Roles & permissions
What each role can open, do, and see — including who gets to see the money.
Every person in a workspace has one role. The role decides which tabs they can open, what they can do, and whose time and money they can see. Tune every role from Settings → Roles & permissions.
Editing roles needs the manage members permission (owners and admins). If Roles & permissions isn't in your settings, your role can't change permissions — which is itself working as intended.
The roles
| Role | In short |
|---|---|
| Owner | Full control of the workspace |
| Admin | Runs the workspace day to day |
| Manager | Leads a team; sees and edits their team's time |
| Member | Tracks their own work |
| Viewer | Read-only |
Three things a role controls
Which features show up for them at all — turn one off and it disappears from their sidebar.
The permissions below — managing clients, inviting people, seeing money, exporting.
None, their own, their team's, or everyone's — set separately for viewing and editing.
What they can do — the permissions
Eight switches, set per role in Settings → Workspace → Roles & permissions. Here's what each does and where it starts:
| Permission | What it allows | Owner | Admin | Manager | Member | Viewer |
|---|---|---|---|---|---|---|
| Track time | Log their own time | ✓ | ✓ | ✓ | ✓ | — |
| Manage clients & projects | Create and edit clients, projects, engagements | ✓ | ✓ | — | — | — |
| Manage members & invites | Invite people, change roles | ✓ | ✓ | — | — | — |
| Manage sharing | Grant outside collaborators access to a client or project | ✓ | ✓ | — | — | — |
| See all workspace data | See every client and project, not just what they're on | ✓ | ✓ | — | — | — |
| See billing | Revenue, bill rates, invoices | ✓ | ✓ | ✓ | — | — |
| See costs & margin | Cost rates, expenses, profit | ✓ | ✓ | — | — | — |
| Export the whole workspace | Download everything as Excel or JSON | ✓ | ✓ | — | — | — |
Everything except the Owner row is editable — an admin can give a manager exports, or take billing away. The Owner row is fixed, so a workspace always has someone who can do everything.
Export the whole workspace also needs See all workspace data: the file contains everyone's time, so exporting can't become a way around what you can see on screen.
Whose time — the four scopes
The third control has four levels, set separately for viewing and editing (edit has no "own"):
| Scope | Reaches |
|---|---|
| None | Nobody's time but the app basics |
| Own | Only their own time (view only) |
| Team | The teams they manage |
| All | Everyone in the workspace |
Override tabs for one person
Beyond the role defaults, you can override which tabs a single person sees from their row on the Team page — handy when one member needs (or shouldn't have) a feature the rest of their role does.
Seeing billing (revenue, bill rates) and seeing costs (cost rates, profit, margin) are separate switches, so you can hand someone revenue without exposing what people are paid. A manager starts with billing but not costs — see the table above for where every role begins.
This is usually the answer to "why can't my teammate see money columns on reports or engagements?" One more thing money-related isn't in that table: cost rates never leave owners and admins, whatever the permissions say. Grant a manager "See costs & margin" and they'll see the margin, not what each person is paid.
Pick a role on the screen to see exactly what it can reach, in plain language, with financial visibility called out on its own.
Bring people in and assign them a role.