Roles and permissions

Give people exactly the access they need — no more, no less.

Plans:
FreeStarterProfessionalBusiness
For:Admin
0:00 / 2:55
Listen to this article

A shift supervisor needs the roster. A bookkeeper needs the payroll. Neither of them needs your billing details.

A role decides two things: which parts of the dashboard someone can open, and whether they can change what they see or only look at it.

The five built-in roles

Available on every plan, including Free. Pick the one that matches the job.

👑 Manager Everything except Settings — the closest thing to a second owner.
📋 Supervisor Runs the floor: roster, live monitoring, photos, messages, and approving leave. Never sees pay.
📅 Scheduler Builds and sends the roster. Nothing else — no pay, no staff changes.
💰 Payroll Officer Timesheets, payroll, exports and mileage. The bookkeeper. Can't edit the roster or your staff.
👀 Viewer Read-only across the business. Changes nothing. Doesn't see pay unless you add it.
🙋 Staff The default, and not an admin role at all. They see their own dashboard — roster, timesheet, payslips, leave and mileage.

Building your own role

If none of the five fit, build one. Custom roles need the Professional or Business plan; the five built-in roles work on every plan.

  1. Go to Settings → Roles & permissions.
  2. Choose Create role.
  3. Pick the built-in role closest to what you want — you always start from something, never a blank page.
  4. Adjust each area to No access, View, or Manage.
  5. Tick any of the extras: export payroll data, sign off timesheets, approve leave, approve mileage claims, send roster emails.
  6. Give it a name and save.
⚠️

Starting from a role brings its extras with it. If you begin from Manager, all five extras are already ticked — so setting every area to No access does not leave the role granting nothing. It still approves leave, signs off timesheets and exports payroll. That is the point of the extras being separate, but it surprises people. The editor shows you the running total under This role grants…; if it lists things you did not intend, untick them, or use Remove the extras too. Want a genuinely empty role? Choose Start with no access instead of a preset.

📱

Works on your phone too. The app has the same editor under Settings → Roles — create, edit, duplicate and delete — and you assign a role from Manage → Staff. Only plan changes still happen on the website.

A worked example

A business asked for someone who could only download the timesheet PDF and reach nothing else. That is one role:

  • Set every area to No access.
  • Tick Export / download payroll data.
  • Name it "Timesheet Export Only" and assign it.

When that person signs in they see Payments → Export and nothing else. Not the payroll dashboard, not the staff list, not the roster.

It works because the extras are separate from the View/Manage choice. Ticking “export” doesn’t quietly also grant “see everyone’s pay on screen”.

What nobody can be given

Some things belong to the account owner and cannot be handed out — not to a manager, and not to a custom role. There is no checkbox for them:

  • Changing the plan or payment method, and the billing portal.
  • Buying or cancelling add-ons.
  • Deleting the business.
  • Resetting two-factor authentication.
  • Creating and assigning roles.
🔒

That last one is the point. Because only you can assign roles, nobody can quietly give themselves more access than you gave them — not even a manager.

Assigning a role

  1. Go to Manage → Staff Members.
  2. Add, invite or edit a staff member.
  3. Choose their Role.

Only the account owner can assign a role that has admin access. Managers can add and edit staff, but cannot promote anyone — including themselves.

Two things worth knowing

  • Editing a role applies straight away. If you add roster access to a role, everyone with it can use the roster on their next click — no signing out.
  • Moving someone to a different role signs them out. They sign back in with their new access. This is deliberate: it is how their access is refreshed everywhere at once.

Anyone with an admin role needs a login (email and password) to reach the dashboard. See Invite staff by email.