Roles & permissions

What each role can open, do, and see — including who gets to see the money.

Every person in a workspace has one role. The role decides which tabs they can open, what they can do, and whose time and money they can see. Tune every role from Settings → Roles & permissions.

This screen is admin-only

Editing roles needs the manage members permission (owners and admins). If Roles & permissions isn't in your settings, your role can't change permissions — which is itself working as intended.

The roles

RoleIn short
OwnerFull control of the workspace
AdminRuns the workspace day to day
ManagerLeads a team; sees and edits their team's time
MemberTracks their own work
ViewerRead-only

Three things a role controls

Tabs they can open

Which features show up for them at all — turn one off and it disappears from their sidebar.

What they can do

The permissions below — managing clients, inviting people, seeing money, exporting.

Whose time they can see and edit

None, their own, their team's, or everyone's — set separately for viewing and editing.

What they can do — the permissions

Eight switches, set per role in Settings → Workspace → Roles & permissions. Here's what each does and where it starts:

PermissionWhat it allowsOwnerAdminManagerMemberViewer
Track timeLog their own time
Manage clients & projectsCreate and edit clients, projects, engagements
Manage members & invitesInvite people, change roles
Manage sharingGrant outside collaborators access to a client or project
See all workspace dataSee every client and project, not just what they're on
See billingRevenue, bill rates, invoices
See costs & marginCost rates, expenses, profit
Export the whole workspaceDownload everything as Excel or JSON

Everything except the Owner row is editable — an admin can give a manager exports, or take billing away. The Owner row is fixed, so a workspace always has someone who can do everything.

Export the whole workspace also needs See all workspace data: the file contains everyone's time, so exporting can't become a way around what you can see on screen.

Whose time — the four scopes

The third control has four levels, set separately for viewing and editing (edit has no "own"):

ScopeReaches
NoneNobody's time but the app basics
OwnOnly their own time (view only)
TeamThe teams they manage
AllEveryone in the workspace

Override tabs for one person

Beyond the role defaults, you can override which tabs a single person sees from their row on the Team page — handy when one member needs (or shouldn't have) a feature the rest of their role does.

Money is private by default

Seeing billing (revenue, bill rates) and seeing costs (cost rates, profit, margin) are separate switches, so you can hand someone revenue without exposing what people are paid. A manager starts with billing but not costs — see the table above for where every role begins.

This is usually the answer to "why can't my teammate see money columns on reports or engagements?" One more thing money-related isn't in that table: cost rates never leave owners and admins, whatever the permissions say. Grant a manager "See costs & margin" and they'll see the margin, not what each person is paid.

Pick a role on the screen to see exactly what it can reach, in plain language, with financial visibility called out on its own.

Inviting your team

Bring people in and assign them a role.

Was this helpful?
Still stuck? Contact support and we'll help.