Roles & permissions: who sees what
2 min read · Updated Jul 17, 2026
Every member has exactly one role, and every rule below is enforced in the database — removing a button never removes access; the data layer does.
| Role | In one line |
|---|---|
| Super Admin | Current staff only — the sole cross-workspace tier, used to provision tenants. |
| Tenant Admin | Runs your workspace end to end: members, roles, integrations, sync config, audit log. |
| Project Manager | Creates and edits projects, manages time and membership, sees financials. |
| Engineer | Edits their assigned tasks, logs their own time, comments. Sees financials on viewable projects. |
| Sales Manager | Owns the CRM — all companies, deals, campaigns, commissions. Reads project data, doesn't manage it. |
| Account Executive | Views any company in the workspace; edits only their own book of accounts and deals. No costs or margins outside their own deals. |
| Read-only (Partner) | External client. Only shared projects, through partner-safe views. Never any financial data. |
The scoping rules that surprise people

- +Engineers see all workspace projects, but can only edit tasks assigned to them and log their own time.
- +Sales Managers read project data like an engineer but can't edit tasks, manage membership, or configure integrations.
- +Account Executives can now VIEW any company in the workspace and find it in search — assigned to them or not — but can still only EDIT their own book (creating or changing a company, deal, activity or note on someone else's account is blocked). Sell price and margin still show only on their own deals; actual hours and budget burn stay hidden because they carry cost data.
- +Only Tenant Admins can invite users, change roles, configure integrations, or read the audit log.
- +Converting a won quote into a project is PM-and-up — Sales Managers run the CRM, not conversions.
Everyone can look up a company
There's a Companies item pinned near the top of the left menu, above Sales and above Projects, for every internal member. It's a read-only directory of your current partners (customers) — open one to see its contacts, recent support tickets, and latest activity. No dollar figures appear here: MRR, deal values, quotes and contract amounts stay with the sales team.
- +Current partners (customers) are visible to everyone on the team, view-only.
- +Prospects stay private to CRM users (anyone with CRM access) — they never appear in the everyone view.
- +Sales users (account executives, sales managers, admins) get the full CRM record with financials from the same menu item; everyone else gets the read-only slice.
- +Partner (read-only) guests never see the Companies directory or any CRM data.
Checking what a specific person sees
- 1Open Settings → MembersPick the person.
- 2Open the role previewIt renders a plain-language digest — can, sees, cannot — generated from the same rules the database enforces.
Note
Changing a role
Takes effect on the member's next request — no re-login needed. Demotions apply immediately to data access, not just navigation.
Was this helpful?
