Skip to main content
A permission and a scope are two different things, and TimeTracker checks both.
  • A capability answers: may you do this at all?
  • A supervision scope answers: for whom?
Priya holds time.viewOthers, so she may view other people’s hours. Her scope decides whose hours those are. If someone tells you “I have the permission but I still cannot see it”, the answer is almost always scope.

What a scope controls

One setting governs two things at once. This is worth reading twice, because naming only half of it is what confuses people. A scope decides:
  1. Which people you can act on – their time, leave and timecards.
  2. Whether you see every project, or only the ones you manage or are staffed on.
The people half is where the middle scopes differ. On the project half there are really only two answers: Workspace scope sees every project, and every other scope sees only the projects you manage or are assigned to. Because you only see a client when you can see one of their projects, project reach also decides which clients appear in your lists. There is no separate client scope.

The five levels

Scope is set on a role, from narrowest to widest. The longer explanation of each:
Projects they manage or are assigned to, and nobody else’s time, leave or timecards – even if they hold the permissions.This is the default for Members and Contractors. Sarah sees her own work and the projects she is on. She does not see what Jonas tracked.
Projects they manage or are assigned to, plus anyone who shares one of those projects with them.Priya manages the Bluebird Website Redesign. Sarah and Jonas are both on it, so Priya can see and approve their time on any project they share with her.
Projects they manage or are assigned to, plus anyone in the same group.Being in a group does not by itself add a project. This scope widens the people, not the project list.
Both of the above. Their projects, plus anyone on those projects or in the same group.Use this when a team lead runs projects and also line-manages people who are not on those projects.
Every project and every person, with no filter.Use for Owners, Admins, Finance, and small teams with no meaningful split.

Default scope for each role

Two roles have a locked scope. An Owner is always Workspace – they cannot lose sight of their own business. A Client is always None – the portal firewall depends on it. Neither can be changed.
Every other role’s scope is editable when you build a custom role.

Which permissions actually need a scope

Most permissions do not care about scope. Editing a task or creating a project is about the thing, not about a person. Scope matters for the permissions that reach across people: A capability from this list is meaningless at scope None – you hold the permission but it has nobody to apply to. The role editor warns you about that combination.
Some permissions are deliberately not scoped. Closing a period, changing workspace settings and managing members are workspace-level administration, not per-person data access. A report is an aggregate surface – its rows are scoped, but holding report.view on its own implies no cross-person reach.

A worked example

Northwind Studio has two client teams.
  • Priya is a Project Manager at scope Project. She runs Bluebird Coffee’s Website Redesign and Harbor Logistics’ Mobile App.
  • Sarah and Jonas are on the Bluebird project.
  • Ana is a contractor on the Fenwick Legal Brand Refresh only.
What Priya sees: Now Tom (Admin, scope Workspace) sees all four people and all four projects, because his scope has no filter. If Northwind wants Priya to cover for Ana’s manager during holidays, they have two options: add Priya to the Fenwick project, or widen her scope to include her group.

How scope interacts with reports

A report is not exempt from scope. The report runs, but the rows it returns are filtered to what you may see. That means two people can open the same saved report and get different totals, and both are correct. Priya’s version of a “Hours by person” report shows the people in her scope. Tom’s shows everyone. This is deliberate – it lets you share one report definition across a team without leaking data. See report permissions.

Scope and cost are different walls

Scope decides whose data you see. It does not decide which numbers you see. Cost rates and margin are hidden by a separate capability check (rate.viewCost, time.viewCost). Someone can have workspace-wide scope and still never see what people cost. See cost rates.

Permissions

Common questions

Their scope does not reach that person. Either add the manager to a project the person works on, put them both in the same group and use a group scope, or widen the role to workspace scope.
Scope lives on the role. To give one person a different reach, build a custom role for them. Per-person overrides can only take permissions away, not widen scope.
No. A group scope widens which people you can act on. It does not add their projects to your list.
Because report rows are scoped. Each person sees the slice they are allowed to see. Nothing is broken.
No. The Owner role is locked to workspace scope precisely so this cannot happen.

Roles and permissions

The capability half of the check.

Custom roles

Where scope is set.

Groups

Standing teams that a scope can follow.

Project visibility

Which projects appear in your list.