Skip to main content

Roles & permissions

Settings6 min read

A workspace role is the default on every job. A job team role can replace that default on one site. Invite people under Settings → Users. Edit permission bundles under Roles & permissions.

When to use this

Use this when someone needs a login, when a role is too broad or too narrow, or when a client should see one job only.

Do not use it to turn modules on. That is Settings → Features. Do not invite a customer as a workspace seat: add them as a Customer contact on the job team.

Before you start

  • You can open Users (user-management rights; typically Owner or Admin).
  • You know whether they need a workspace login or job-only access.

Invite a workspace member

Open Settings → Users. Choose Invite User. The dialog is Invite Workspace Member. Enter Email Address, pick Workspace Role, then Send Invite.

Pending rows show Invitation pending. You can Revoke Invitation. After they join, Change Role or Remove User.

Create a custom role (optional)

Open Roles & permissions. Choose New role. The dialog is Create custom role. Name it, tick only the bundles they need, then Create role.

On an existing role: Edit, Duplicate, or Delete. System roles can Reset defaults. Types you will see: System, Custom, and Customised.

Workspace membership roles

These names appear on a US workspace. Owner is not offered on invite (the creator already has it).

RoleTypical use
OwnerBilling, full workspace control, integrations, and user management
AdminFull operational control without billing ownership
Project ManagerBroad job delivery and commercial management
Estimator / Cost ManagerEstimating, valuations, change orders, and cost control
BuyerProcurement, vendors, orders, and commitments
AccountsBills, invoices, payments, and accounting workflows
SuperintendentField operations and resource quantities without rates or totals
Field WorkerAssigned work, daily log, punch items, time, and material requests
Read-OnlyOperational read access without sensitive commercial information

If a menu is missing, the role lacks that scope (for example quotes:write or integrations:manage).

What done looks like

  • The person accepts the email and appears as Active on Users.
  • They see the modules their role allows.
  • A custom role shows as Custom (or Customised if you later change a system role).

Common mistakes

  • Inviting a customer as a workspace member. Use Client on the job team instead.
  • Granting Admin because Estimator / Cost Manager was not quite right. Prefer New role with fewer ticks.
  • Looking for a workspace seat named Customer Contact. On the job team the type is Customer contact; that uses the Client system role and is not offered on workspace invite.
Job team and punch-list permission keys

On Job → Team, choose Add Member. Subtabs include Workspace Team, Collaborators, and Customer Contacts. Types that are not workspace seats:

TypePurpose
Customer contactClient-side visibility on that job (system role Client)
CollaboratorExternal partner with limited write access
Contract AdministratorCommercial / change-order workflow on contract jobs

You can also assign workspace roles on one job only (for example Superintendent on this plot). One effective role per job. Company admin permissions still come from the workspace assignment.

Punch-list keys stay as product keys: snags:read, snags:write, snags:manage, snags:close. See Punch List.

A Superintendent can use Resources ordered for descriptions and quantities without vendor rates or order totals.