Roles
Every user holds one role. Higher-level roles include the privileges of every lower-level role.
Admin (Level 4)
Full access. Nothing restricted.
Manager (Level 3)
Day-to-day operations. No HR or system configuration.
Supervisor (Level 2)
Shop floor authority. Shifts + view-only context.
User (Level 1)
Kiosk and workstation only. Never enters admin namespace.
Permission matrix
A check (✓) means the role can perform that action.
| Permission | Admin | Manager | Supervisor | User |
|---|---|---|---|---|
| Access Admin Access the admin namespace |
✓ | ✓ | ✓ | — |
| Review Shifts Review shifts, adjust times, add notes |
✓ | ✓ | ✓ | — |
| Manual Start Shift Manually start scheduled or unscheduled shifts on behalf of workers |
✓ | — | ✓ | — |
| Manual End Shift Manually end shifts on behalf of workers |
✓ | — | ✓ | — |
| View Users View user list, schedules, shift history |
✓ | ✓ | ✓ | — |
| View Customers View customer list and details |
✓ | ✓ | ✓ | — |
| View Jobs View job list and details |
✓ | ✓ | ✓ | — |
| Manage Customers Create, edit, delete customers |
✓ | ✓ | — | — |
| Manage Jobs Create, edit, delete jobs |
✓ | ✓ | — | — |
| Manage Estimates Create and revise estimates, quote lines, and quote acceptance workflows |
✓ | ✓ | — | — |
| Manage Internal Codes Create, edit, activate, and deactivate internal task tagging codes |
✓ | ✓ | — | — |
| Manage Contacts Create, edit, delete contacts |
✓ | ✓ | — | — |
| Manage Hiring Create job postings, review and advance applicants, hire |
✓ | — | — | — |
| Manage Labor Codes Create, edit, delete labor codes |
✓ | — | — | — |
| View Supplies View the shop-supplies catalog (items + derived last price/last purchased) |
✓ | ✓ | — | — |
| Manage Supplies Create, edit, deactivate, and reactivate shop-supply items |
✓ | — | — | — |
| Process Supply Requests Act on worker supply requests from the Admin queue — approve, reject, park for technical check, record a purchase. The coordinator (buyer) grant, distinct from view_supplies (read the queue/catalog) and manage_supplies (edit the catalog). |
✓ | ✓ | — | — |
| View Reports View operational / department reports (labor, job costs, customer work summary). Manager-and-up — operational tier. |
✓ | ✓ | — | — |
| View Workforce Reports View workforce and people reports, including team performance. |
✓ | — | — | — |
| View Timecards View the Timecards worklist — the per-week shift review and sign-off surface. |
✓ | ✓ | — | — |
| View Business Revenue Reports View whole-business revenue / P&L / shop-wide rollup dashboards (split from view_reports — admin-only carve-out for cross-department revenue surfaces) |
✓ | — | — | — |
| Export Data Export CSV and report data |
✓ | ✓ | — | — |
| Manage Users Create, edit, deactivate users and assign roles |
✓ | — | — | — |
| Manage Settings Operational settings — schedules, departments, shift types, kiosk devices, tasks, time-tracking config |
✓ | — | — | — |
| Manage Account Account-level configuration — company name, address, timezone, payroll-period, account-wide preferences (split from manage_settings — admin-only carve-out for account-identity surfaces) |
✓ | — | — | — |
| Manage Billing Billing operations — checkout, subscription state, cancellation, reactivation, billing history |
✓ | — | — | — |
| Manage Integrations Stripe + payroll-export + webhook integration configuration — plan changes, billing-interval changes, customer-portal access (split from manage_billing — admin-only carve-out for third-party integration management) |
✓ | — | — | — |
| Destructive Actions Delete records (customers, jobs, users, etc.) |
✓ | — | — | — |
| View Job Costs View per-job cost data on a single job: recorded material and subcontract cost, budget versus actual, and margin. Cross-job rollups stay admin-only. |
✓ | ✓ | — | — |
| Manage Job Costs Record and edit per-job cost data — material and subcontract cost against a job. |
✓ | ✓ | — | — |
| Message Workers Message workers via the account's implicit per-worker threads (admin inbox / iOS). Excludes the user role — workers reach only their own workstation thread by device possession, never the manager inbox. |
✓ | ✓ | ✓ | — |
| View Machines View machines — the asset list, per-machine detail, the utilization report, and the machine-run review queue. The read half of managing machines. |
✓ | ✓ | — | — |
| Manage Machines Manage machines (create/edit machine records) and review/correct machine runs — the write half of view_machines |
✓ | ✓ | — | — |
| Manage Time Off Admin-only management of the Time Off module — policies, assignments, grants, adjustments, opening balances (FAB-1742). Not granted to manager: managers approve/deny requests but do not configure policy or manually adjust balances. |
✓ | — | — | — |
| Approve Time Off View the Time Off landing surface, see who is off, and approve or deny time-off requests. |
✓ | ✓ | — | — |