vehicle or an address.
  • None — the section is not in the menu at all.

The Permission Matrix lists every section of the app, in menu order, with one column per role. Read down a role’s column to see what someone with that role gets, or across a row to see who can reach a section.

Field capabilities

Some actions do not fit the view-and-edit shape because they are narrower than a section. The Field capabilities table lists them:

  • Collecting a payment on a job, seeing that job’s invoice, creating the invoice from the job, adjusting its lines and applying a discount — the field money path, granted to Technicians and Managers so a job can be finished in the driveway without a billing role.
  • Managing their own hours and requesting time off from the field app.
  • Recording an expense — a Manager can photograph a fuel receipt from the truck without being able to change the chart of accounts.

These are deliberately separate so that giving someone the ability to collect a payment on the job they are working never gives them the billing section, which also covers refunds, credit memos and your own subscription.

A few things to know

  • Roles take effect on the next request. Changing someone’s role applies the moment you save; they do not need to sign out.
  • The matrix is generated from the rules the server enforces, so what you read here is what a request would be allowed to do — it cannot be out of date.
  • There must always be one active Admin. The app refuses to change the role of, or deactivate, the last one.
  • Platform staff are not a role you can assign. When our support team accesses your account, that access is time-limited, tagged with a reason and logged — it is not part of your team.
Table of Contents