One map says what each role sees and can do: which screens appear, whether they can edit projects, cards or estimates, whether they see contracts, invoices and change orders, who may approve a price and who may set their own, and whether they are trusted with admin. Crew leaders and workers get the field app instead of the dashboard. Change a role for your company, or make an exception for one person, and that is what the app draws for them — and the server checks the role on the actions that matter.
Also called: who can see what · user roles · access control · stop the crew seeing prices · permissions
Your crew opens the job without ever seeing what it sold for
Try itA man on the slab needs the job, the dates, the address and somewhere to put photos. He does not need the contract, the change orders or the invoice. In most builder software the only way to keep him out of them is to not give him an account at all. Here those three sit in their own block — Customer Documents — and are off for every field role, and the new-job card on his phone carries the dates, the address, the plans and who's going. Never the price.
A worker scrolls the project, finds the change order, and sees the job billed at $184,000 for eleven days of his crew's time — and by Thursday the whole crew has done that arithmetic in the truck.
The crew works without doing the arithmetic on what you charged versus what they're paid, so there's no Thursday-truck grumbling and no pay conversation you didn't plan. The three switches are per role, so a project manager can have them without the field getting them too.
About forty switches, grouped into the five decisions you actually make
What screens do they see, what can they change, can they see money documents, what can they do on a stage, are they trusted with admin. Every permission sits under one of those five headings instead of in one long list of flags, and the count rides on every role: Admin 40, Sales Manager 23, Sales Rep 14, Project Manager 31, Crew Leader 15, Worker 4. A wall of forty checkboxes is a screen an owner bounces off and never finishes.
You sit down to stop one man deleting things, meet forty unlabelled flags in a column, tick none of them, and every account in the company stays an admin for another year.
The owner can read a role's shape at a glance and actually finish setting it up, instead of abandoning a wall of flags halfway — so roles get set right the first week, not 'one day'. The headings are the questions an owner asks; the price of grouping is that each flag has to live somewhere, like Invite Members under Admin, because inviting is granting.
Crew leaders and workers never see the office side at all
Sign in as a crew leader or a worker and you don't get the dashboard, the pipeline, estimates or the money — you get the field app, full screen: clock in, add a photo, what's blocking you, the stage checklist. It is the same app the texted link opens, so a man with a login and a man without one see the same thing. That is the split that lets you hand over the schedule without handing over the business. The app itself is on the crew app.
You give a crew leader a login so he can mark progress, and he spends his lunch break scrolling the sales pipeline and the estimates for every job in the county.
A framer opens one screen with three big buttons and gets on with it — no menus to learn, nothing to wander into — which is why crews actually use it instead of texting the office. Giving field roles their own app, rather than a trimmed office screen, means there is no back door to the office side to forget to lock.
Your PM can see what the job sold for without being able to change it
Viewing estimates was originally closed to project managers, and every builder hit the same wall: the man running the build could not see what was sold, so he priced the change orders blind. A project manager now reads the estimate and still cannot edit it — seeing and editing are two separate switches, not one estimates door.
The PM writes the change order for the extra doors at the price he assumes you used, the customer signs it that evening, and it comes in eleven hundred dollars under the estimate nobody let him read.
The PM writes change orders at the right price because he can see what was sold — and still can't shave a number on a job that's already signed. Seeing and editing are two switches, kept apart on purpose, because the person running delivery is the one with a reason to trim a price that's running over.
Approving a rep's price and pricing your own are two different switches
A line priced off its catalog rate locks the estimate until someone who can approve signs off — or sets their own number for it. Who can do that is a permission, and so is the other half: setting your own prices off catalog and sending without waiting. Admins and sales managers hold both from the start; a sales rep holds neither, so his off-catalog price waits for a sign-off. The lock reads the same permissions this screen sets. The approval itself is on pricing approvals.
Your best salesman quotes a barndominium at a number he's sure of, and the estimate sits locked until Monday because the only approver is on vacation.
The owner decides who is trusted with his margin, and a trusted sales manager never waits in a queue to quote — while a new rep's discount still gets a second look. Approving somebody else's price and pricing your own are split because one is authority over colleagues and the other is trust with your own work.
A sales manager runs the bench without becoming a second admin
The Sales Manager role is a rep who can also lead: he approves prices, prices his own work, sees every lead, and invites and manages sales reps — their details and accounts, nobody else's. He does not get Manage Users, Delete Items, the crews or the account's settings. When he invites, the only role on his menu is Sales Rep, and the server refuses anything else.
To let your sales manager add his own reps you make him an admin, and a month later he has changed the crew pay settings and the company's phone numbers.
The person running sales can hire, coach and unblock his reps without phoning the owner — and the owner keeps the money, the crews and the account to himself. It is its own role rather than a stripped-down admin because a manager role that quietly becomes a second admin is how accounts lose control.
Permissions are decided on the server, not in the browser
An earlier version kept per-man overrides in the browser's own storage, which meant an employee who knew how to open the inspector could tick himself into anything. They were pulled out. Hiding the button and refusing the action are now the same rule. A permission system that only hides controls is a suggestion.
A worker opens the inspector on a Sunday, writes himself into the admin role, reads the whole pipeline, and there is nothing anywhere that says he did.
An employee can't tick himself into the money screens from his own browser, so the owner doesn't have to wonder who's been reading what. A person's access is worked out on the server, in order — the role, your account's version of it, then any exception for that one person — and the actions that matter are checked again when they arrive.
An account with no role gets the least access, not the most
It used to be the other way round. A man who reached the sign-in page without going through his invitation arrived with every tab on screen and no data behind any of it. Anybody without a role is now treated as a worker — which means the field app, with a note that there's nothing to show until he's on a crew — and the screen waits for his role to load before it decides what to draw.
The new hire lands on the sign-in page instead of his invite link, gets every tab in the business, and rings you to say the sales pipeline is broken because there is nothing in it.
A mix-up at sign-up leaves the new hire with too little rather than too much, so the worst case is a phone call, not a stranger reading your pipeline. The role is written onto the account by the invitation, and the wait-for-load stops anyone seeing an admin screen for a second and watching it vanish.
One crew cannot see another crew's jobs, or what another crew got paid
With View All Crews off, the schedule and the dashboard contain that person's own crew's projects only, and the crew filter isn't there to be found — and the field app only ever shows a crew its own jobs. It is applied to the project list itself rather than to the filter, so a control leaking through changes nothing. This page decides who is allowed to look at a crew's pay; what that pay is made of — the pool, the day rates and the surplus — is on day rates with shared surplus.
Two crews compare notes at the yard on Friday, one worked out from the schedule that the other's job ran four days shorter for the same money, and Monday starts with a pay conversation you did not plan.
Crews compare notes at the yard; when each only sees its own jobs, nobody works out another crew's take from the schedule and Monday doesn't start with a pay argument. Filtering the list rather than the chips is the whole decision — a leaked chip then shows nothing new.
A worker holds four of the forty, and logs his own work
Home, the dashboard, the schedule and My Work — that is 4 of 40, and Home is the one every role gets. In practice a worker lives in the field app: he clocks in on the job he's on, and his hours wait for somebody who can approve them. No contacts, no estimates, no invoicing, no other crew's week. Most of what he needs never asks him to sign in at all — the day a crew leader opens on his phone is on the crew app.
You give a labourer a login so he can put his own hours in, and he arrives on the contacts list holding every customer's phone number you have.
A labourer can put his own hours in without being handed every customer's phone number, so the owner can give the whole crew access without thinking twice. The worker role was built up from nothing rather than trimmed down from admin, and what he submits lands in a queue a manager has to look at.
The man who logs the hours is not the man who approves them
My Work and Approve Labor are two separate switches. A crew leader holds the first and not the second, so his own hours land in a queue somebody else clears. A project manager holds both. A leader punching in the man who left his phone in the truck is this same permission working on a jobsite, and that record — including whose name goes on it — is on the jobsite punch clock.
Friday's sheet says forty hours on a stage the crew was on for three days, and it is already sitting in the job's costs before anybody has read it.
Hours get a second pair of eyes before they turn into pay, so an honest 32-hour week and a generous one never look the same in your job costs. My Work and Approve Labor are separate switches — a crew leader holds the first, a project manager both — and the cost is a queue the office clears each week.
One person, one switch — and the screen shows his real settings
Try itA role is the starting point. Any single ability can be turned on or off for one named person on top of it — Marcus the rep who also needs to see change orders. His card shows his own settings: black follows his role, accent is an exception for him alone, and it keeps overriding the role even if you edit the role later. Tick it back to the role's value and the exception really clears. You cannot take admin off yourself, so nobody locks the company out of its own settings.
One estimator needs to see change orders, so he is made an admin for a fortnight, and eighteen months later he still is.
The owner fixes the one rep who needs one extra thing in ten seconds, without inventing a role or handing out an admin login nobody takes back — and what he sees on the card is exactly what that rep gets. When the exception spreads to the whole role, change the role itself in permission presets.
The settings link somebody forwards him opens his own profile
Most Settings tabs are admin-only, Roles & Access among them. A man without Manage Users who follows a link straight into one of them lands on My Profile — not an error, not a blank page. The same holds for a deep link into a view his role cannot see: the app falls back to a screen he does have. If you want to be sure before you send it, look at the app through his eyes first.
Your office manager forwards a settings link to a sales rep to be helpful, and he spends ten minutes on a white page deciding whether to ring you about it or just ignore the software from now on.
A rep or a project manager who follows a forwarded link lands somewhere sensible instead of a white page, so nobody decides the software is broken. The fallback watches the view as well as the role, because a blank page reads as a bug rather than as a rule being kept.
A role starts on the roster, and stops there too
Permissions only exist where there is an account to hold them; the full list of everyone who works here, login or no login, sits on the team members tab. Most of a builder's roster has no login at all, and the count line says so out loud. When a man leaves you switch him off rather than delete him, and that is done from his row on the same tab.
A crew leader quits on the Friday, nobody thinks about the account, and in November he can still open the schedule on his own phone and read every job you have on.
The owner switches off a leaver the same day and keeps every log, photo and signature they ever wrote — so the question 'who ticked that checkpoint in March?' still has an answer. Switching off and deleting are kept as two different actions for exactly that reason.
Once a year somebody has to read the list
Everyone who can sign in, at what role, and when they last did it — on one panel. Marking it reviewed freezes a dated snapshot of exactly that list against the name of the admin who read it. It goes overdue after a year and says so.
The rep who left in March still has a working login in November, and you find out while filling in a security questionnaire for the one commercial customer who asked.
The owner can hand an insurer or a commercial customer proof of who held access on a given date, instead of a promise. The snapshot is stored, not rebuilt from today's roster, because a review is a claim about a moment.
Closing out a stage belongs to the crew leader
Finishing a stage is not a private act — the customer is told, the office is told, and the next stage's clock starts. So in the field app the crew leader is the one who can close a stage; a worker can't, unless your account opens it to the whole crew. What a man without it sees when he taps the box, and that one setting, are on ticking the work off from a phone.
A first-week labourer taps the last checkpoint on Framing, and the customer gets a stage-complete email about a wall that is not sheeted yet.
The customer only hears 'framing is done' from the man responsible for it, so a first-week labourer can't send a premature stage-complete email about a wall that isn't sheeted. It follows the leader rather than a checkbox because the leader is the one standing there answerable for it.
- 1Every person carries one of six roles.
- 2The role decides which screens they see and what they can change on them.
- 3Crew leaders and workers sign in to the field app, never the office dashboard.
- 4Contracts, invoices and change orders sit in their own block — off for every field role.
- 5Your account can redefine a role, and one person can carry an exception on top of it.
- 6The server refuses what a role cannot do, whatever a screen shows.
- 7A person with no role set is treated as a worker, never as an admin.
Three things went wrong and all three are closed. Per-person overrides used to live in the browser's own storage — an employee who knew how to open the inspector could tick himself into anything, your money screens included. An account with no role set used to be treated as an admin: a new hire who landed on the sign-in page instead of his invitation saw every screen in the business with no data behind any of it. And the switches a builder set on the permissions screen once saved without reaching the people they were for — a rep ticked on for Contacts still had no Contacts tab. Now everything fails closed, and what you set is what they get.
- Everyone who could sign in saw everything.
- Permission overrides could be self-granted from the browser.
- A user with no role defaulted to full access.
- Permission changes on the settings screen did not reach the person.
- There was nothing between a sales rep and an admin for the person running sales.
Permissions grouped into five plain questions
The same five groups are used on a man's own card and in the presets editor, so both screens speak the same language. Every switch carries a plain label — 'My Work (field log)', 'Edit Stage Details & Landmarks' — instead of shorthand only the people who built it would recognise.
Plain-English explanation of every permission
Permission names are shorthand and the consequences are not obvious. Each explanation names what the switch really controls and gives an example in the words the app uses. Manage Building Plans, for instance, notes that everybody can already view and download plans — that switch only decides who can link or unlink one.
Change one man's permissions without changing the role
The grid on a man's card shows what he actually gets — his role's answer unless you have overridden it. Change one and it is stored as his. Set it back to the role's answer and the override is deleted, not kept as a redundant copy. Changing his role clears his overrides.
Crews only see their own work
One switch that changes what the schedule and the dashboard contain, not just what the filter offers. Crew leaders and workers have it off by default. Admins, sales and project managers have it on.
An unknown account gets the least access, not the most
The app reads a man's role off his account and falls back to worker when there is not one. It also waits until the role has finished loading before drawing the menu, so nothing renders off a guess.
Roles & Access — one tab, two views
Permission presets and lead visibility are the same subject — both decide what somebody gets. They sit side by side now, and the address follows the sub-tab so a refresh or a bookmark lands where you were.

