Roles and permissions
Define what a kind of person may do once, then assign the role.
Setting rights per person looks flexible and becomes unmanageable at about the fifth employee, because nobody can answer “who can see the invoices?” any more.
Step by step
- Open Security / admin → Setup → Roles.
- Create a role for each kind of person you have — for example office, sales, technician, accounting.
- Set the permissions on the role. Most areas distinguish view, create, edit and delete, and many distinguish “all” from “own”.
- Assign the role on each person's record under Central → Team.
- Change the role when the job changes, rather than editing one person's rights.
Three principles worth following
- Start narrow. Adding a right when somebody asks is easy; discovering that everybody could delete invoices is not.
- Prefer “own” over “all” where the work is personal — own leads, own tasks, own time.
- Review the roles when the team changes shape, not when something goes wrong.
Two-factor on top
Roles decide what somebody may do once they are in. Security / admin → MFA decides how sure you are that it is them — MFA management, reports and settings. See Sign in with an email code.
The rest of Setup
Security / admin → Setup also holds staff, tenants, help, leads, finance, contract types, estimate requests, modules, e-mail templates, custom fields and GDPR. Settings next to it is the workspace-wide configuration.
Nothing is tracked — the buttons only open a message so you can tell us what was missing.

