Roles & permissions
What each role can open, do, and see — including who gets to see the money.
Every person in a workspace has one role. The role decides which tabs they can open, what they can do, and whose time and money they can see. Tune every role from Settings → Roles & permissions.
Editing roles needs the manage members permission (owners and admins). If Roles & permissions isn't in your settings, your role can't change permissions — which is itself working as intended.
The roles
| Role | In short |
|---|---|
| Owner | Full control of the workspace |
| Admin | Runs the workspace day to day |
| Manager | Leads a team; sees and edits their team's time |
| Member | Tracks their own work |
| Viewer | Read-only — a stakeholder who watches progress. Free (doesn't use a seat) |
A Viewer is for the person who needs to see the work — a client-side leader, an exec, or an internal analyst — but not do it. Because they're free, they're read-only by design: they see the Hours, Engagements, Clients & projects, Tasks, and People tabs (landing on Hours), and the permissions that log time or manage the workspace can't be switched on for them (see below). The Track and Timesheet tabs — which exist to log and submit time — are hidden for viewers, who never log time, and in Settings a viewer sees only their Profile. The one power you can hand a viewer beyond seeing is Export — for the analyst who needs the numbers out — as long as they can also see all of it.
A Member tracks their own work and sees every tab except Mileage, which starts off. That's deliberate: logging travel rides on the Mileage tab, so turning it off removes the ability to log a drive — from the tab, the entry editor, and the calendar — not just the screen. Turn Mileage on for the Member role (or one person) to give travel back. A member also has no billing access by default, so money-heavy tabs adapt rather than disappear — Engagements shows budget and pace in hours (never dollars), the same way Hours drops its money columns.
The Mileage tab isn't just a screen — it's the switch for logging travel anywhere. With it off, a person can still track time normally; they just can't attach a drive to an entry or log mileage. Turn it back on from the role's tabs above.
Three things a role controls
Which features show up for them at all — turn one off and it disappears from their sidebar.
The permissions below — managing clients, inviting people, seeing money, exporting.
None, their own, their team's, or everyone's — set separately for viewing and editing.
What they can do — the permissions
Eight switches, set per role in Settings → Workspace → Roles & permissions. Here's what each does and where it starts:
| Permission | What it allows | Owner | Admin | Manager | Member | Viewer |
|---|---|---|---|---|---|---|
| Track time | Log their own time | ✓ | ✓ | ✓ | ✓ | — |
| Manage clients & projects | Create and edit clients, projects, engagements | ✓ | ✓ | — | — | — |
| Manage members & invites | Invite people, set roles, deactivate or remove them — who's in the workspace | ✓ | ✓ | — | — | — |
| Manage sharing | Grant or revoke access to clients & projects (incl. outside collaborators) and appoint Project Managers — who can reach which work | ✓ | ✓ | — | — | — |
| See all workspace data | See every client and project, not just what they're on | ✓ | ✓ | — | — | — |
| See billing | Revenue, bill rates, invoices | ✓ | ✓ | ✓ | — | — |
| See costs & margin | Cost rates, expenses, profit | ✓ | ✓ | — | — | — |
| Export the whole workspace | Download everything as Excel or JSON | ✓ | ✓ | — | — | — |
Most rows are editable — an admin can give a manager exports, or take billing away. Two rows are fixed. The Owner row is all-on, so a workspace always has someone who can do everything. The Viewer row is the opposite: because a viewer is free (they don't count toward your bill), the permissions that log time or change the workspace — Track time, Manage clients & projects, Manage members, Manage sharing, Manage integrations, and bulk edits — stay off, and a viewer can never be given the power to edit anyone's time. What you can grant is seeing and taking data out: the See switches (billing, costs, all workspace data), Export the whole workspace, and the view time scope — a viewer is meant to see.
Export the whole workspace also needs See all workspace data: the file contains everyone's time, so exporting can't become a way around what you can see on screen.
Billing is scoped to what you can reach. Even with See billing, money figures — like the Profitability report — cover only the clients and projects that person has access to, not the whole workspace. See all workspace data widens that to everything. So a manager with billing sees the numbers for their own clients, and an admin (who has both) sees them all.
Rates on a client or project. Anyone with See billing can open the Rates tab on a client or project and see the bill rates there; See costs adds the cost column. Setting bill rates is open to owners and admins anywhere, and to a manager on the clients and projects they manage — so a manager can price their own work. Cost rates are only ever set by owners and admins. Like everything else money, the rates shown are scoped to the clients and projects that person can access.
A viewer never uses a seat, so keeping them read-only is what makes that safe. If you need someone to log their own time or manage anything, give them the Member role (or higher) — that's a billable seat. This is the answer to "I gave my viewer Track time but it won't stick": it's fixed off on purpose.
Whose time — the four scopes
The third control has four levels, set separately for viewing and editing (edit has no "own"):
| Scope | Reaches |
|---|---|
| None | Nobody's time but the app basics |
| Own | Only their own time (view only) |
| Team | The teams they manage |
| All | Everyone in the workspace |
Override tabs for one person
Beyond the role defaults, you can override which tabs a single person sees from their row on the Team page — handy when one member needs (or shouldn't have) a feature the rest of their role does.
Seeing billing (revenue, bill rates) and seeing costs (cost rates, profit, margin) are separate switches, so you can hand someone revenue without exposing what people are paid. A manager starts with billing but not costs — see the table above for where every role begins.
This is usually the answer to "why can't my teammate see money columns on reports or engagements?" See costs is the deliberate "may see compensation" grant — give it to a manager and they'll see cost and margin including per person (their cost rate, and the by-person view on Profitability), scoped to the clients and projects they can reach. So hand it out only to people who should see what others are paid. Setting cost rates still never leaves owners and admins, whoever can see them.
Pick a role on the screen to see exactly what it can reach, in plain language, with financial visibility called out on its own.
Project managers
Not everyone who runs a project should run the whole workspace. A project manager manages a single client or project — with no workspace-wide admin power. You make someone one by giving them management of a specific client or project, and they can then do everything on that work:
- Edit, archive, and delete it
- Set up and edit its engagements
- Manage its people — grant and revoke who's on it
- Set its bill rates, and assign its tasks
What they don't get is anything workspace-wide: timesheet approval, seeing every client, managing members, or touching work they don't manage. Cost rates stay with owners and admins, as everywhere.
From Clients & projects, open the one you want and go to its People tab.
Next to someone who already has access, turn on Manages this (the crown). They're now its project manager — turn it off to hand management back. You can do the same from the other side: open the person on the Team page and flip Manage on any client or project they're on.
Only someone with manage sharing can turn on Manages this. A project manager can add and remove collaborators on the work they run, but can't mint another manager, and can't move a project to a different client. A Viewer can never be a manager — they're read-only and free; make them a Member first. Demoting a project manager to Viewer automatically drops their management and time-logging on shared work (their access to see it stays), so read-only really means read-only.
Manage a client and you manage every project under it. Manage a single project and your control stops there.
Bring people in and assign them a role.