This page describes the permissions that come built into each Role in the system, as well as the maximum level of access each Role is ever allowed to reach.
This page is a companion to the system guide, which explains how Roles, Groups, Dimensions, and permissions work together across the system. If you are looking for an explanation of how permissions are combined and calculated, start there. This page focuses specifically on what each Role includes out of the box, and how far it can be customized.
Every Role in the system has two related, but different, sets of permissions:
Administrators can freely turn a Role's Default Permissions on or off, and can also grant additional permissions to individual users or through Groups. However, no combination of user-level permissions or Group permissions can ever push a user beyond what their Role's Maximum allows. The Role always acts as a ceiling.
Important: Modules (the tabs a user sees, such as Tasks, Time or Invoices) do not have a Maximum setting. There is only a Default configuration for modules.
| Role | Description |
|---|---|
| Super Administrator | Has full access to every area of the system, including the ability to manage other administrators. |
| Administrator | Has full access to nearly every area of the system, with the same reach as Super Administrator in day-to-day use. |
| Manager | Manages the Clients, Projects and Workspaces they have been given management access to, including their team, time tracking and billing. |
| Executive | Works across nearly every area of the system, but does not manage billing, time entries, task templates, or system configuration by default. |
| Internal Collaborator | An internal team member who can work on the data they have access to and link objects together, but cannot create or assign tasks, and has no access to financial or administrative areas. |
| External Collaborator | An external partner or contractor who can work on the data they have access to and link objects together, but cannot create or assign tasks, and has no access to financial or administrative areas. |
| Collaborator (Customer) | A customer-facing collaborator who can work on the data shared with them, with restricted permissions, and can link objects they already have edit access to. |
| Guest | Has limited, read-only visibility into specific data such as tasks, time entries, and expenses. Cannot upload data or leave comments. |
| Guest (Customer) | Has limited, read-only visibility into their own data. Cannot upload data, but can leave comments. |
| Non-Executive Director | An oversight Role that can view other users' tasks, time entries, expenses, and billing figures, without editing rights anywhere in the system. |
Every permission in the system exists at two levels for each Role:
A permission can only ever be active for a user if it falls within that user's Role Maximum. If a Role's Maximum does not allow a permission, it will always appear greyed out on the permissions screen — it cannot be turned on by editing the user directly, and it cannot be turned on by adding the user to a Group.
The Executive Role does not come with Can manage security configuration turned on by default — new Executive users cannot manage other users, groups, or permissions out of the box.
However, this permission does fall within the Executive Role's Maximum. This means an administrator can open a specific Executive user's permissions (or a Group that user belongs to) and turn this permission on, if the business need arises.
The Guest Role is the most restricted Role in the system. On the permissions screen, every permission for Guest appears unchecked, and only three of them can even be clicked: Can see other user's tasks, Can see other users' time entries, and Can see actual expenses paid by other users. Every other permission is greyed out.
This means a Guest's Maximum only ever allows visibility into that specific data — never the ability to create, edit, or delete anything. No administrator can change this by editing a Guest user or by adding them to a Group; the Role itself does not allow it.
Important: Administrators may enable any permission that falls within a Role's Maximum but is currently off by default. Permissions that fall outside the Maximum can never be enabled for that Role, through any method.
System Permissions control access to system-wide actions that are not tied to a specific Project, Client or other piece of data — things like managing users, managing templates, or seeing other people's time entries.
| Permission | Description |
|---|---|
| Can manage security configuration | Create, update and delete users and groups, and change their permissions. |
| Can manage configuration, owner company data, tabs, logos and colors | Edit the application configuration, company information, scheduled events, application upgrades, the logo and the brand colors. |
| Can manage task templates | Create, update and delete task templates. Once created, any user with task permissions can use them. |
| Can use task templates | Create new tasks from existing task templates. |
| Can manage time entries | Full permissions over time entries, including editing entries created by other users. |
| Can add mail accounts | Add email accounts, either for themselves or for other users. |
| Can manage dimensions | Full permissions over dimensions: create new dimensions and change their configuration. This is an advanced administrative feature. |
| Can manage dimension members | Full permissions over dimension members — create, edit, and delete Workspaces, Projects, Clients, and similar records. |
| Can manage tasks, including assigning tasks to others and completing others' tasks | Full permissions over tasks: assign tasks to other users and mark other users' tasks as complete. |
| Can manage billing | Edit billing configurations. |
| Can see other users' tasks | See tasks that are not assigned to them. |
| Can update other users' event invitations | Change the status of other users' event invitations. |
| Can link objects | Link and unlink objects to one another. |
| Can manage repetitive properties of tasks | Modify the repetition settings of recurring tasks. |
| Can see other users' time entries | See time entries that were not entered by them. |
| Can reopen task | Reopen a task that was previously marked as complete. |
| Can see actual expenses paid by other users | See actual expenses that were not paid by them. |
| Can edit confirmed invoices | Edit invoices that have already been confirmed. |
| Can manage invoicing configuration | Modify the invoicing settings. |
| Can add time entries in Time module | Add time entries directly from the Time module. When this is off, the user can only add time entries from inside a task. |
The table below shows which System Permissions are turned on by default for each Role. A checkmark (✓) means the permission is active the moment a new user of that Role is created. A blank cell means the permission starts off — it may still be turned on later, depending on whether the Role's Maximum allows it.
Role abbreviations used in this table:
SA = Super Administrator · AD = Administrator · MG = Manager · EX = Executive · IC = Internal Collaborator · EC = External Collaborator · CC = Collaborator (Customer) · GU = Guest · GC = Guest (Customer) · ND = Non-Executive Director
| Permission | SA | AD | MG | EX | IC | EC | CC | GU | GC | ND |
|---|---|---|---|---|---|---|---|---|---|---|
| Can manage security configuration | ✓ | ✓ | ✓ | |||||||
| Can manage configuration, branding, tabs | ✓ | ✓ | ||||||||
| Can manage task templates | ✓ | ✓ | ✓ | |||||||
| Can use task templates | ✓ | ✓ | ✓ | ✓ | ||||||
| Can manage time entries | ✓ | ✓ | ✓ | |||||||
| Can add mail accounts | ✓ | ✓ | ✓ | ✓ | ||||||
| Can manage dimensions | ✓ | ✓ | ||||||||
| Can manage dimension members | ✓ | ✓ | ✓ | ✓ | ||||||
| Can manage tasks (assign / complete others') | ✓ | ✓ | ✓ | ✓ | ||||||
| Can manage billing | ✓ | ✓ | ✓ | |||||||
| Can see other user's tasks | ✓ | ✓ | ✓ | ✓ | ||||||
| Can update other user's event invitations | ✓ | ✓ | ✓ | |||||||
| Can link objects | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | |||
| Can manage repetitive properties of tasks | ✓ | ✓ | ✓ | ✓ | ||||||
| Can see other user's time entries | ✓ | ✓ | ✓ | ✓ | ||||||
| Can reopen task | ✓ | ✓ | ✓ | ✓ | ||||||
| Can see actual expenses paid by other users | ✓ | ✓ | ✓ | ✓ | ||||||
| Can edit confirmed invoices | ✓ | ✓ | ||||||||
| Can manage invoicing configuration | ✓ | ✓ | ||||||||
| Can add time entries in Time module | ✓ | ✓ | ✓ | ✓ | ✓ |
The table below shows the highest level of access each Role is ever allowed to reach. A blank cell means the permission is greyed out on screen and can never be granted to that Role — not by editing a user directly, and not through a Group.
How to read this table together with the Default table above:
Role abbreviations used in this table:
SA = Super Administrator · AD = Administrator · MG = Manager · EX = Executive · IC = Internal Collaborator · EC = External Collaborator · CC = Collaborator (Customer) · GU = Guest · GC = Guest (Customer) · ND = Non-Executive Director
| Permission | SA | AD | MG | EX | IC | EC | CC | GU | GC | ND |
|---|---|---|---|---|---|---|---|---|---|---|
| Can manage security configuration | ✓ | ✓ | ✓ | ✓ | ||||||
| Can manage configuration, branding, tabs | ✓ | ✓ | ||||||||
| Can manage task templates | ✓ | ✓ | ✓ | |||||||
| Can use task templates | ✓ | ✓ | ✓ | ✓ | ||||||
| Can manage time entries | ✓ | ✓ | ✓ | |||||||
| Can add mail accounts | ✓ | ✓ | ✓ | ✓ | ||||||
| Can manage dimensions | ✓ | ✓ | ||||||||
| Can manage dimension members | ✓ | ✓ | ✓ | ✓ | ||||||
| Can manage tasks (assign / complete others') | ✓ | ✓ | ✓ | ✓ | ||||||
| Can manage billing | ✓ | ✓ | ✓ | |||||||
| Can see other user's tasks | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ||
| Can update other user's event invitations | ✓ | ✓ | ✓ | ✓ | ||||||
| Can link objects | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | |||
| Can manage repetitive properties of tasks | ✓ | ✓ | ✓ | ✓ | ||||||
| Can see other user's time entries | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ||
| Can reopen task | ✓ | ✓ | ✓ | ✓ | ✓ | |||||
| Can see actual expenses paid by other users | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ||
| Can edit confirmed invoices | ✓ | ✓ | ✓ | |||||||
| Can manage invoicing configuration | ✓ | ✓ | ✓ | |||||||
| Can add time entries in Time module | ✓ | ✓ | ✓ | ✓ | ✓ |
Modules are the tabs a user sees across the top of the application — such as Tasks, Time, Expenses or Invoices. Unlike System Permissions, modules do not have a Maximum: a Role either includes a module by default, or it does not appear for that Role at all unless an administrator adds it.
| Module | Description |
|---|---|
| Overview | The landing dashboard shown when a user logs in. |
| Calendar | Displays events, milestones, and scheduled items. |
| Documents | Stores and organizes files. |
| Tasks | Manages tasks, subtasks, and task lists. |
| Time | Tracks time entries against tasks and projects. |
| Settings (More) | Access to additional configuration and account settings. |
| Contacts | Manages people and companies. |
| Reporting | Generates and views reports. |
| Expenses | Manages budgeted and actual expenses. Requires the Expenses module to be installed. |
| Invoices | Manages invoicing and billing documents. Requires the Invoicing module to be installed. |
Additional modules — such as Email, Projects, Customers, Forms, Tickets, Workspaces and Tags — are provided by optional modules and only appear once the corresponding module has been installed and enabled.
The table below shows which of the ten core modules each Role sees by default.
Role abbreviations used in this table:
SA = Super Administrator · AD = Administrator · MG = Manager · EX = Executive · IC = Internal Collaborator · EC = External Collaborator · CC = Collaborator (Customer) · GU = Guest · GC = Guest (Customer) · ND = Non-Executive Director
| Module | SA | AD | MG | EX | IC | EC | CC | GU | GC | ND |
|---|---|---|---|---|---|---|---|---|---|---|
| Overview | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Calendar | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Documents | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | |
| Tasks | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ||
| Time | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ||
| Settings (More) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ||
| Contacts | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ||||
| Reporting | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ||||
| Expenses | ✓ | ✓ | ✓ | ✓ | ||||||
| Invoices | ✓ | ✓ | ✓ | ✓ |
Note: As a general rule, every additional module (Email, Projects, Customers, Forms, Tickets, Workspaces, Tags) is visible only to Super Administrator, Administrator, Manager, and Executive by default. Collaborators and Guests never receive an additional module automatically — an administrator must grant it manually if needed. Workspaces and Tags, specifically, are created disabled and must be switched on before any Role can see them.
While System Permissions control system-wide actions, Object Permissions control what a user can do with individual records — Tasks, Files, Expenses, Invoices, and so on — once they already have access to the Project, Client, or other dimension member that record belongs to.
There are three levels of object access:
| Value | Meaning |
|---|---|
| W | The user can create and edit objects of this type. |
| W+D | The user can create, edit, and delete objects of this type. |
| (blank) | The user has no write or delete access to objects of this type. |
A note on Read access: Unlike Write and Delete, Read access is not set directly by a Role. Instead, it depends on whether the user (or a Group they belong to) has been granted access to the Project, Client, Workspace, or other dimension member the object belongs to. In practice, this means: sharing a Project with a user or Group gives them read access to the object types included in that share. Their Role then determines how much further beyond reading they are allowed to go.
Role abbreviations used in this table:
SA = Super Administrator · AD = Administrator · MG = Manager · EX = Executive · IC = Internal Collaborator · EC = External Collaborator · CC = Collaborator (Customer) · GU = Guest · GC = Guest (Customer) · ND = Non-Executive Director
| Object Type | SA | AD | MG | EX | IC | EC | CC | GU | GC | ND |
|---|---|---|---|---|---|---|---|---|---|---|
| Task | W+D | W+D | W+D | W | ||||||
| Milestone | W+D | W+D | W+D | W | ||||||
| Event | W+D | W+D | W+D | W | ||||||
| File | W+D | W+D | W+D | W | W | W | ||||
| Message | W+D | W+D | W+D | W | ||||||
| Web Link | W+D | W+D | W+D | W | ||||||
| Contact | W+D | W+D | W+D | W | ||||||
| Time Entry | W+D | W+D | W+D | W | W | W | W | |||
| Report | W+D | W+D | W+D | W | ||||||
| Expense | W+D | W+D | W+D | W | ||||||
| Expense Item | W+D | W+D | W+D | W | ||||||
| Actual Expense | W+D | W+D | W+D | W | ||||||
| Invoice | W+D | W+D | W | W |
Note: Invoices cannot be deleted by Manager or Executive by default — they may only create and edit them. This is intentional, to protect confirmed billing records.
Role abbreviations used in this table:
SA = Super Administrator · AD = Administrator · MG = Manager · EX = Executive · IC = Internal Collaborator · EC = External Collaborator · CC = Collaborator (Customer) · GU = Guest · GC = Guest (Customer) · ND = Non-Executive Director
| Object Type | SA | AD | MG | EX | IC | EC | CC | GU | GC | ND |
|---|---|---|---|---|---|---|---|---|---|---|
| Task | W+D | W+D | W+D | W+D | ||||||
| Milestone | W+D | W+D | W+D | W+D | ||||||
| Event | W+D | W+D | W+D | W+D | ||||||
| File | W+D | W+D | W+D | W+D | W | W | W | |||
| Message | W+D | W+D | W+D | W+D | W | W | W | |||
| Web Link | W+D | W+D | W+D | W+D | W | W | W | |||
| Contact | W+D | W+D | W+D | W+D | W | W | W | |||
| Time Entry | W+D | W+D | W+D | W+D | W | W | W | |||
| Report | W+D | W+D | W+D | W+D | W | W | W | |||
| Expense / Expense Item / Actual Expense | W+D | W+D | W+D | W+D | ||||||
| Invoice | W+D | W+D | W+D | W |
Note: additional object types provided by optional modules — such as Mail, Forms and Tickets — generally follow the same pattern: full create/edit/delete access for Super Administrator, Administrator and Manager, and no access for Collaborators or Guests. Executive typically receives create/edit access on Mail, and full create/edit/delete access on Forms and Tickets.
Note: objects that are not filed under any Project, Client, or other dimension member follow a separate, more restrictive set of rules, and are generally only accessible to Super Administrator, Administrator, Manager, and Executive when this behavior has been specifically enabled for the installation.
The permissions described earlier on this page are part of the base product and are available on every installation. In addition to those, some modules add permissions of their own. These extra permissions only appear on the permissions screen once the module that provides them has been installed and enabled — on an installation without that module, they simply do not exist.
There is an important detail worth knowing: not every module adds a visible tab. Some modules add a tab at the top of the screen (like Expenses), while others add permissions only and change nothing visually. This means you cannot always tell whether a module is installed just by looking at the tabs.
To check exactly which modules are active on your installation, go to Administration → Plugins. The table below includes the name each module displays on that screen, so you can find it quickly.
| Permission | What it allows | Provided by | Shown in Administration → Plugins as | Adds a tab? |
|---|---|---|---|---|
| Can manage mail templates | Create, edit and manage reusable email templates. | Mail Templates | object_templates — Generic templates for content objects | No |
| Can see billing information | View billing information on records where it applies. | Billing & Cost | billing_and_cost_permissions — Adds permissions to see billing or cost information | No |
| Can see cost information | View cost information on records where it applies. | Billing & Cost | billing_and_cost_permissions — Adds permissions to see billing or cost information | No |
| Can edit completed payments | Edit payments that have already been marked as completed. | Expenses | expenses and expenses2 — Expenses module for Feng Office | Yes → Expenses |
| Can manage all people | Manage all contact and user records across the system. | Part of the core product — no module required | (not listed under Plugins) | — |
Note: If a permission listed above does not appear on your permissions screen, the module that provides it is not currently active on your installation. Keep in mind that Mail Templates and Billing & Cost add permissions only — they do not add a visible tab — so the only reliable way to confirm whether they are installed is to check Administration → Plugins.
Just like the base permissions, these follow the Default and Maximum model. The table below shows which of them are turned on by default for each Role, once the corresponding module is installed.
Role abbreviations used in this table:
SA = Super Administrator · AD = Administrator · MG = Manager · EX = Executive · IC = Internal Collaborator · EC = External Collaborator · CC = Collaborator (Customer) · GU = Guest · GC = Guest (Customer) · ND = Non-Executive Director
| Permission | SA | AD | MG | EX | IC | EC | CC | GU | GC | ND |
|---|---|---|---|---|---|---|---|---|---|---|
| Can manage mail templates | ✓ | ✓ | ||||||||
| Can see billing information | ✓ | ✓ | ✓ | ✓ | ||||||
| Can see cost information | ✓ | ✓ | ✓ | ✓ | ||||||
| Can edit completed payments | ✓ | ✓ | ||||||||
| Can manage all people | ✓ |
This table shows the highest level each Role is ever allowed to reach for these permissions. A blank cell means the permission is greyed out on screen and can never be granted to that Role — not by editing a user directly, and not through a Group.
Role abbreviations used in this table:
SA = Super Administrator · AD = Administrator · MG = Manager · EX = Executive · IC = Internal Collaborator · EC = External Collaborator · CC = Collaborator (Customer) · GU = Guest · GC = Guest (Customer) · ND = Non-Executive Director
| Permission | SA | AD | MG | EX | IC | EC | CC | GU | GC | ND |
|---|---|---|---|---|---|---|---|---|---|---|
| Can manage mail templates | ✓ | ✓ | ✓ | ✓ | ||||||
| Can see billing information | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | |||
| Can see cost information | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | |||
| Can edit completed payments | ✓ | ✓ | ✓ | |||||||
| Can manage all people | ✓ | ✓ | ✓ | ✓ |