Permissions Reference Guide

Quick reference guide showing what each role can do in Assignar Pay - compare permissions across all roles.

Permissions Reference Guide

This guide provides a comprehensive overview of what each role can do in Assignar Pay. Use this reference to understand the capabilities and limitations of each role when setting up your team.

Quick Comparison Table

Feature AreaOwnerAdminManagerMemberFieldCustomerSupplierVisitor
Team & Account Management
Manage billing and subscriptionsβœ…βŒβŒβŒβŒβŒβŒβŒ
Add and remove team membersβœ…βŒβŒβŒβŒβŒβŒβŒ
Manage team rolesβœ…βœ…βŒβŒβŒβŒβŒβŒ
Invite new team membersβœ…βœ…βŒβŒβŒβŒβŒβŒ
Manage account settingsβœ…βœ…βŒβŒβŒβŒβŒβŒ
Manage integrationsβœ…βœ…βŒβŒβŒβŒβŒβŒ
Manage API keysβœ…βœ…βŒβŒβŒβŒβŒβŒ
Manage tagsβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Invoice Management
Create invoicesβœ…βœ…βœ…βŒβŒβŒβŒβŒ
View invoicesβœ…βœ…βœ…βœ…βŒβœ…*❌❌
Edit invoicesβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Delete invoicesβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Send invoicesβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Approve invoicesβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Change invoice statusβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Quote Management
Create quotesβœ…βœ…βœ…βœ…βŒβŒβŒβŒ
View quotesβœ…βœ…βœ…βœ…βŒβŒβŒβŒ
Edit quotesβœ…βœ…βœ…βœ…βŒβŒβŒβŒ
Delete quotesβœ…βœ…βŒβŒβŒβŒβŒβŒ
Send quotesβœ…βœ…βŒβŒβŒβŒβŒβŒ
Approve quotesβœ…βœ…βŒβŒβŒβŒβŒβŒ
Change quote statusβœ…βœ…βŒβŒβŒβŒβŒβŒ
Create quote templatesβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Edit quote templatesβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Delete quote templatesβœ…βœ…βŒβŒβŒβŒβŒβŒ
View quote templatesβœ…βœ…βœ…βœ…βŒβŒβŒβŒ
Create quote assembliesβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Edit quote assembliesβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Delete quote assembliesβœ…βœ…βŒβŒβŒβŒβŒβŒ
View quote assembliesβœ…βœ…βœ…βœ…βŒβŒβŒβŒ
Order Management
Create ordersβœ…βœ…βœ…βŒβŒβŒβŒβŒ
View ordersβœ…βœ…βœ…βœ…βŒβŒβŒβŒ
Edit ordersβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Delete ordersβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Procurement Management
Create purchase ordersβœ…βœ…βœ…βŒβŒβŒβŒβŒ
View purchase ordersβœ…βœ…βœ…βœ…βŒβŒβœ…*❌
Edit purchase ordersβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Delete purchase ordersβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Approve purchase ordersβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Manage suppliersβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Invite suppliersβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Submit supplier invoicesβœ…βœ…βœ…βœ…βŒβŒβŒβŒ
Review supplier invoicesβœ…βœ…βœ…βœ…βŒβŒβŒβŒ
Approve supplier invoicesβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Client & Project Management
Create clientsβœ…βœ…βœ…βŒβŒβŒβŒβŒ
View clientsβœ…βœ…βœ…βœ…βŒβŒβŒβŒ
Edit clientsβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Delete clientsβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Create projectsβœ…βœ…βœ…βŒβŒβŒβŒβŒ
View projectsβœ…βœ…βœ…βœ…βŒβŒβŒβŒ
Edit projectsβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Delete projectsβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Invite customersβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Time & Payroll Management
Create timesheetsβœ…βœ…βœ…βŒβŒβŒβŒβŒ
View timesheetsβœ…βœ…βœ…βœ…βŒβœ…βŒβŒ
Edit timesheetsβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Delete timesheetsβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Manage payrollβœ…βœ…βœ…βŒβŒβŒβŒβŒ
View payroll informationβœ…βœ…βœ…βœ…βŒβŒβŒβŒ
Rates & Scheduling
Create Schedule of Ratesβœ…βœ…βœ…βŒβŒβŒβŒβŒ
View Schedule of Ratesβœ…βœ…βœ…βœ…βŒβŒβŒβŒ
Edit Schedule of Ratesβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Delete Schedule of Ratesβœ…βœ…βŒβŒβŒβŒβŒβŒ
View Schedule of Valuesβœ…βœ…βœ…βœ…βŒβŒβŒβŒ
Create/Edit Schedule of Valuesβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Delete Schedule of Valuesβœ…βœ…βŒβŒβŒβŒβŒβŒ
View master itemsβœ…βœ…βœ…βœ…βŒβŒβŒβŒ
Create/Edit master itemsβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Delete master itemsβœ…βŒβŒβŒβŒβŒβŒβŒ
Financial Operations
View payment historyβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Process paymentsβœ…βœ…βŒβŒβŒβŒβŒβŒ
View financial reportsβœ…βœ…βŒβŒβŒβŒβŒβŒ
Document Management
Create documentsβœ…βœ…βœ…βœ…βŒβŒβœ…βŒ
View documentsβœ…βœ…βœ…βœ…βŒβœ…βœ…βŒ
Edit documentsβœ…βœ…βœ…βœ…βŒβŒβŒβŒ
Delete documentsβœ…βœ…βŒβŒβŒβŒβŒβŒ
Forms
Build and manage formsβœ…βœ…βœ…βŒβŒβŒβŒβŒ
View and respond to formsβœ…βœ…βœ…βœ…βœ…βœ…βœ…βœ…
Workpacks
View workpacksβœ…βœ…βœ…βœ…βœ…βœ…βŒβŒ
Manage workpacksβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Approve workpacksβœ…βœ…βœ…βŒβŒβŒβŒβŒ
Sign off workpacksβœ…βœ…βœ…βœ…βœ…βŒβŒβŒ
Override workpack statusβœ…βœ…βŒβŒβŒβŒβŒβŒ
SMS
View SMS moduleβœ…βœ…βœ…βœ…βŒβŒβŒβŒ
Send SMS broadcasts and repliesβœ…βœ…βœ…βœ…βŒβŒβŒβŒ
Manage SMS configurationβœ…βœ…βŒβŒβŒβŒβŒβŒ
Advanced Features
Access AI featuresβœ…βœ…βœ…βœ…βŒβŒβŒβŒ

*Customer access is limited to specifically shared information only. *Supplier access is limited to purchase orders issued to them and related invoice submission. *Field access is limited to the worker's own work. A Field user sees only their own shifts and timesheets and the workpacks assigned to them. The ❌ on "View clients/projects" refers to the clients and projects management pages; when filling a timesheet a Field user can still pick from the account's clients, projects, roles, and equipment. They file their own timesheets from My Shifts, rather than creating timesheets for others.

Note: Sender numbers for SMS are provisioned by your Account Manager. Sending SMS also requires recipients to have opted in β€” see the SMS guide for details.

Detailed Permissions by Category

🏒 Account & Team Management

Owner Only:

  • Complete billing and subscription control
  • Add and remove team members
  • Assign and change user roles
  • Delete entire account or major data
  • Manage integrations with other systems

Admin Capabilities:

  • Invite new team members
  • Manage most account settings
  • Configure workflows and processes
  • Handle day-to-day team coordination
  • Manage API keys for integrations and automation

Limited Access (Manager/Member):

  • View team information
  • Access relevant account data
  • Use account features within their scope

πŸ”‘ API Key Management

Owner & Admin:

  • Create API keys for integrations and automation
  • View and list all API keys for the account
  • Revoke (delete) API keys when needed
  • Manage API key scopes and permissions
  • Monitor API key usage and access logs

Manager & Member:

  • No access to API key management
  • Cannot create, view, or delete API keys

πŸ’° Financial Operations

Owner Exclusive:

  • Process payments and billing
  • Send invoices to customers
  • Change invoice statuses
  • Delete financial records
  • Access complete financial oversight

Admin & Manager Shared:

  • Create and edit invoices
  • View financial reports and payment history
  • Handle customer billing inquiries

Manager Only:

  • View comprehensive financial data for projects
  • Access payment history for areas of responsibility

Member Access:

  • Create invoices for their work
  • View invoice status and basic information

⏰ Time & Payroll Management

Recent Update: Manager role now includes timesheet management capabilities.

Owner & Admin:

  • Complete payroll management
  • Full timesheet control (create, edit, delete)
  • Process payroll payments
  • Set compensation structures

Manager (Enhanced):

  • Create timesheets for team members
  • Edit and update timesheet entries
  • View comprehensive timesheet data
  • Monitor team time allocation

Member:

  • View timesheet information for reference
  • Access time-related data for planning

πŸ“Š Project & Rate Management

Owner Control:

  • Create and manage Schedule of Values (SOV)
  • Complete control over client relationships
  • Delete major project data

Admin Capabilities:

  • Create and manage Schedule of Rates (SOR)
  • Create and edit master items
  • Manage client relationships
  • Create, edit, delete, and view projects

Manager Access:

  • View rates and scheduling information
  • Access project data for coordination
  • Use master items for planning
  • View project information
  • Create and edit projects for their teams

Member Access:

  • View basic client and project information
  • Access data relevant to their work
  • View project details for assigned work

πŸ›’ Procurement Management

Recent Addition: Comprehensive procurement system for managing suppliers and purchase orders.

Owner & Admin:

  • Complete purchase order management (create, approve, delete)
  • Supplier directory management
  • Supplier portal access control
  • Supplier invoice approval
  • Procurement analytics and reporting

Manager (Enhanced):

  • Create and edit purchase orders
  • Review supplier invoices
  • Coordinate procurement activities
  • Track order fulfillment

Supplier (External Portal):

  • View purchase orders issued to their company
  • Submit invoices against approved purchase orders
  • Upload supporting documents and receipts
  • Track invoice status and communication history

πŸ“ Document & Information Management

All Internal Roles (Owner through Member):

  • Create and edit documents
  • Access document libraries
  • Collaborate on shared documents

Supplier Access:

  • Create documents (receipts, certificates)
  • View documents related to their purchase orders
  • Upload supporting documentation

Admin & Owner Only:

  • Delete documents
  • Manage document access permissions
  • Control sharing with external parties

Customer Access:

  • View only specifically shared documents
  • Read-only access to relevant information

πŸ“ Forms

Owner, Admin & Manager:

  • Build and manage forms (create, edit, configure workflows)
  • View and respond to forms

All Other Roles (Member, Customer, Supplier, Visitor):

  • View and respond to forms they have access to
  • The Visitor role is designed primarily around forms access β€” it's the most restricted role and is intended for limited or external participants who only need to fill in forms

πŸ“¦ Workpacks

Owner & Admin:

  • View, manage, approve, and sign off workpacks
  • Override workpack status

Manager:

  • View, manage, approve, and sign off workpacks
  • Cannot override workpack status

Member:

  • View workpacks
  • Sign off workpacks assigned to them

Field:

  • See the full workpack (for context) when it's assigned to them or on an order they're rostered to
  • Sign off only the checkpoints assigned to them β€” by name or tag
  • Cannot see unrelated workpacks, or act on checkpoints assigned to someone else

Customer:

  • View workpacks that have been shared with them

πŸ’¬ SMS

Recent Addition: Two-way SMS messaging for coordinating with your crew.

Owner & Admin:

  • View the SMS module (inbox, outbox, templates, groups, usage)
  • Send broadcasts and replies
  • Manage SMS configuration-level operations

Manager & Member:

  • View the SMS module
  • Send broadcasts and replies

Note: Sending SMS requires recipients to have opted in to receive messages, and a sender number must be provisioned for your account by your Account Manager. See the SMS guide for full details on consent and setup.

Understanding Permission Hierarchy

πŸ”Ί Role Hierarchy

  1. Owner (Highest authority) - Complete control
  2. Admin - Broad operational access
  3. Manager - Focused management capabilities
  4. Member - Essential work access
  5. Field - On-site workers; own shifts, timesheets, and assigned work only
  6. Customer - View-only shared access (external client portal)
  7. Supplier - External procurement portal access
  8. Visitor (Most restricted) - Forms access only

πŸ›‘οΈ Security Principles

Principle of Least Privilege:

  • Each role has only the access needed for their responsibilities
  • Higher roles can perform actions on lower roles but not on peers
  • Sensitive operations require higher-level authorization

Data Protection:

  • Customer data is isolated and controlled
  • Internal business data is protected from external access
  • Financial operations have additional security layers

Best Practices for Role Assignment

🎯 Choosing the Right Role

Assign Owner to:

  • Business owners and key decision-makers
  • Those who need complete financial oversight
  • Users responsible for billing and subscriptions

Assign Admin to:

  • Operations managers and senior staff
  • Those who handle daily business management
  • Users who coordinate teams and processes

Assign Manager to:

  • Project managers and team leaders
  • Department heads and supervisors
  • Those who coordinate specific business areas

Assign Member to:

  • Individual contributors and employees
  • Contractors and staff who need basic access
  • Those focused on specific tasks and deliverables

Assign Field to:

  • On-site crews, operators, and workers (typically on mobile)
  • Anyone who should only see their own shifts, timesheets, and assigned work
  • Workers who log their own time and complete assigned workpack checkpoints

Assign Customer to:

  • External clients and customers
  • Third-party partners with limited access needs
  • Anyone outside your organization requiring controlled access

Assign Supplier to:

  • External suppliers and vendors
  • Contractors providing goods or services
  • Service providers who fulfill purchase orders
  • Material suppliers and equipment vendors

Assign Visitor to:

  • Limited or external participants who only need to complete forms
  • Anyone who should have the most restricted access possible

πŸ”„ Regular Review

Monthly Reviews:

  • Assess if team members have appropriate access
  • Review role assignments as responsibilities change
  • Remove access for departing team members

Quarterly Planning:

  • Evaluate role structure effectiveness
  • Plan for team growth and changing needs
  • Update permissions based on business evolution

⚠️ Common Mistakes to Avoid

  • Over-privileging: Giving higher access than needed
  • Under-privileging: Restricting access too much for job requirements
  • Inconsistent assignment: Not following clear role criteria
  • Neglecting reviews: Failing to update roles as needs change
  • Poor documentation: Not explaining role assignments to team members

Getting Help with Permissions

If you need assistance with role assignments or permissions:

  1. Review this guide to understand available options
  2. Assess your team needs and responsibilities
  3. Start conservatively with lower access levels
  4. Adjust as needed based on actual usage
  5. Contact support for complex permission scenarios

Remember that roles can be adjusted as your team and business needs evolve. Start with appropriate baseline access and refine based on actual usage and business requirements.