Skip to content

Roles and Permissions

Roles decide what people can see and do in a workspace.

Start simple. Give each person the smallest access they need to do their job. You can adjust access later.

Admins have full workspace control. They can manage users, settings, billing, permissions, and normal workspace work.

Jobs and Dispatch

Jobs, dispatch board, job records, and job files.

Time

Timesheets, clock in/out, edit requests, and time approval.

Money

Invoices, payments, financials, reports, and activity.

Operations

Inventory, fleet, and employee records. These are Manager-level by default — a Manager can work with them without being made an Admin.

Company control

Managing users, billing, and settings. This is the Admin-level bucket, and it is the only one that is.

  1. Keep at least two trusted Admins when possible.

    QELM prevents removing the last active Admin.

  2. Give office users the access they need for estimates, invoices, payments, and support.

  3. Give managers the access they need for jobs, dispatch, employees, inventory, fleet, and time.

  4. Give field users Employee access first.

  5. Only add special permission overrides when the default role does not fit.

  • A workspace must always have at least one active Admin.
  • You cannot deactivate your own account.
  • You cannot remove your own Admin role.
  • Employee users should be tied to an employee record when they are manually created.
  • Manager and Employee permissions can be customized.
  • Admin permissions are full-control and are not the normal customization path.