Permissions reference

Every box in the role editor, what it lets someone do, and what it does not.

On this page

Every checkbox in Settings → Configuration → Roles, in the order you see them, with what each one actually lets a member do. If you are still choosing between the built-in roles, start with Roles and permissions instead.

How to read this page

A permission is one thing a member can do on the properties they are assigned to. A role is a bundle of permissions, and a member holding several roles on a property gets everything in all of them.

Two permissions are exceptions and reach the whole workspace, because what they control is shared to begin with: the lists of expense categories and payment methods, and the accounting connection. Granting either on one property grants it everywhere, and both rows say so. Anything that belongs to no single property, such as adding a property, changing workspace settings, or editing roles and approval workflows, is limited to workspace admins and is not granted by a box on this page.

The Status column reads one of four ways:

  • Enforced means the server checks it. Untick it and the action is refused, in the web app, in the mobile app, and through the API.
  • View only decides whether a member finds that section at all. It shapes the menus and pages they see rather than locking the records behind them.
  • Not active yet is reserved. Ticking it is safe and changes nothing today, and the row says what controls that behaviour instead.
  • Set in Billing means the box is not the control. Billing belongs to the account, and the owner grants it per person.

Two rules that no checkbox on this page can change:

  • Workspace admins pass everything. When you invite somebody you choose whether they are an Admin or a Member. Admins see and do everything on every property, whatever their roles say.
  • Approvals follow workflows, not permissions. Verification and approval steps are configured in workflows, and each step is assigned to a role. To act on a step, a member must hold that step's role on that property. Ticking extra boxes here will not do it.

Administration

PermissionWhat it lets someone doStatus
Full access full_accessPasses every check in the system on assigned properties. This is what makes the Admin role an admin. Grant it only to people you would make an admin.Enforced
Manage who works on a property manage_membersInvite people to a property, change their roles, and remove them. They cannot hand out a role that carries full access unless they hold it themselves.Enforced
Fix attached files and captured values manage_workflow_attachmentsReplace or delete a file attached to an approval step, remove an old version, and correct values captured on it, such as a wrong receipt or amount. Documents copied onto a contract stay locked. No role holds this by default.Enforced
Manage the accounting connection manage_accounting_integrationConnect the workspace to the accounting system and maintain the mappings: expense category to account, payment method to journal, VAT rate to tax code. The connection is one per workspace, so granting this on one property grants it across all of them. Held by Accountant.Enforced

Properties

PermissionWhat it lets someone doStatus
Edit property details manage_propertiesEdit the details of the properties they are assigned to. Adding a new property is a workspace decision and is limited to workspace admins, because a new property counts against your plan and belongs to no existing property.Enforced
Add, edit and remove units manage_unitsCreate units on a property, change their details, and delete a unit along with its history. Held by Property Manager.Enforced

Leases

PermissionWhat it lets someone doStatus
Draft and send lease offers manage_leasesCreate, edit and submit lease offers, record what the client answered, and manage the documents on a contract. This is the working permission of the Lease Manager.Enforced
Approve lease offers and contracts approve_leasesAct on the manager and general-manager review steps, turn an approved offer into a contract, and replace or remove a contract document. Broader than the name suggests. Held by General Manager and Property Manager.Enforced

Contracts

PermissionWhat it lets someone doStatus
See contracts view_contractsShows the Contracts section. Anyone who can draft or approve leases already sees it.View only
See contracts (older setting) create_contractsKept so older roles keep working. Despite the name it creates nothing; it only reveals the Contracts section. Use the row below to let someone add an existing contract.View only
Add an existing contract add_direct_contractRecord a contract that already exists, by hand or by importing an Ejar PDF, without going through the offer approval chain. It also covers the PDF reading itself, which costs money, so grant it deliberately. No role holds this by default.Enforced

Maintenance

Who may work on maintenance is decided by the maintenance workflow's step assignments and by role seniority, not by the boxes in this group. They mark what kind of job a role is, which is what the app uses to decide which sections to offer.

PermissionWhat it lets someone doStatus
Marks the role as field staff complete_maintenanceMarks the role as field staff, which keeps admin sections out of their way. Who finishes a maintenance job is set in the maintenance workflow.Not active yet
Marks the role as a maintenance reviewer review_maintenanceWho reviews finished work is set in the maintenance workflow. On mobile this box also shows the rent reminder list, which is unrelated to maintenance.Not active yet
Marks the role as maintenance management manage_maintenanceAssigning and closing maintenance follows the workflow and role seniority. Ticking this also reveals the Properties section.Not active yet

Recurring tasks

PermissionWhat it lets someone doStatus
Manage recurring tasks manage_recurring_tasksCreate, edit, pause, reactivate and reassign recurring templates such as cleaning, inspections and filter changes, on the properties they are assigned to. Also covers renew and terminate decisions on recurring service agreements. Held by General Manager, Property Manager and Accountant.Enforced

Payments

PermissionWhat it lets someone doStatus
See payments view_paymentsShows the Payments section and lets them open a payment.View only
Record payments manage_paymentsRecord a rent payment against an installment, including a single payment covering every unit on a multi-unit contract. Changing or deleting a payment afterwards needs "Record and adjust money owed". Held by Accountant.Enforced
Sign off on payments verify_paymentsApprove or return a recorded payment. If your payment workflow has an approval step, the role assigned to that step decides instead, so in most workspaces this box mainly grants the ability to open a payment for review. Held by Treasurer.Enforced

Receivables

PermissionWhat it lets someone doStatus
See receivables view_receivablesShows the Receivables section and what each tenant owes.View only
Record and adjust money owed manage_receivablesThe broad money permission, wider than its name: record and edit rent payments, expenses and deposit movements, link and unlink payments, and write off or adjust what is owed. Held by Accountant.Enforced
Give payment discounts manage_payment_discountsReduce what a tenant owes on scheduled installments, one at a time or in bulk, and see the discount history. Kept separate from ordinary receivables work because forgiving rent is a business decision. No role holds this by default.Enforced
Propose a new payment plan manage_payment_reschedulesPropose re-timing, splitting or merging the installments a tenant has left. Nothing changes until the proposal is approved, and who approves it is set in the workflow. Held by Lease Manager.Enforced

Expenses

PermissionWhat it lets someone doStatus
See expenses view_expensesShows the Expenses section.View only
Record expenses manage_expensesRecord and edit expenses and mark them paid, on the properties they are assigned to. Expense categories and payment methods are shared lists, so granting this on one property lets them change those for the whole workspace. Held by Accountant.Enforced

Deposits

PermissionWhat it lets someone doStatus
See deposits view_depositsShows the Deposits section.View only
Sort out stuck deposits manage_depositsCancel a refund stuck waiting for approval, and delete a deposit record. Recording a deposit or its refund needs "Record and adjust money owed". Held by Accountant.Enforced

Financial reporting

PermissionWhat it lets someone doStatus
Financial oversight view_financialsOne tick that opens every money section: payments, receivables, expenses and deposits. The natural choice for an owner, a treasurer or an outside auditor who should see the numbers but touch nothing. Held by General Manager, Accountant and Treasurer.View only

Contacts

PermissionWhat it lets someone doStatus
See contacts manage_contactsShows the Contacts section with tenants, owners and vendors. Editing a contact is currently open to anyone who can reach the section, so treat this as who sees contacts rather than who may change them. Held by General Manager, Lease Manager and Property Manager.View only

View access

PermissionWhat it lets someone doStatus
See the dashboard view_dashboardShows the dashboard with portfolio figures. This is the whole of the Shareholder role.View only
See reports view_reportsShows the Reports section. Held by General Manager and Accountant.View only

Billing

Billing belongs to the account, not to a property role. The account owner always has it, workspace admins have it by default, and the owner grants or revokes it per person from Settings → Billing. The boxes below are listed because the role editor shows every permission in the catalog, but the control is elsewhere.

PermissionWhat it lets someone doStatus
Manage the subscription subscription.manageSubscribing, changing plan, cancelling and retrying a failed payment. Granted per person in Settings, Billing.Set in Billing
See invoices invoices.viewShows the Invoices tab with your subscription invoices.Set in Billing
Download invoices invoices.downloadAnyone who can see an invoice can already download it, so this box changes nothing.Set in Billing
Manage saved cards payment_methods.manageThe card your subscription is billed to. Note this is not the same as the workspace payment methods, such as Cash or Bank transfer, which live under Expenses.Set in Billing