Skip to content
Current/ Help Center

Roles & permissions: who sees what

2 min read · Updated Jul 17, 2026

Every member has exactly one role, and every rule below is enforced in the database — removing a button never removes access; the data layer does.

RoleIn one line
Super AdminCurrent staff only — the sole cross-workspace tier, used to provision tenants.
Tenant AdminRuns your workspace end to end: members, roles, integrations, sync config, audit log.
Project ManagerCreates and edits projects, manages time and membership, sees financials.
EngineerEdits their assigned tasks, logs their own time, comments. Sees financials on viewable projects.
Sales ManagerOwns the CRM — all companies, deals, campaigns, commissions. Reads project data, doesn't manage it.
Account ExecutiveViews any company in the workspace; edits only their own book of accounts and deals. No costs or margins outside their own deals.
Read-only (Partner)External client. Only shared projects, through partner-safe views. Never any financial data.

The scoping rules that surprise people

The Roles & access tab spells out exactly what each role can do.
  • Engineers see all workspace projects, but can only edit tasks assigned to them and log their own time.
  • Sales Managers read project data like an engineer but can't edit tasks, manage membership, or configure integrations.
  • Account Executives can now VIEW any company in the workspace and find it in search — assigned to them or not — but can still only EDIT their own book (creating or changing a company, deal, activity or note on someone else's account is blocked). Sell price and margin still show only on their own deals; actual hours and budget burn stay hidden because they carry cost data.
  • Only Tenant Admins can invite users, change roles, configure integrations, or read the audit log.
  • Converting a won quote into a project is PM-and-up — Sales Managers run the CRM, not conversions.

Everyone can look up a company

There's a Companies item pinned near the top of the left menu, above Sales and above Projects, for every internal member. It's a read-only directory of your current partners (customers) — open one to see its contacts, recent support tickets, and latest activity. No dollar figures appear here: MRR, deal values, quotes and contract amounts stay with the sales team.

  • Current partners (customers) are visible to everyone on the team, view-only.
  • Prospects stay private to CRM users (anyone with CRM access) — they never appear in the everyone view.
  • Sales users (account executives, sales managers, admins) get the full CRM record with financials from the same menu item; everyone else gets the read-only slice.
  • Partner (read-only) guests never see the Companies directory or any CRM data.

Checking what a specific person sees

  1. 1
    Open Settings → Members
    Pick the person.
  2. 2
    Open the role preview
    It renders a plain-language digest — can, sees, cannot — generated from the same rules the database enforces.
Note
Changing a role
Takes effect on the member's next request — no re-login needed. Demotions apply immediately to data access, not just navigation.
Was this helpful?