Skip to main content

Roles and permissions

Tenant administrators manage application access from More > Settings > Access. The access workspace includes users, roles, modules, and privileges. Job Permissions provides a second layer for operational data scope.

Access model

flowchart LR
PLAN[Subscription modules] --> ROLE[Role permissions]
ROLE --> USER[User]
USER --> SCOPE[Job and cost-code scope]
SCOPE --> RESULT[Visible pages, actions, and records]

Modules are grouped into product categories. Permissions commonly follow view, create, edit, and delete actions, with additional workflow or report privileges where needed.

Create or update a role

  1. Open Settings > Access > Roles.
  2. Create a role or select an existing one.
  3. Enable only the modules and actions required for that responsibility.
  4. Save the role and assign it to the appropriate users.
  5. Test navigation, direct page access, and record visibility with a user in that role.

Configure job permissions

Open Setup > Job Permissions to control the relationship between users or employees, jobs, and cost codes. Use this when a user can access a module but should see only part of the tenant's operational data.

User administration

Authorized users can create, update, deactivate, and reset passwords for tenant users. Deletion is a soft deactivation so historical references can be retained. When adding or reactivating a user, the tenant's subscription seat limit also applies.

Access review checklist

  • Remove or deactivate access promptly when no longer needed.
  • Avoid routine use of full administrator roles.
  • Review sensitive billing, integration, and configuration permissions separately.
  • Confirm employee linkage and data scope after changing a role.
  • Use audit and access logs to investigate unexpected activity.