> ## Documentation Index
> Fetch the complete documentation index at: https://docs.timetracker.in/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles and permissions matrix

> The complete TimeTracker permissions matrix: all 66 capabilities against all 7 roles, grouped by area, with the default supervision scope for each role.

Every capability in TimeTracker, against every role. A check means the role holds it
by default. A dash means it does not.

## Role summary

| Role                | Capabilities | Default supervision scope |
| ------------------- | :----------: | ------------------------- |
| **Owner**           |   66 of 66   | Workspace *(locked)*      |
| **Admin**           |   65 of 66   | Workspace                 |
| **Project Manager** |   43 of 66   | Project                   |
| **Finance**         |   14 of 66   | Workspace                 |
| **Member**          |   16 of 66   | None                      |
| **Contractor**      |   12 of 66   | None                      |
| **Client**          |    0 of 66   | None *(locked)*           |

<Note>
  **Owner and Admin differ by exactly one capability:** `workspace.delete`. Everything
  else an Owner can do, an Admin can do too.

  **Client holds zero internal capabilities.** A portal contact is not a member of your
  team. They see only what is shared with their own client company. That empty set is
  the portal firewall, and it cannot be edited.
</Note>

## The matrix

### Workspace

| Capability                 | Owner | Admin | Project Manager | Finance | Member | Contractor | Client |
| -------------------------- | :---: | :---: | :-------------: | :-----: | :----: | :--------: | :----: |
| `workspace.updateSettings` |   ✓   |   ✓   |        –        |    –    |    –   |      –     |    –   |
| `workspace.delete`         |   ✓   |   –   |        –        |    –    |    –   |      –     |    –   |
| `billing.manage`           |   ✓   |   ✓   |        –        |    –    |    –   |      –     |    –   |
| `data.export`              |   ✓   |   ✓   |        –        |    ✓    |    –   |      –     |    –   |
| `location.manage`          |   ✓   |   ✓   |        –        |    –    |    –   |      –     |    –   |

### Members and roles

| Capability          | Owner | Admin | Project Manager | Finance | Member | Contractor | Client |
| ------------------- | :---: | :---: | :-------------: | :-----: | :----: | :--------: | :----: |
| `member.invite`     |   ✓   |   ✓   |        ✓        |    –    |    –   |      –     |    –   |
| `member.create`     |   ✓   |   ✓   |        –        |    –    |    –   |      –     |    –   |
| `member.changeRole` |   ✓   |   ✓   |        –        |    –    |    –   |      –     |    –   |
| `member.remove`     |   ✓   |   ✓   |        –        |    –    |    –   |      –     |    –   |
| `role.manage`       |   ✓   |   ✓   |        –        |    –    |    –   |      –     |    –   |
| `invite.revoke`     |   ✓   |   ✓   |        ✓        |    –    |    –   |      –     |    –   |
| `audit.read`        |   ✓   |   ✓   |        ✓        |    ✓    |    –   |      –     |    –   |
| `group.manage`      |   ✓   |   ✓   |        –        |    –    |    –   |      –     |    –   |

### Clients, projects and tasks

| Capability            | Owner | Admin | Project Manager | Finance | Member | Contractor | Client |
| --------------------- | :---: | :---: | :-------------: | :-----: | :----: | :--------: | :----: |
| `client.view`         |   ✓   |   ✓   |        ✓        |    ✓    |    ✓   |      –     |    –   |
| `client.manage`       |   ✓   |   ✓   |        ✓        |    –    |    –   |      –     |    –   |
| `project.manage`      |   ✓   |   ✓   |        ✓        |    –    |    –   |      –     |    –   |
| `tag.manage`          |   ✓   |   ✓   |        ✓        |    –    |    –   |      –     |    –   |
| `task.create`         |   ✓   |   ✓   |        ✓        |    –    |    ✓   |      ✓     |    –   |
| `task.edit`           |   ✓   |   ✓   |        ✓        |    –    |    ✓   |      ✓     |    –   |
| `task.delete`         |   ✓   |   ✓   |        ✓        |    –    |    –   |      –     |    –   |
| `task.reviseEstimate` |   ✓   |   ✓   |        ✓        |    –    |    –   |      –     |    –   |
| `task.bulkEdit`       |   ✓   |   ✓   |        ✓        |    –    |    –   |      –     |    –   |

### Rates and cost

| Capability         | Owner | Admin | Project Manager | Finance | Member | Contractor | Client |
| ------------------ | :---: | :---: | :-------------: | :-----: | :----: | :--------: | :----: |
| `rate.manage`      |   ✓   |   ✓   |        ✓        |    –    |    –   |      –     |    –   |
| `rate.viewBilling` |   ✓   |   ✓   |        ✓        |    –    |    –   |      –     |    –   |
| `rate.viewCost`    |   ✓   |   ✓   |        –        |    –    |    –   |      –     |    –   |

### Time tracking

| Capability      | Owner | Admin | Project Manager | Finance | Member | Contractor | Client |
| --------------- | :---: | :---: | :-------------: | :-----: | :----: | :--------: | :----: |
| `time.track`    |   ✓   |   ✓   |        ✓        |    –    |    ✓   |      ✓     |    –   |
| `time.edit`     |   ✓   |   ✓   |        ✓        |    –    |    ✓   |      ✓     |    –   |
| `time.viewCost` |   ✓   |   ✓   |        –        |    –    |    –   |      –     |    –   |

### Timesheets

| Capability            | Owner | Admin | Project Manager | Finance | Member | Contractor | Client |
| --------------------- | :---: | :---: | :-------------: | :-----: | :----: | :--------: | :----: |
| `time.submit`         |   ✓   |   ✓   |        ✓        |    –    |    ✓   |      ✓     |    –   |
| `time.viewOthers`     |   ✓   |   ✓   |        ✓        |    –    |    –   |      –     |    –   |
| `time.editOthers`     |   ✓   |   ✓   |        ✓        |    –    |    –   |      –     |    –   |
| `time.submitOnBehalf` |   ✓   |   ✓   |        ✓        |    –    |    –   |      –     |    –   |
| `time.remind`         |   ✓   |   ✓   |        ✓        |    –    |    –   |      –     |    –   |
| `time.approve`        |   ✓   |   ✓   |        ✓        |    –    |    –   |      –     |    –   |
| `time.reopenApproval` |   ✓   |   ✓   |        –        |    –    |    –   |      –     |    –   |
| `time.adjust`         |   ✓   |   ✓   |        ✓        |    ✓    |    –   |      –     |    –   |
| `period.close`        |   ✓   |   ✓   |        –        |    –    |    –   |      –     |    –   |

### Time Clock

| Capability                | Owner | Admin | Project Manager | Finance | Member | Contractor | Client |
| ------------------------- | :---: | :---: | :-------------: | :-----: | :----: | :--------: | :----: |
| `timecard.clock`          |   ✓   |   ✓   |        ✓        |    ✓    |    ✓   |      ✓     |    –   |
| `timecard.view`           |   ✓   |   ✓   |        ✓        |    ✓    |    ✓   |      ✓     |    –   |
| `timecard.submit`         |   ✓   |   ✓   |        ✓        |    ✓    |    ✓   |      ✓     |    –   |
| `timecard.manage`         |   ✓   |   ✓   |        ✓        |    –    |    –   |      –     |    –   |
| `timecard.submitOnBehalf` |   ✓   |   ✓   |        ✓        |    –    |    –   |      –     |    –   |
| `timecard.approve`        |   ✓   |   ✓   |        ✓        |    –    |    –   |      –     |    –   |
| `timecard.reopen`         |   ✓   |   ✓   |        –        |    –    |    –   |      –     |    –   |

### Work schedules

| Capability        | Owner | Admin | Project Manager | Finance | Member | Contractor | Client |
| ----------------- | :---: | :---: | :-------------: | :-----: | :----: | :--------: | :----: |
| `schedule.view`   |   ✓   |   ✓   |        ✓        |    ✓    |    ✓   |      ✓     |    –   |
| `schedule.manage` |   ✓   |   ✓   |        –        |    –    |    –   |      –     |    –   |

### Budgets and money

| Capability               | Owner | Admin | Project Manager | Finance | Member | Contractor | Client |
| ------------------------ | :---: | :---: | :-------------: | :-----: | :----: | :--------: | :----: |
| `budget.manage`          |   ✓   |   ✓   |        ✓        |    –    |    –   |      –     |    –   |
| `invoice.manage`         |   ✓   |   ✓   |        ✓        |    ✓    |    –   |      –     |    –   |
| `payment.record`         |   ✓   |   ✓   |        ✓        |    ✓    |    –   |      –     |    –   |
| `expense.submit`         |   ✓   |   ✓   |        ✓        |    ✓    |    ✓   |      ✓     |    –   |
| `expense.approve`        |   ✓   |   ✓   |        ✓        |    ✓    |    –   |      –     |    –   |
| `expenseCategory.manage` |   ✓   |   ✓   |        –        |    ✓    |    –   |      –     |    –   |

### Time off

| Capability           | Owner | Admin | Project Manager | Finance | Member | Contractor | Client |
| -------------------- | :---: | :---: | :-------------: | :-----: | :----: | :--------: | :----: |
| `leave.request`      |   ✓   |   ✓   |        ✓        |    ✓    |    ✓   |      ✓     |    –   |
| `leave.approve`      |   ✓   |   ✓   |        ✓        |    –    |    –   |      –     |    –   |
| `leave.viewOthers`   |   ✓   |   ✓   |        ✓        |    –    |    –   |      –     |    –   |
| `leave.managePolicy` |   ✓   |   ✓   |        –        |    –    |    –   |      –     |    –   |

### Reports

| Capability        | Owner | Admin | Project Manager | Finance | Member | Contractor | Client |
| ----------------- | :---: | :---: | :-------------: | :-----: | :----: | :--------: | :----: |
| `report.view`     |   ✓   |   ✓   |        ✓        |    –    |    ✓   |      –     |    –   |
| `report.create`   |   ✓   |   ✓   |        ✓        |    –    |    ✓   |      –     |    –   |
| `report.edit`     |   ✓   |   ✓   |        ✓        |    –    |    ✓   |      –     |    –   |
| `report.manage`   |   ✓   |   ✓   |        –        |    –    |    –   |      –     |    –   |
| `report.share`    |   ✓   |   ✓   |        –        |    –    |    –   |      –     |    –   |
| `report.schedule` |   ✓   |   ✓   |        –        |    –    |    –   |      –     |    –   |
| `report.export`   |   ✓   |   ✓   |        –        |    –    |    –   |      –     |    –   |

### Resource Planner

| Capability           | Owner | Admin | Project Manager | Finance | Member | Contractor | Client |
| -------------------- | :---: | :---: | :-------------: | :-----: | :----: | :--------: | :----: |
| `block.manage`       |   ✓   |   ✓   |        ✓        |    –    |    ✓   |      ✓     |    –   |
| `block.manageOthers` |   ✓   |   ✓   |        ✓        |    –    |    –   |      –     |    –   |

### Integrations

| Capability       | Owner | Admin | Project Manager | Finance | Member | Contractor | Client |
| ---------------- | :---: | :---: | :-------------: | :-----: | :----: | :--------: | :----: |
| `webhook.manage` |   ✓   |   ✓   |        –        |    –    |    –   |      –     |    –   |

## How to read this

Three things decide whether an action succeeds. This table covers only the first.

| Check                                                                          | Question                      | This page                 |
| ------------------------------------------------------------------------------ | ----------------------------- | ------------------------- |
| **Capability**                                                                 | May you do this at all?       | Yes – the matrix above    |
| **[Supervision scope](/concepts/supervision-scope)**                           | For whom?                     | Only the default per role |
| **[App](/concepts/apps-and-modules) and [plan](/concepts/plans-and-features)** | Is the area on, and paid for? | No                        |

A Project Manager holds `time.approve`, but only for people inside their scope. A
capability is not a scope. See [supervision scope](/concepts/supervision-scope).

## Owner-exclusive capabilities

One capability can never be granted to another role, no matter how you build it:

| Capability         | Why it is reserved                                                                                                                               |
| ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ |
| `workspace.delete` | Deleting the workspace is irreversible. Even a custom "admin-like" role is refused this, so an Admin cannot mint a role that deletes the tenant. |

Granting ownership itself is also Owner-only. It is not done through the capability
list at all – an Owner transfers it deliberately. See
[change someone's role](/team/change-someones-role).

## Capabilities that can be denied per person

Per-person overrides are **deny-only**. You can take a capability away from one
person on top of their role. You can never use an override to grant something the
role does not already include.

| Capability       | Why you would switch it off                                                                                                                   |
| ---------------- | --------------------------------------------------------------------------------------------------------------------------------------------- |
| `timecard.clock` | Clocking in and out is a working style, not a rank. A contractor who bills by deliverable should not use the clock, while everyone else does. |

See [per-person permissions](/team/per-person-permissions).

## Capabilities a per-project role can widen

A person can hold a different role on one project. That per-project role is
**widen-only**, and it reaches exactly one capability:

| Capability            | Effect                                                                                             |
| --------------------- | -------------------------------------------------------------------------------------------------- |
| `task.reviseEstimate` | A person can be allowed to revise estimates on a single project without holding it workspace-wide. |

Every other capability is decided by the workspace role alone. A per-project role can
never take something away.

## Which capabilities need a scope

These capabilities reach across people, so a supervision scope decides who they
apply to. At scope **None** they have nobody to act on.

`time.viewOthers` · `time.editOthers` · `time.submitOnBehalf` ·
`time.reopenApproval` · `time.remind` · `time.approve` · `time.adjust` ·
`timecard.manage` · `timecard.approve` · `timecard.submitOnBehalf` ·
`timecard.reopen` · `leave.approve` · `leave.viewOthers` · `expense.approve` ·
`block.manageOthers`

Everything else is about a thing, not a person. Closing a period, changing workspace
settings and managing members are workspace-level administration.

## Which roles can be invited

Every role except Owner can be assigned in an invitation. Ownership is never minted
at invite time – an existing Owner transfers it.

A **Client** can only be invited from that client company's page, because a portal
contact has to belong to a company. See
[invite a client contact](/portal/invite-a-client-contact).

## Two roles have a locked capability set

| Role       | What is locked                                                                  |
| ---------- | ------------------------------------------------------------------------------- |
| **Owner**  | Holds every capability. Scope pinned to Workspace. Cannot be deleted or edited. |
| **Client** | Holds no capabilities. Scope pinned to None. Cannot be deleted or edited.       |

The other five roles are editable, and you can build new ones. See
[custom roles](/team/custom-roles).

## Common questions

<AccordionGroup>
  <Accordion title="Can I give a Member the ability to approve time?">
    Yes, with a [custom role](/team/custom-roles). Copy the Member set, add
    `time.approve`, and give the role a supervision scope – otherwise the person has
    the permission and nobody to use it on.
  </Accordion>

  <Accordion title="Why does Finance hold so few capabilities?">
    Finance owns the money surface, not delivery. Invoices, payments, expenses,
    expense categories, the audit log and data export. It deliberately does not hold
    project or task management.
  </Accordion>

  <Accordion title="Why can a Contractor not see clients?">
    `client.view` is the only difference in that area. A Contractor tracks time and
    works tasks without seeing your book of business. They also lack the three report
    capabilities a Member holds.
  </Accordion>

  <Accordion title="Does a Project Manager see cost rates?">
    No. `rate.viewCost` and `time.viewCost` stay with Owner and Admin by default, so
    internal pay data does not travel with delivery responsibility. A PM does hold
    `rate.viewBilling` – what you charge.
  </Accordion>

  <Accordion title="Can I edit the Owner role?">
    No. Owner is locked at every capability and at workspace scope. That is what makes
    it a guaranteed way back into your own workspace.
  </Accordion>
</AccordionGroup>

## Related guides

<CardGroup cols={2}>
  <Card title="Capabilities reference" icon="key" href="/reference/capabilities">
    What each capability actually lets you do.
  </Card>

  <Card title="Supervision scope" icon="user-group" href="/concepts/supervision-scope">
    The other half of every permission check.
  </Card>

  <Card title="Custom roles" icon="sliders" href="/team/custom-roles">
    Build a role that fits your team.
  </Card>

  <Card title="Per-person permissions" icon="user-gear" href="/team/per-person-permissions">
    Deny-only exceptions for one person.
  </Card>

  <Card title="Roles and permissions" icon="lock" href="/concepts/roles-and-capabilities">
    The model behind the matrix.
  </Card>

  <Card title="I cannot see a feature" icon="circle-question" href="/troubleshooting/i-cannot-see-a-feature">
    Which of the four gates is closed.
  </Card>
</CardGroup>
