The three checks
Two people can open the very same shared report and read different numbers. That is correct behaviour, not a bug.
The seven report capabilities
report.manage is a superset of report.edit – holding manage satisfies every edit check on its own.
Editing rules
Ownership alone is never enough on a personal report. And a shared report is workspace property, so its author does not keep unilateral rights over it.
What each role holds by default
Reports does not appear in the sidebar for Finance, Contractor or Client, because none of them holds
report.view.
The curation tier – manage, share, schedule and export – is Owner and Admin only out of the box. A workspace can move any of them onto a custom role. See /team/custom-roles.
Finance holds
data.export, which is the workspace-wide bulk export, not report export. They are different rights. See /data/export-your-data.The cost and rate firewall
This is the rule that matters most. A report never shows cost, revenue or margin to someone whose role may not see them – no matter what the report asks for. The firewall is enforced on the server, on every path: the screen, the drill-down, the export, the print view and the scheduled email. There is no arrangement of a report, no share link, and no export format that gets around it.The gated figures
Cost and billing are honoured independently. Someone who can see billing rates but not cost sees Revenue and not Labor cost. Someone with the reverse sees Labor cost and not Revenue.
Why profit needs both
Profit is revenue minus cost. Someone who could see profit next to cost could subtract one from the other and reconstruct the revenue figure they were not allowed to see. Margin is the same problem in reverse – revenue is profit divided by margin. Requiring both capabilities closes that gap. It is the one place two permissions are demanded together.What you actually see
Roster fields
Group, Manager, Job title and Employment type are gated on roster access. A role that cannot read the roster cannot group or filter by them either. This stops a report becoming a side door onto roster information the team page already hides from that person.Source gates
Two sources need a capability beyondreport.view:
The other six – Time entries, Projects, Tasks, Timesheets, Time off and Timecard – need only
report.view. They still narrow which rows you see, based on your scope.
Supervision scope
A capability says whether you may. Scope says for whom. A manager withtime.viewOthers still only sees the people their scope reaches. A report folds only over those people, so a total covers your reach, not the whole workspace.
When your scope is narrower than the roster, a note sits above the table:
Covering 4 of 12 members – your role only sees the people you supervise.The note only appears when it matters. If you see everybody, there is nothing to say. See /concepts/supervision-scope.
Drill-down
Clicking a subtotal opens the records behind it, and the same three checks apply again:- Rows – you see your own records plus those of people in your scope.
- Fields – billing and cost rates on each record only appear if you may see them.
- Hidden records – anything out of reach is counted, never shown: “N more entries aren’t shown because you don’t have access to them.”
Exports and schedules
A schedule also stops sending if its creator loses
report.view – through a role change or leaving the workspace. Nothing is sent, and no error reaches the recipients.
report.export never implies cost access. Someone who can export but cannot see cost downloads a file with no cost columns.
Example
Northwind Studio’s shared Unbilled work report asks for Billable time, Uninvoiced time and Revenue.
Sarah’s totals also fold only over her own time, so her copy shows a coverage note.
Changing what someone can do
1
Decide capability or scope
“They cannot open Reports” is a capability problem. “They see only some people” is a scope problem.
2
Open the role
Go to Settings → Roles and open the role.
3
Grant the capability
Tick the report capability you need, or the cost or billing capability.
4
Or set the scope
Change the role’s supervision scope to widen who its holders can see.
5
Save
The change is live. Capabilities are checked fresh on every action.
Plans
Permissions and plans are separate gates, and both must pass:
The Reports app itself is on every plan and never paywalled. See /concepts/plans-and-features.
Common questions
Can a report ever leak a number I am not allowed to see?
Can a report ever leak a number I am not allowed to see?
No. The firewall runs on the server on every path – screen, drill-down, export, print and scheduled email. A gated value never reaches your browser.
Why can Finance not open Reports?
Why can Finance not open Reports?
Finance holds no report capability by default. It owns the money surface – invoices, payments and the bulk data export – not the reporting surface. Grant
report.view on a custom role if you need it.Why does my colleague's export have more columns?
Why does my colleague's export have more columns?
Their role can see cost or billing figures that yours cannot. The file mirrors what each person may see.
I own this report – why can I not edit it?
I own this report – why can I not edit it?
Ownership alone is not enough. A personal report needs ownership plus
report.edit. A shared report needs report.manage regardless of who made it.Can I give someone export access without cost access?
Can I give someone export access without cost access?
Yes, and it is a good default.
report.export never implies cost visibility – their file has no cost columns.Does hiding a column change the totals?
Does hiding a column change the totals?
No. Totals are calculated over the whole filtered set. A column you cannot see is not subtracted from anything; it is just not shown to you.
Troubleshooting
Related guides
Roles and capabilities
The seven roles and every capability.
Supervision scope
Which people your reports cover.
Cost rates
What cost visibility actually exposes.
Metrics reference
Which figures carry which gate.
Share a report
Publishing without widening access.
Plans and features
What Free covers and what Pro adds.