Where to start
Settings → RolesBefore you start
- Identify the work the person needs to perform and review their current roles before changing access. Editing a shared role affects its assigned users.
- Use a separate unassigned practice role to learn the controls. Role names and job titles do not prove what access a person has.
1Find a role and its assigned users
Open Settings → Roles. This is an owner/administrator or full-access management surface. The list shows Role Name, Description and Users. Select a row to open it. Search permissions is available inside the role editor.
Export downloads the role list as CSV with the role name, description and assigned user names. It is not a backup of every permission checkbox.
2Create or edit the role
Choose Create for a separate role, or select an existing row for Edit Role. Enter a unique Role name and a useful Description. Save role stays disabled while the name is blank. The name permits up to 100 characters.
Changes remain in this editor until Save role succeeds. Cancel, the close button or Escape closes the unsaved editor. Check the Users column before editing a role that other people already use.
3Search and read the permission explanations
Search permissions matches feature names, group names and the explanations. Expand What this controls under a row to read its current meaning and additional requirements. Clear the search to see all groups again.
A checkbox can control a particular action or screen while another permission, feature setting or record restriction also applies. Follow the explanation for that row instead of assuming every checkbox grants complete access to the feature.
4Choose individual actions or Full control
Read, Create, Update and Delete are separate where offered. For example, Files: Create allows upload and folder creation; Files: Delete is a separate choice. Opening or downloading files uses Read.
Full control includes current and future actions for that section. Checking every individual box does not silently select Full control. If you remove an individual action from a section that had Full control, the other current actions remain selected and the Full control box clears.
5Use Select shown and Clear shown carefully
Each permission group offers Select shown and Clear shown. With a search active, these act on the matching rows currently shown in that group, not every hidden row elsewhere in the role.
Select shown selects the current individual actions. It does not add future Full control automatically. Clear shown removes grants for those shown sections. Review the resulting checkboxes before saving.
6Understand Full application access and Owner
Full application access grants broad application access, including role management and future permissions. Turn it off to configure individual permissions. For a non-owner, Integrations still needs its explicit Configure integrations box.
The Owner role always has full access. Its name and permissions cannot be restricted here, and it cannot be deleted. Its description can be edited. A user’s Administrator flag also grants general access; it does not remove the explicit non-owner Integrations requirement.
7Separate account, quote, drawing, cost and file access
Accounts controls client records. AR Statistics is a separate readout. Quotes & Orders: Read includes selling prices; Drawing (no pricing) supplies a drawing-only path when full quote read access is absent. Files: Read can provide a files-only quote view.
Cost & Margin Data and Customer Engagement have separate Read choices. Read the Quotes & Orders explanation for Unlock, Template Correction, Change Order and the retained follow-up permission rules. Do not assume a drawing-only grant also allows editing or viewing prices.
8Separate sending, mailbox delivery and QuickBooks configuration
Send quotes & contracts controls the quote/contract email action and Mark as Sent. Email Templates controls maintaining the template library; it is separate from permission to send.
System emails use SlabOS by default. The sending user must connect Gmail or Outlook and enable Send system emails as me for system emails to use that mailbox. Connecting alone is insufficient. Granting Send does not connect a mailbox or change that delivery setting.
Run QuickBooks sync / import controls running the sync/import operations. Connection and mapping configuration uses Integrations. An Integrations grant still follows the owner/administrator requirements for saving company integration settings.
9Review pricing, jobs, scheduling and crew dependencies
Price Lists governs the rate-card administration pages. Jobs governs project records; Job / Phase Status, Job Tasks and Change Account / Salesperson are separate controls. Read their explanations before assuming Jobs: Update includes every adjacent action.
Calendar & Activities governs scheduling operations. Work dashboard: all activities also requires Calendar Read or Crew App Read. Crew App Access controls the crew screens; the crew Inventory tab additionally follows Slab Inventory: Read. Job titles and activity mapping determine which work crew members see.
10Review inventory and purchasing controls
Slab Inventory covers slabs, remnants and allocations; holding stock from a quote needs Update. Shop Supplies has its own permissions. Suppliers & Purchase Orders covers supplier records, purchase orders and supplier invoices.
Purchase Order Files has independent upload and delete choices. Those are separate from the Files controls used on quotes, jobs and accounts. Match the permissions to the receiving, viewing, editing or purchasing work the person actually does.
11Review sales, tools and financial visibility
Pipeline: team tabs changes whether broader salesperson tabs appear; it requires Quotes Read and does not replace Locked Views. Leads has separate actions. Invoices & Payments covers customer invoice and payment operations.
CAD controls drawings, templates and related fabrication operations. Reports & Analytics does not override an owner-only Analytics page. Win Work and Email Signature Studio have separate Read controls, and the signature studio also depends on the feature being enabled. Company financial access retains its additional owner/administrator rules.
12Review the individual template permissions
The Templates group separates Form Templates, Event Templates & Activity Types, Job Info Defaults, Quote Info Defaults and Client Info Defaults. Read typically opens the matching tab; Update permits saving where offered.
Crew App Settings, Client Portal, Job Page Layout, Account Page Layout, Displays, CAD Sheets and Fab 3D Exports each have their own row. Shop-default layouts are separate from personal layout preferences. Quick Shapes & Tile Patterns follows the actions and shop feature availability explained in that row.
13Understand Team Edits and administration controls
Team Edits allows a person to change the specified fields on their own user record. It does not make them an administrator of every team member. Role and Locked Views self-edit grants can let a person widen their own access, so review their purpose deliberately. Changing one’s own password is handled separately in Profile.
Change Logs controls history visibility. Task Tracker can expose all employees’ tasks instead of only one’s own. HR / Operations has Read and a shared Manage records grant for its writes; the employee People panel retains its existing Full control requirement for editing. Open the row explanations for the exact scope.
14Review older saved permissions without guessing
Expand Legacy permissions and other access rules. Existing older or unrecognized keys are retained unless explicitly removed. Some advisory keys never enforced access; their presence does not establish a working restriction.
The old Cancel Orders, Shared Saved Views, Account Settings, Quote Settings, QuickBooks Settings, Salespeople and System Settings boxes are not offered as new working controls. Payment access uses Invoices & Payments; connection configuration uses Integrations. An existing quotes:write grant retains its documented follow-up behavior.
15Save, reopen and handle errors
Choose Save role and wait for the editor to close successfully. Open the same role again and check its name, description and selected permissions. A failed save leaves the editor and error visible so you can correct the problem and retry.
A duplicate name must be changed before saving. If a user still has unexpected access, inspect their other roles, Administrator flag, feature availability and record restrictions. Verify representative allowed and restricted actions with an appropriately configured test account; sidebar visibility alone is insufficient.
16Duplicate or delete a role deliberately
Duplicate role immediately creates a separate role with “(copy)” added to its name and copies the description and permissions. It does not copy the assigned users. Open the new row to inspect or rename it. If that copy name already exists, rename the existing copy or choose another approach before duplicating again.
Delete role opens a confirmation. Keep role cancels it. Delete role permanently removes that role and its assignments from users. Check the assigned people and their remaining access first. The Owner role has no delete action.
17Check the user’s complete setup in Team
Open Settings → Team and the intended user. Every assigned role contributes permissions together. Removing a grant from one role does not remove access supplied by another role or the Administrator flag. Save in the user editor applies role assignment changes; Cancel leaves the draft unsaved.
Roles define access. Job Titles affect crew work filtering and customer-portal team eligibility. Crew-only login, employee-without-login status, Shop Location, Login From and job check-in access are separate settings. Review them using the Team and Crew guides instead of treating them as role names.
18Distinguish the two Locked Views choices
In the user editor, Lock this user’s view & search to only records they create and manage scopes lists, search and calendar to their work. Lock entry but show all leaves broader lists visible while restricting which records they can open.
The two choices are alternatives. Clearing the active choice leaves neither selected and follows the normal access rules; it is not the same as selecting browse. Shop-location defaults and Pipeline team-tab navigation do not replace these record restrictions. Owners and administrators are exempt from these locks. Verify the intended account’s actual tasks after an access change.
Check the result
- The saved role has exactly the intended current and future grants; its assigned users have been reviewed.
- The user’s combined roles, Administrator flag, Locked Views, location/login constraints and feature availability explain their actual access.
- Checks include required actions and restricted records, not only which menu items appear.
If something looks wrong
- If an individual checkbox is disabled, check Full application access or whether you opened Owner. Integrations is an explicit exception for non-owners.
- If search hides a control, clear it and inspect the full catalog. Select shown and Clear shown only affect the shown rows in their group.
- An error does not prove a save succeeded. Reopen the role after a successful save and check its current values. Do not test deletion or messaging on customer records.