Roles & permissions
A workspace role is the default on every job. A job team role can replace that default on one site. Invite people under Workspace settings → Users. Edit permission bundles under Roles & permissions.
Workspace settings → Users
desktop
When to use this
Use this when someone needs a login, when a role is too broad or too narrow, or when a client should see one job only.
Do not use it to turn modules on. That is Workspace settings → Features. Do not invite a customer as a workspace seat: add them as a Customer contact on the job team.
Before you start
- You can open Users (user-management rights; typically Owner or Admin).
- You know whether they need a workspace login or job-only access.
Invite a workspace member
Open Workspace settings → Users. Choose Invite User. The dialog is Invite Workspace Member. Enter Email Address, pick Workspace Role, then Send Invite.
Pending rows show Invitation pending. You can Revoke Invitation. After they join, Change Role or Remove User.
Create a custom role (optional)
Open Roles & permissions. Choose New role. The dialog is Create custom role. Name it, tick only the bundles they need, then Create role.
On an existing role: Edit, Duplicate, or Delete. System roles can Reset defaults. Types you will see: System, Custom, and Customised.
Workspace membership roles
These names appear on a UK workspace. Owner is not offered on invite (the creator already has it).
| Role | Typical use |
|---|---|
| Owner | Billing, full workspace control, integrations, and user management |
| Admin | Full operational control without billing ownership |
| Project Manager | Broad job delivery and commercial management |
| Quantity Surveyor | Estimating, valuations, variations, and cost control |
| Buyer | Procurement, suppliers, orders, and commitments |
| Accounts | Bills, invoices, payments, and accounting workflows |
| Site Manager | Site operations and resource quantities without rates or totals |
| Site Operative | Assigned work, diary, snags, time, and material requests |
| Read-Only | Operational read access without sensitive commercial information |
If a menu is missing, the role lacks that scope (for example quotes:write or integrations:manage).
What done looks like
- The person accepts the email and appears as Active on Users.
- They see the modules their role allows.
- A custom role shows as Custom (or Customised if you later change a system role).
Common mistakes
- Inviting a customer as a workspace member. Use Client on the job team instead.
- Granting Admin because Quantity Surveyor was not quite right. Prefer New role with fewer ticks.
- Looking for a workspace seat named Customer Contact. On the job team the type is Customer contact; that uses the Client system role and is not offered on workspace invite.
Job team and snag permission keys
On Job → Team, choose Add Member. Subtabs include Workspace Team, Collaborators, and Customer Contacts. Types that are not workspace seats:
| Type | Purpose |
|---|---|
| Customer contact | Client-side visibility on that job (system role Client) |
| Collaborator | External partner with limited write access |
| Contract Administrator | Commercial / variation workflow on contract jobs |
You can also assign workspace roles on one job only (for example Site Manager on this plot). One effective role per job. Company admin permissions still come from the workspace assignment.
Snag keys (same product keys in every locale): snags:read, snags:write, snags:manage, snags:close. See Snagging.
A Site Manager can use Resources ordered for descriptions and quantities without supplier rates or order totals.