Permission matrix
Authorization is enforced server-side on every page, action, export, and API call. This is the authoritative map of who can do what.
Legend: โ allowed ยท ๐ read-only ยท โ not allowed (403).
Screensโ
| Screen | Route | Engineer | Reviewer | Finance | Admin |
|---|---|---|---|---|---|
| Overview | /overview | โ | โ | โ | โ |
| My time | /my-time | โ | โ | โ | โ |
| Customers and projects | /customers | ๐ | ๐ | โ | โ |
| Customer detail | /customers/{id} | ๐ | ๐ | โ | โ |
| Agreements and rates | /agreements | ๐ | ๐ | โ | โ |
| Review queue | /review | โ | โ | โ | โ |
| Billing | /billing | โ | ๐ | โ | โ |
| Reports | /reports | โ | โ | โ | โ |
| Reports CSV export | /reports/export | โ | โ | โ | โ |
| Administration | /administration | โ | โ | โ | โ |
Time entriesโ
| Action | Engineer | Reviewer | Finance | Admin |
|---|---|---|---|---|
| Create own entry | โ | โ | โ | โ |
| Edit own draft/rejected | โ | โ | โ | โ |
| Submit own draft/rejected | โ | โ | โ | โ |
| Delete own non-approved | โ | โ | โ | โ |
| Approve / reject any | โ | โ | โ | โ |
| Approve all pending | โ | โ | โ | โ |
Editing/deleting is restricted to your own entries; a different engineer's entry returns 403.
Customers, projects, commercialsโ
| Action | Engineer | Reviewer | Finance | Admin |
|---|---|---|---|---|
| Create/edit customer | โ | โ | โ | โ |
| Archive/reactivate customer | โ | โ | โ | โ |
| Create project / change status | โ | โ | โ | โ |
| Assign/unassign engineer | โ | โ | โ | โ |
| Create agreement / allowance / rate | โ | โ | โ | โ |
| Close/reopen/recalculate billing | โ | โ | โ | โ |
Administrationโ
| Action | Engineer | Reviewer | Finance | Admin |
|---|---|---|---|---|
| Change a user's role | โ | โ | โ | โ |
| Enable/disable a user | โ | โ | โ | โ |
| Manage personal API tokens | โ | โ | โ | โ |
| Manage service clients | โ | โ | โ | โ |
| Read the audit trail | โ | โ | โ | โ |
APIโ
API callers need both the right role and, for tokens, the right scope. Scopes are intersected with the principal's role. See API quickstart and Personal API tokens.
Landing routesโ
/ redirects admin and finance to /overview; reviewer and
engineer to /my-time.