Skip to main content

Permission matrix

Authorization is enforced server-side on every page, action, export, and API call. This is the authoritative map of who can do what.

Legend: โœ… allowed ยท ๐Ÿ‘ read-only ยท โ€” not allowed (403).

Screensโ€‹

ScreenRouteEngineerReviewerFinanceAdmin
Overview/overviewโœ…โœ…โœ…โœ…
My time/my-timeโœ…โœ…โœ…โœ…
Customers and projects/customers๐Ÿ‘๐Ÿ‘โœ…โœ…
Customer detail/customers/{id}๐Ÿ‘๐Ÿ‘โœ…โœ…
Agreements and rates/agreements๐Ÿ‘๐Ÿ‘โœ…โœ…
Review queue/reviewโ€”โœ…โœ…โœ…
Billing/billingโ€”๐Ÿ‘โœ…โœ…
Reports/reportsโœ…โœ…โœ…โœ…
Reports CSV export/reports/exportโœ…โœ…โœ…โœ…
Administration/administrationโ€”โ€”โ€”โœ…

Time entriesโ€‹

ActionEngineerReviewerFinanceAdmin
Create own entryโœ…โœ…โœ…โœ…
Edit own draft/rejectedโœ…โœ…โœ…โœ…
Submit own draft/rejectedโœ…โœ…โœ…โœ…
Delete own non-approvedโœ…โœ…โœ…โœ…
Approve / reject anyโ€”โœ…โœ…โœ…
Approve all pendingโ€”โœ…โœ…โœ…

Editing/deleting is restricted to your own entries; a different engineer's entry returns 403.

Customers, projects, commercialsโ€‹

ActionEngineerReviewerFinanceAdmin
Create/edit customerโ€”โ€”โœ…โœ…
Archive/reactivate customerโ€”โ€”โœ…โœ…
Create project / change statusโ€”โ€”โœ…โœ…
Assign/unassign engineerโ€”โ€”โœ…โœ…
Create agreement / allowance / rateโ€”โ€”โœ…โœ…
Close/reopen/recalculate billingโ€”โ€”โœ…โœ…

Administrationโ€‹

ActionEngineerReviewerFinanceAdmin
Change a user's roleโ€”โ€”โ€”โœ…
Enable/disable a userโ€”โ€”โ€”โœ…
Manage personal API tokensโ€”โ€”โ€”โœ…
Manage service clientsโ€”โ€”โ€”โœ…
Read the audit trailโ€”โ€”โ€”โœ…

APIโ€‹

API callers need both the right role and, for tokens, the right scope. Scopes are intersected with the principal's role. See API quickstart and Personal API tokens.

Landing routesโ€‹

/ redirects admin and finance to /overview; reviewer and engineer to /my-time.