Roles & permissions

What each role can open, do, and see — including who gets to see the money.

Every person in a workspace has one role. The role decides which tabs they can open, what they can do, and whose time and money they can see. Tune every role from Settings → Roles & permissions.

This screen is admin-only

Editing roles needs the manage members permission (owners and admins). If Roles & permissions isn't in your settings, your role can't change permissions — which is itself working as intended.

The roles

RoleIn short
OwnerFull control of the workspace
AdminRuns the workspace day to day
ManagerLeads a team; sees and edits their team's time
MemberTracks their own work
ViewerRead-only — a stakeholder who watches progress. Free (doesn't use a seat)

A Viewer is for the person who needs to see the work — a client-side leader, an exec, or an internal analyst — but not do it. Because they're free, they're read-only by design: they see the Hours, Engagements, Clients & projects, Tasks, and People tabs (landing on Hours), and the permissions that log time or manage the workspace can't be switched on for them (see below). The Track and Timesheet tabs — which exist to log and submit time — are hidden for viewers, who never log time, and in Settings a viewer sees only their Profile. The one power you can hand a viewer beyond seeing is Export — for the analyst who needs the numbers out — as long as they can also see all of it.

A Member tracks their own work and sees every tab except Mileage, which starts off. That's deliberate: logging travel rides on the Mileage tab, so turning it off removes the ability to log a drive — from the tab, the entry editor, and the calendar — not just the screen. Turn Mileage on for the Member role (or one person) to give travel back. A member also has no billing access by default, so money-heavy tabs adapt rather than disappear — Engagements shows budget and pace in hours (never dollars), the same way Hours drops its money columns.

Hiding Mileage removes travel logging

The Mileage tab isn't just a screen — it's the switch for logging travel anywhere. With it off, a person can still track time normally; they just can't attach a drive to an entry or log mileage. Turn it back on from the role's tabs above.

Three things a role controls

Tabs they can open

Which features show up for them at all — turn one off and it disappears from their sidebar.

What they can do

The permissions below — managing clients, inviting people, seeing money, exporting.

Whose time they can see and edit

None, their own, their team's, or everyone's — set separately for viewing and editing.

What they can do — the permissions

Eight switches, set per role in Settings → Workspace → Roles & permissions. Here's what each does and where it starts:

PermissionWhat it allowsOwnerAdminManagerMemberViewer
Track timeLog their own time
Manage clients & projectsCreate and edit clients, projects, engagements
Manage members & invitesInvite people, set roles, deactivate or remove them — who's in the workspace
Manage sharingGrant or revoke access to clients & projects (incl. outside collaborators) and appoint Project Managers — who can reach which work
See all workspace dataSee every client and project, not just what they're on
See billingRevenue, bill rates, invoices
See costs & marginCost rates, expenses, profit
Export the whole workspaceDownload everything as Excel or JSON

Most rows are editable — an admin can give a manager exports, or take billing away. Two rows are fixed. The Owner row is all-on, so a workspace always has someone who can do everything. The Viewer row is the opposite: because a viewer is free (they don't count toward your bill), the permissions that log time or change the workspace — Track time, Manage clients & projects, Manage members, Manage sharing, Manage integrations, and bulk edits — stay off, and a viewer can never be given the power to edit anyone's time. What you can grant is seeing and taking data out: the See switches (billing, costs, all workspace data), Export the whole workspace, and the view time scope — a viewer is meant to see.

Export the whole workspace also needs See all workspace data: the file contains everyone's time, so exporting can't become a way around what you can see on screen.

Billing is scoped to what you can reach. Even with See billing, money figures — like the Profitability report — cover only the clients and projects that person has access to, not the whole workspace. See all workspace data widens that to everything. So a manager with billing sees the numbers for their own clients, and an admin (who has both) sees them all.

Rates on a client or project. Anyone with See billing can open the Rates tab on a client or project and see the bill rates there; See costs adds the cost column. Setting bill rates is open to owners and admins anywhere, and to a manager on the clients and projects they manage — so a manager can price their own work. Cost rates are only ever set by owners and admins. Like everything else money, the rates shown are scoped to the clients and projects that person can access.

Viewers are free, so they're read-only

A viewer never uses a seat, so keeping them read-only is what makes that safe. If you need someone to log their own time or manage anything, give them the Member role (or higher) — that's a billable seat. This is the answer to "I gave my viewer Track time but it won't stick": it's fixed off on purpose.

Whose time — the four scopes

The third control has four levels, set separately for viewing and editing (edit has no "own"):

ScopeReaches
NoneNobody's time but the app basics
OwnOnly their own time (view only)
TeamThe teams they manage
AllEveryone in the workspace

Override tabs for one person

Beyond the role defaults, you can override which tabs a single person sees from their row on the Team page — handy when one member needs (or shouldn't have) a feature the rest of their role does.

Money is private by default

Seeing billing (revenue, bill rates) and seeing costs (cost rates, profit, margin) are separate switches, so you can hand someone revenue without exposing what people are paid. A manager starts with billing but not costs — see the table above for where every role begins.

This is usually the answer to "why can't my teammate see money columns on reports or engagements?" See costs is the deliberate "may see compensation" grant — give it to a manager and they'll see cost and margin including per person (their cost rate, and the by-person view on Profitability), scoped to the clients and projects they can reach. So hand it out only to people who should see what others are paid. Setting cost rates still never leaves owners and admins, whoever can see them.

Pick a role on the screen to see exactly what it can reach, in plain language, with financial visibility called out on its own.

Project managers

Not everyone who runs a project should run the whole workspace. A project manager manages a single client or project — with no workspace-wide admin power. You make someone one by giving them management of a specific client or project, and they can then do everything on that work:

  • Edit, archive, and delete it
  • Set up and edit its engagements
  • Manage its people — grant and revoke who's on it
  • Set its bill rates, and assign its tasks

What they don't get is anything workspace-wide: timesheet approval, seeing every client, managing members, or touching work they don't manage. Cost rates stay with owners and admins, as everywhere.

Open the client or project

From Clients & projects, open the one you want and go to its People tab.

Make them a manager

Next to someone who already has access, turn on Manages this (the crown). They're now its project manager — turn it off to hand management back. You can do the same from the other side: open the person on the Team page and flip Manage on any client or project they're on.

Promoting a manager is an admin action

Only someone with manage sharing can turn on Manages this. A project manager can add and remove collaborators on the work they run, but can't mint another manager, and can't move a project to a different client. A Viewer can never be a manager — they're read-only and free; make them a Member first. Demoting a project manager to Viewer automatically drops their management and time-logging on shared work (their access to see it stays), so read-only really means read-only.

It works from the client down

Manage a client and you manage every project under it. Manage a single project and your control stops there.

Inviting your team

Bring people in and assign them a role.

Was this helpful?
Still stuck? Contact support and we'll help.