Skip to main content

Roles and permissions

Access is controlled by a single role on your account. Roles are assigned by an administrator and are enforced on the server for every page, action, export, and API call — hiding a button is never the only protection.

How you get a role

Your role comes from your identity provider's group claim when you sign in, or is set directly by an administrator on the Users and roles screen. Unknown identities fall back to the least-privileged role, engineer.

The four roles​

RoleIn one line
EngineerLogs and submits their own time.
ReviewerReviews and approves or rejects submitted time.
FinanceRuns the commercial side: customers, projects, rates, billing.
AdminEverything, plus people, roles, tokens, and service clients.

Engineer​

The default, least-privileged role. An engineer can:

  • Log, edit, delete (while not approved), and submit their own time.
  • See and fix their own rejected entries.
  • View the Overview (personal tiles) and Reports.
  • Log time only against projects they are assigned to.

Reviewer​

Everything an engineer can do, plus:

  • Work the Review queue.
  • Approve or reject submitted time (with a reason) for anyone.
  • Approve everything pending in one action.
  • Open the Billing screen (read-only).

Finance​

Everything a reviewer can do, plus the commercial screens:

Admin​

Everything the other roles can do, plus the Administration screen:

Quick permission matrix​

CapabilityEngineerReviewerFinanceAdmin
Log / edit / submit own time✅✅✅✅
Review & approve time—✅✅✅
Manage customers & projects——✅✅
Manage agreements, allowances, rates——✅✅
Close / reopen billing periods——✅✅
Run reports & export CSV✅✅✅✅
Manage users, roles, tokens, service clients———✅

The full, page-by-page matrix is in Permission matrix.

The sidebar adapts to your role

Only the sections your role can open appear in the sidebar — an engineer, for example, sees no Review queue, Billing, or Administration. If you reach a section you lack access to anyway (for example a direct link), the page returns a 403 message: the server, not the menu, is the source of truth. The Permission matrix tells you what to expect.

Privileges are also scoped to your own data​

Where a role is not explicitly required, the app still scopes by ownership:

  • Engineers only see and edit their own time entries.
  • Only the project's customer is used to resolve billing and allowances.
  • Personal API tokens inherit your role and, optionally, a narrower scope.

See Permission matrix for the detail.