Roles & permissions
A workspace role is the default on every job. A job team role can replace that default on one site. Invite people under Settings → Users. Edit permission bundles under Roles & permissions.
Settings → Users
desktop
When to use this
Use this when someone needs a login, when a role is too broad or too narrow, or when a client should see one job only.
Do not use it to turn modules on. That is Settings → Features. Do not invite a customer as a workspace seat: add them as a Customer contact on the job team.
Before you start
- You can open Users (user-management rights; typically Owner or Admin).
- You know whether they need a workspace login or job-only access.
Invite a workspace member
Open Settings → Users. Choose Invite User. The dialog is Invite Workspace Member. Enter Email Address, pick Workspace Role, then Send Invite.
Pending rows show Invitation pending. You can Revoke Invitation. After they join, Change Role or Remove User.
Create a custom role (optional)
Open Roles & permissions. Choose New role. The dialog is Create custom role. Name it, tick only the bundles they need, then Create role.
On an existing role: Edit, Duplicate, or Delete. System roles can Reset defaults. Types you will see: System, Custom, and Customised.
Workspace membership roles
These names appear on a US workspace. Owner is not offered on invite (the creator already has it).
| Role | Typical use |
|---|---|
| Owner | Billing, full workspace control, integrations, and user management |
| Admin | Full operational control without billing ownership |
| Project Manager | Broad job delivery and commercial management |
| Estimator / Cost Manager | Estimating, valuations, change orders, and cost control |
| Buyer | Procurement, vendors, orders, and commitments |
| Accounts | Bills, invoices, payments, and accounting workflows |
| Superintendent | Field operations and resource quantities without rates or totals |
| Field Worker | Assigned work, daily log, punch items, time, and material requests |
| Read-Only | Operational read access without sensitive commercial information |
If a menu is missing, the role lacks that scope (for example quotes:write or integrations:manage).
What done looks like
- The person accepts the email and appears as Active on Users.
- They see the modules their role allows.
- A custom role shows as Custom (or Customised if you later change a system role).
Common mistakes
- Inviting a customer as a workspace member. Use Client on the job team instead.
- Granting Admin because Estimator / Cost Manager was not quite right. Prefer New role with fewer ticks.
- Looking for a workspace seat named Customer Contact. On the job team the type is Customer contact; that uses the Client system role and is not offered on workspace invite.
Job team and punch-list permission keys
On Job → Team, choose Add Member. Subtabs include Workspace Team, Collaborators, and Customer Contacts. Types that are not workspace seats:
| Type | Purpose |
|---|---|
| Customer contact | Client-side visibility on that job (system role Client) |
| Collaborator | External partner with limited write access |
| Contract Administrator | Commercial / change-order workflow on contract jobs |
You can also assign workspace roles on one job only (for example Superintendent on this plot). One effective role per job. Company admin permissions still come from the workspace assignment.
Punch-list keys stay as product keys: snags:read, snags:write, snags:manage, snags:close. See Punch List.
A Superintendent can use Resources ordered for descriptions and quantities without vendor rates or order totals.