Skip to content
Current/ Help Center

Roles & permissions: who sees what

2 min read · Updated Sep 11, 2026

Every member has exactly one role, and every rule below is enforced in the database — removing a button never removes access; the data layer does.

RoleIn one line
Super AdminCurrent staff only — the sole cross-workspace tier, used to provision tenants.
Tenant AdminRuns your workspace end to end: members, roles, integrations, sync config, audit log.
Project ManagerCreates and edits projects, manages time and membership, sees financials.
EngineerEdits their assigned tasks, logs their own time, comments. Sees financials on viewable projects.
Sales ManagerOwns the CRM — all companies, deals, campaigns, commissions. Reads project data, doesn't manage it.
Account ExecutiveViews any company in the workspace; edits only their own book of accounts and deals. Never a raw cost rate or a per-person cost; account-level margin, cost to serve and hours only inside a company's renewal dossier.
Read-only (Partner)External client. Only shared projects, through partner-safe views. Never any financial data.

The scoping rules that surprise people

The Roles & access tab spells out exactly what each role can do.
  • Engineers see all workspace projects, but can only edit tasks assigned to them and log their own time.
  • Sales Managers read project data like an engineer but can't edit tasks, manage membership, or configure integrations. The two CRM connectors are the narrow exception: on ScalePad Lifecycle Manager and CrewHu they can test the connection, run a manual sync, map and ignore clients, disconnect, and set the alert thresholds. Saving the API key or token is Tenant Admin only, on those two as on every other connector.
  • Account Executives can now VIEW any company in the workspace and find it in search — assigned to them or not — but can still only EDIT their own book (creating or changing a company, deal, activity or note on someone else's account is blocked). Sell price and deal margin still show only on their own deals, and project hours and budget burn stay hidden because they carry cost data. One deliberate exception, added in August 2026: the renewal dossier's private profitability section, where an AE can read account-level gross margin, cost to serve, effective hourly rate and total hours for any company they can view. The breakdown by technician inside that section is workspace admins only, and the cost rates themselves are still admin only.
  • Only Tenant Admins can invite users, change roles, configure integrations, or read the audit log.
  • Converting a won quote into a project is PM-and-up — Sales Managers run the CRM, not conversions.

Everyone can look up a company

Companies heads the menu section named for whatever your workspace calls the businesses you serve (Partners, Clients, Customers), and every internal member has it. It's a read-only directory of your current partners (customers) — open one to see its contacts, recent support tickets, and latest activity. No money figures appear here: MRR, deal values, quotes and contract amounts stay with the sales team.

  • Current partners (customers) are visible to everyone on the team, view-only.
  • Prospects stay private to CRM users (anyone with CRM access) — they never appear in the everyone view.
  • Sales users (account executives, sales managers, admins) get the full CRM record with financials from the same menu item; everyone else gets the read-only slice.
  • Partner (read-only) guests never see the Companies directory or any CRM data.

Checking what a specific person sees

  1. 1
    Open Settings → Members
    Pick the person.
  2. 2
    Open the role preview
    It renders a plain-language digest — can, sees, cannot — generated from the same rules the database enforces.
Note
Changing a role
Takes effect on the member's next request — no re-login needed. Demotions apply immediately to data access, not just navigation.
Was this helpful?