Permissions Reference Guide

Quick reference guide showing what each role can do in Assignar Pay - compare permissions across all roles.

Permissions Reference Guide

This guide provides a comprehensive overview of what each role can do in Assignar Pay. Use this reference to understand the capabilities and limitations of each role when setting up your team.

Quick Comparison Table

Feature AreaOwnerAdminManagerMemberFieldCustomerSupplierVisitor
Team & Account Management
Manage billing and subscriptions
Add and remove team members
Manage team roles
Invite new team members
Manage account settings
Manage integrations
Manage API keys
Manage tags
Check the progress of background tasks
Assignar Connect
Build and manage automated workflows
Invoice Management
Create invoices
View invoices✅*
Edit invoices
Delete invoices
Send invoices
Approve invoices
Change invoice status
View invoice print templates
Create and edit invoice print templates
Delete invoice print templates
Quote Management
Create quotes
View quotes
Edit quotes
Delete quotes
Send quotes
Approve quotes
Change quote status
Create quote templates
Edit quote templates
Delete quote templates
View quote templates
Create quote assemblies
Edit quote assemblies
Delete quote assemblies
View quote assemblies
View quote print templates
Create and edit quote print templates
Delete quote print templates
Order Management
Create orders
View orders
Edit orders
Delete orders
Procurement Management
Create purchase orders
View purchase orders✅*
Edit purchase orders
Delete purchase orders
Approve purchase orders
View purchase order print templates
Create and edit purchase order print templates
Delete purchase order print templates
Manage suppliers
Invite suppliers
Submit supplier invoices
Review supplier invoices
Approve supplier invoices
Client & Project Management
Create clients
View clients
Edit clients
Delete clients
Create projects
View projects
Edit projects
Delete projects
Invite customers
Time & Payroll Management
Create timesheets
View timesheets✅*
Edit timesheets
Delete timesheets
Manage payroll
View payroll information
Rates & Scheduling
Create Schedule of Rates
View Schedule of Rates
Edit Schedule of Rates
Delete Schedule of Rates
View Schedule of Values
Create/Edit Schedule of Values
Delete Schedule of Values
View master items
Create/Edit master items
Delete master items
Financial Operations
View payment history
Process payments
View financial reports
Document Management
Create documents
View documents✅*✅*
Edit documents
Delete documents
Forms
Build and manage forms
View and respond to forms
Workpacks
View workpacks✅*✅*
Manage workpacks
Approve workpacks
Sign off workpacks✅*
Override workpack status
Override workpack sign-off rules
SMS
View SMS module
Send SMS broadcasts and replies
Manage SMS configuration
Advanced Features
Access AI features

*Customer access is limited to specifically shared information only. *Supplier access is limited to purchase orders issued to them and related invoice submission. *Assignar Connect must be switched on for your organisation before it appears in your navigation. *Field access is limited to the worker's own work. A Field user sees only their own shifts and timesheets and the workpacks assigned to them. The ❌ on "View clients/projects" refers to the clients and projects management pages; when filling a timesheet a Field user can still pick from the account's clients, projects, roles, and equipment. They file their own timesheets from My Shifts, rather than creating timesheets for others.

Note: Sender numbers for SMS are provisioned by your Account Manager. Sending SMS also requires recipients to have opted in — see the SMS guide for details.

Detailed Permissions by Category

🏢 Account & Team Management

Owner Only:

  • Complete billing and subscription control
  • Delete the entire account

Owner & Admin:

  • Add and remove team members
  • Assign and change user roles
  • Invite new team members
  • Manage account settings
  • Manage integrations with other systems
  • Manage API keys for integrations and automation

Manager:

  • Manage tags
  • Check the progress of background tasks
  • No access to billing, team membership, roles, settings, integrations, or API keys

Member and below:

  • No account or team management access

🔗 Assignar Connect

Assignar Connect is the visual workflow builder for automating work between Assignar Pay, Assignar Operations, and the other apps your business uses.

Owner, Admin & Manager:

  • Build, edit, test, and publish automated workflows
  • Connect the other apps your workflows need
  • Share a workspace with colleagues so you can build together

Everyone else:

  • No access to Connect

Connect must be switched on for your organisation before it appears in your navigation. If you cannot see it, ask your account Owner or contact us.

🔑 API Key Management

Owner & Admin:

  • Create API keys for integrations and automation
  • View and list all API keys for the account
  • Revoke (delete) API keys when needed
  • Monitor API key usage and access logs

Everyone else:

  • No access to API key management

💰 Financial Operations

Owner Only:

  • Process payments and billing
  • Delete a Schedule of Values

Owner & Admin:

  • View financial reports
  • Delete documents and print templates

Owner, Admin & Manager:

  • Create, edit, delete, send, and approve invoices
  • Change invoice status
  • View payment history

Member:

  • View invoices
  • No invoice creation or editing

⏰ Time & Payroll Management

Owner, Admin & Manager:

  • Complete payroll management
  • Full timesheet control (create, edit, delete)
  • Monitor team time allocation

Member:

  • View timesheet and payroll information for reference
  • Access time-related data for planning

Field:

  • File their own timesheets from My Shifts
  • See only their own shifts and time

📊 Project & Rate Management

Owner Only:

  • Delete a Schedule of Values
  • Delete master items

Owner & Admin:

  • Delete a Schedule of Rates

Owner, Admin & Manager:

  • Create, edit, and view Schedules of Rates and Schedules of Values
  • Create and edit master items
  • Create, edit, delete, and view clients and projects
  • Invite customers to the client portal

Member:

  • View clients, projects, rates, schedules, and master items
  • No creating, editing, or deleting

🛒 Procurement Management

Owner, Admin & Manager:

  • Complete purchase order management — create, edit, approve, and delete
  • Supplier directory management and supplier portal invitations
  • Approve supplier invoices
  • Create and edit purchase order print templates

Owner & Admin:

  • Delete purchase order print templates

Member:

  • View purchase orders
  • Submit and review supplier invoices
  • Cannot approve supplier invoices

Supplier (External Portal):

  • View purchase orders issued to their company
  • Submit invoices against approved purchase orders
  • Upload supporting documents and receipts
  • Track invoice status and communication history

📁 Document & Information Management

All Internal Roles (Owner through Member):

  • Create and edit documents
  • Access document libraries
  • Collaborate on shared documents

Supplier Access:

  • Create documents (receipts, certificates)
  • View documents related to their purchase orders
  • Upload supporting documentation

Admin & Owner Only:

  • Delete documents
  • Manage document access permissions
  • Control sharing with external parties

Customer Access:

  • View only specifically shared documents
  • Read-only access to relevant information

📝 Forms

Owner, Admin & Manager:

  • Build and manage forms (create, edit, configure workflows)
  • View and respond to forms

All Other Roles (Member, Customer, Supplier, Visitor):

  • View and respond to forms they have access to
  • The Visitor role is designed primarily around forms access — it's the most restricted role and is intended for limited or external participants who only need to fill in forms

📦 Workpacks

Owner Only:

  • Override the sign-off rules on a workpack

Owner & Admin:

  • View, manage, approve, and sign off workpacks
  • Override workpack status

Manager:

  • View, manage, approve, and sign off workpacks
  • Cannot override workpack status

Member:

  • View workpacks
  • Sign off workpacks assigned to them

Field:

  • See the full workpack (for context) when it's assigned to them or on an order they're rostered to
  • Sign off only the checkpoints assigned to them — by name or tag
  • Cannot see unrelated workpacks, or act on checkpoints assigned to someone else

Customer:

  • View workpacks that have been shared with them

💬 SMS

Recent Addition: Two-way SMS messaging for coordinating with your crew.

Owner & Admin:

  • View the SMS module (inbox, outbox, templates, groups, usage)
  • Send broadcasts and replies
  • Manage SMS configuration-level operations

Manager & Member:

  • View the SMS module
  • Send broadcasts and replies

Note: Sending SMS requires recipients to have opted in to receive messages, and a sender number must be provisioned for your account by your Account Manager. See the SMS guide for full details on consent and setup.

Understanding Permission Hierarchy

🔺 Role Hierarchy

  1. Owner (Highest authority) - Complete control
  2. Admin - Broad operational access
  3. Manager - Focused management capabilities
  4. Member - Essential work access
  5. Field - On-site workers; own shifts, timesheets, and assigned work only
  6. Customer - View-only shared access (external client portal)
  7. Supplier - External procurement portal access
  8. Visitor (Most restricted) - Forms access only

🛡️ Security Principles

Principle of Least Privilege:

  • Each role has only the access needed for their responsibilities
  • Higher roles can perform actions on lower roles but not on peers
  • Sensitive operations require higher-level authorization

Data Protection:

  • Customer data is isolated and controlled
  • Internal business data is protected from external access
  • Financial operations have additional security layers

Best Practices for Role Assignment

🎯 Choosing the Right Role

Assign Owner to:

  • Business owners and key decision-makers
  • Those who need complete financial oversight
  • Users responsible for billing and subscriptions

Assign Admin to:

  • Operations managers and senior staff
  • Those who handle daily business management
  • Users who coordinate teams and processes

Assign Manager to:

  • Project managers and team leaders
  • Department heads and supervisors
  • Those who coordinate specific business areas
  • Anyone who should be able to build automated workflows in Assignar Connect

Assign Member to:

  • Individual contributors and employees
  • Contractors and staff who need basic access
  • Those focused on specific tasks and deliverables

Assign Field to:

  • On-site crews, operators, and workers (typically on mobile)
  • Anyone who should only see their own shifts, timesheets, and assigned work
  • Workers who log their own time and complete assigned workpack checkpoints

Assign Customer to:

  • External clients and customers
  • Third-party partners with limited access needs
  • Anyone outside your organization requiring controlled access

Assign Supplier to:

  • External suppliers and vendors
  • Contractors providing goods or services
  • Service providers who fulfill purchase orders
  • Material suppliers and equipment vendors

Assign Visitor to:

  • Limited or external participants who only need to complete forms
  • Anyone who should have the most restricted access possible

🔄 Regular Review

Monthly Reviews:

  • Assess if team members have appropriate access
  • Review role assignments as responsibilities change
  • Remove access for departing team members

Quarterly Planning:

  • Evaluate role structure effectiveness
  • Plan for team growth and changing needs
  • Update permissions based on business evolution

⚠️ Common Mistakes to Avoid

  • Over-privileging: Giving higher access than needed
  • Under-privileging: Restricting access too much for job requirements
  • Inconsistent assignment: Not following clear role criteria
  • Neglecting reviews: Failing to update roles as needs change
  • Poor documentation: Not explaining role assignments to team members

Getting Help with Permissions

If you need assistance with role assignments or permissions:

  1. Review this guide to understand available options
  2. Assess your team needs and responsibilities
  3. Start conservatively with lower access levels
  4. Adjust as needed based on actual usage
  5. Contact support for complex permission scenarios

Remember that roles can be adjusted as your team and business needs evolve. Start with appropriate baseline access and refine based on actual usage and business requirements.