Role & Permissions controls what users can see and do. It separates API Permissions from Module Access so a role’s visible interface and allowed actions can be managed deliberately.

Manage roles

Select Manage Roles to review available roles and create or update custom roles. System roles such as Super Admin and Admin are protected from unsafe deactivation.

API Permissions

API permissions control actions such as viewing, creating, updating, deleting, approving, or exporting records.

  1. Select a role.
  2. Open API Permissions.
  3. Expand a permission group.
  4. Enable or disable the required actions.
  5. Save the changes.

Module Access

Module Access controls navigation and sub-navigation visibility. It includes:

  • Main modules such as Projects, Messages, Clients, Vendors, Timesheet, and Settings
  • Project sub-pages such as Files, Tasks, Timeline, Snags, and Payments
  • Individual Settings tabs

Enable a top-level module before enabling its nested views. Save the role after reviewing the complete selection.

Super administrator behaviour

Super administrators always have full API and module access. Their access does not depend on individual module rows.

Changes during an active session

Access updates are sent to connected users. A user may need to navigate again or refresh if their connection was interrupted.

Why is a tab visible but an action disabled?+

Module Access made the page visible, but the role is missing the API permission for that action. Review both permission layers.