Roles and permissions
Tenant administrators manage application access from More > Settings > Access. The access workspace includes users, roles, modules, and privileges. Job Permissions provides a second layer for operational data scope.
Access model
flowchart LR
PLAN[Subscription modules] --> ROLE[Role permissions]
ROLE --> USER[User]
USER --> SCOPE[Job and cost-code scope]
SCOPE --> RESULT[Visible pages, actions, and records]
Modules are grouped into product categories. Permissions commonly follow
view, create, edit, and delete actions, with additional workflow or
report privileges where needed.
Create or update a role
- Open Settings > Access > Roles.
- Create a role or select an existing one.
- Enable only the modules and actions required for that responsibility.
- Save the role and assign it to the appropriate users.
- Test navigation, direct page access, and record visibility with a user in that role.
Configure job permissions
Open Setup > Job Permissions to control the relationship between users or employees, jobs, and cost codes. Use this when a user can access a module but should see only part of the tenant's operational data.
User administration
Authorized users can create, update, deactivate, and reset passwords for tenant users. Deletion is a soft deactivation so historical references can be retained. When adding or reactivating a user, the tenant's subscription seat limit also applies.
Access review checklist
- Remove or deactivate access promptly when no longer needed.
- Avoid routine use of full administrator roles.
- Review sensitive billing, integration, and configuration permissions separately.
- Confirm employee linkage and data scope after changing a role.
- Use audit and access logs to investigate unexpected activity.