> ## Documentation Index
> Fetch the complete documentation index at: https://docs.timetracker.in/llms.txt
> Use this file to discover all available pages before exploring further.

# Location rule permissions

> Who can create and manage location rules in TimeTracker, what a rule can never restrict, and what people are asked to allow on their own device.

Two different questions live on this page:

1. **Who can manage location rules** – a capability question.
2. **What a rule can do to someone** – a state question, and a deliberately
   limited one.

## Who can manage location rules

One capability controls everything: `location.manage`.

| Role            | Holds `location.manage` |
| --------------- | ----------------------- |
| Owner           | Yes                     |
| Admin           | Yes                     |
| Project Manager | No                      |
| Finance         | No                      |
| Member          | No                      |
| Contractor      | No                      |
| Client          | No                      |

Only Owner and Admin. It is not given to Project Manager or Finance, and it is
not granted to custom roles by default.

Without it you see: *"You can't change where people are allowed to work from. Ask
a workspace admin if you need to."*

### What the capability covers

| Action                                                | Needs                                 |
| ----------------------------------------------------- | ------------------------------------- |
| See the Location rules settings pages                 | `location.manage`                     |
| Create, rename, edit a rule                           | `location.manage`                     |
| Add networks and places                               | `location.manage`                     |
| Choose what a rule limits                             | `location.manage`                     |
| Switch a rule between Watching and Enforcing          | `location.manage`                     |
| Assign a rule to people                               | `location.manage`                     |
| Delete a rule                                         | `location.manage`                     |
| Read the [activity log](/location-rules/activity-log) | `location.manage` **or** `audit.read` |

An auditor holding `audit.read` can read the log without being able to change a
single rule.

<Note>
  The **Location rules** sidebar entry appears only when you hold the capability
  **and** the app is switched on.
</Note>

## Location is a state block, not a permission

This is the distinction that matters most.

|                     | Capability                     | Location rule                             |
| ------------------- | ------------------------------ | ----------------------------------------- |
| Question it answers | **May** you do this at all?    | Can you do it **right now, from here**?   |
| Where it lives      | Roles and per-person overrides | A location rule                           |
| Changes when        | An admin changes your role     | You move                                  |
| What you see        | The control disappears         | The control stays visible but is disabled |

Sarah Lin still holds `time.track` in a coffee shop. The rule refuses the action
until she is back at an approved network or place. Her role is untouched, and
everything she already tracked is safe.

<Note>
  Blocked controls are **visible and disabled**, never hidden. Hiding them would
  look like a permission problem, which would send people to the wrong person for
  help.
</Note>

## What a rule can never limit

Thirteen actions can be limited. Everything to do with running the workspace is
**permanently excluded**:

| Never limitable                    | Why                                        |
| ---------------------------------- | ------------------------------------------ |
| Workspace settings                 | You must always be able to fix a rule      |
| Billing                            | A location rule must never stop you paying |
| Roles and custom roles             | Access management must stay reachable      |
| Inviting and removing members      | Same                                       |
| Revoking invitations               | Same                                       |
| Reading the audit trail            | Same                                       |
| Managing location rules themselves | Otherwise a rule could lock itself in      |

The enforce confirmation states it: *"you will always be able to reach these
settings – location rules never limit settings, billing or roles."*

## The 13 actions a rule can limit

| Group                         | Actions                      | Capability         |
| ----------------------------- | ---------------------------- | ------------------ |
| **Workspace**                 | Export workspace data        | `data.export`      |
| **Clients, projects & tasks** | Create tasks                 | `task.create`      |
|                               | Edit tasks                   | `task.edit`        |
| **Time tracking**             | Track time                   | `time.track`       |
|                               | Edit time entries            | `time.edit`        |
| **Timesheets**                | Submit own timesheet         | `time.submit`      |
|                               | Approve or reject timesheets | `time.approve`     |
| **Timecards**                 | Clock in and out             | `timecard.clock`   |
|                               | Submit own timecard          | `timecard.submit`  |
|                               | Approve or reject timecards  | `timecard.approve` |
| **Budgets & money**           | Submit expenses              | `expense.submit`   |
|                               | Approve or reject expenses   | `expense.approve`  |
| **Reports**                   | Export reports               | `report.export`    |

A rule can only ever restrict a capability someone **already holds**. It never
grants anything.

## What people are asked on their own device

Being straight with your team about this is worth doing before you switch a rule
on.

### For an office network check

**Nothing is asked.** The address a connection comes from is visible to any
website. There is no prompt and nothing to allow.

### For a place check

| Situation                                          | What happens                                               |
| -------------------------------------------------- | ---------------------------------------------------------- |
| They have already allowed location for TimeTracker | Their position is read quietly in the background           |
| They have never been asked                         | **Nothing is requested.** No pop-up appears.               |
| They have denied location                          | No position is read. The check records **Couldn't check**. |

TimeTracker never triggers a browser permission prompt on its own. If somebody has
not granted location access, every check on their actions records **Couldn't
check**, and they see a banner explaining how to allow it if a rule needs it.

### What is stored about a person

For each check: the time, the internet address, the position their device
reported, the rule that applied, and the outcome. The reported position is kept
even when it was discarded as too vague.

That record is readable by anyone with `location.manage` or `audit.read`. See
[Activity log](/location-rules/activity-log).

## Who is never subject to a rule

| Who                                | Why                                                                                    |
| ---------------------------------- | -------------------------------------------------------------------------------------- |
| **Client-portal contacts**         | Clients are outside your workspace. They are excluded from every rule and every count. |
| **Anyone exempted**                | An assignment set to **Exempt – no location rule** lifts every rule from that target.  |
| **Anyone no assignment points at** | A rule with no assignment does nothing at all.                                         |

## What someone blocked actually sees

A banner at the top of the app, with a **Check again** button:

| State                           | Message                                                                                                                                                                                             |
| ------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Away from an approved place     | **You're away from `<rule>`** – *"Your workspace only allows `<actions>` from the office. Everything you've already tracked is saved – you can carry on working and finish this when you're back."* |
| Location blocked in the browser | **We can't tell where you are** – *"Your browser is blocking location access… Turn on location for this site in your browser settings, then reload."*                                               |
| No connection                   | **You're offline** – *"Nothing is lost – everything you've tracked is saved and will be here when you reconnect."*                                                                                  |
| Mid-check                       | **We're checking where you are**                                                                                                                                                                    |

Blocked controls show a message naming where the action *can* be done – *"You can
clock in from work. Nothing you've tracked is affected."*

<Tip>
  Every message says the same thing twice: what to do, and that nothing is lost.
  That is deliberate. A person blocked mid-week needs to know their tracked time is
  safe before they need to know anything else.
</Tip>

## Precedence when several assignments match

Most specific wins:

**Person → Group → Role → Everyone**

Within the same level, an **exemption beats a restriction**. Across levels the
more specific level wins outright, so a rule applied to one person survives a
workspace-wide exemption.

Someone in several groups follows their **first** group.

## Example

Northwind Studio's setup:

| Person        | Role            | Assignment          | Effect                                  |
| ------------- | --------------- | ------------------- | --------------------------------------- |
| Maya Ellis    | Owner           | Everyone → `Studio` | Covered, and can always change the rule |
| Tom Whitfield | Admin           | Everyone → `Studio` | Covered, and can manage rules           |
| Priya Raman   | Project Manager | Everyone → `Studio` | Covered. Cannot see the rules page.     |
| Ana Ferreira  | Contractor      | Person → `Studio`   | Covered by her own assignment           |
| Sarah Lin     | Member          | Person → **Exempt** | Not covered – she travels to clients    |
| Ruth Castillo | Client          | –                   | Never covered. Clients are excluded.    |

Sarah's person-level exemption beats the workspace-wide `Studio` assignment,
because a more specific level always wins.

## Turning everything off

Turn the **Location rules** app off under **Settings → Apps**: *"Location rules
stop applying straight away and everyone can clock in and submit from anywhere.
Your rules, the people they cover, and the history are all kept."*

This is the emergency exit. An Owner or Admin who has locked the team out can
always reach it, because settings can never be limited by a rule.

<Note>
  Even with the app off, an admin can still open the rules pages to see and fix
  them. That is deliberate – you must be able to repair a rule before you turn the
  app back on.
</Note>

## Common questions

<AccordionGroup>
  <Accordion title="Can a location rule lock me out of my own workspace?">
    No. Settings, billing, roles and member management can never be limited. You
    can always reach **Settings → Location rules** and switch a rule back to
    Watching, or turn the whole app off.
  </Accordion>

  <Accordion title="Can a Project Manager manage location rules?">
    No. Only Owner and Admin hold `location.manage`.
  </Accordion>

  <Accordion title="Does a location rule remove a permission?">
    No. It blocks an action based on where you are. Your role and capabilities are
    unchanged, and the action works again as soon as you are back at work.
  </Accordion>

  <Accordion title="Will my team get a browser pop-up asking for location?">
    Not from TimeTracker. It never triggers a permission prompt on its own. Someone
    who has not granted location produces "Couldn't check" and sees a banner
    explaining how to allow it.
  </Accordion>

  <Accordion title="What can an admin see about where I am?">
    The internet address you connected from, the position your device reported,
    which rule applied and what was decided. All of it is in the activity log.
  </Accordion>

  <Accordion title="Are client-portal contacts affected?">
    No. Clients are never subject to a location rule.
  </Accordion>

  <Accordion title="Can I exempt one person from a workspace-wide rule?">
    Yes. Apply a rule to that person and choose **Exempt – no location rule**. A
    person-level assignment beats a workspace-level one.
  </Accordion>
</AccordionGroup>

## Troubleshooting

**I cannot see the Location rules page.** You need `location.manage`, and the
Location rules app must be on. Owner and Admin only.

**Someone is blocked who should not be.** Check the **Who this affects** table on
the settings page. It shows the rule and the level it was applied at. Then check
the [activity log](/location-rules/activity-log) for the reason.

**A rule is stopping an action I did not intend to limit.** Open the rule and read
**What this rule limits**. Untick what should not be there and save.

**I need to lift everything now.** Turn the Location rules app off under
**Settings → Apps**. Every rule stops applying immediately and nothing is lost.

## Related guides

<CardGroup cols={2}>
  <Card title="Location rules overview" icon="map-pin" href="/location-rules/overview">
    The concept and what it cannot see.
  </Card>

  <Card title="Create a location rule" icon="plus" href="/location-rules/create-a-policy">
    Building and assigning a rule.
  </Card>

  <Card title="Activity log" icon="clock-rotate-left" href="/location-rules/activity-log">
    What is recorded about each check.
  </Card>

  <Card title="Roles and capabilities" icon="shield" href="/concepts/roles-and-capabilities">
    The full capability model.
  </Card>

  <Card title="Per-person permissions" icon="user-gear" href="/team/per-person-permissions">
    Denying a capability, which is a different thing.
  </Card>

  <Card title="Apps and modules" icon="toggle-on" href="/concepts/apps-and-modules">
    The emergency off switch.
  </Card>
</CardGroup>
