Docs

Roles and permissions

Every person in a WorkOSync company has one of eight roles. A role decides which modules appear in the sidebar and which routes the person can open, so salaries stay with HR, the books with finance and the pipeline with sales. Owners and Administrators can tailor any role from Users & Access.

The eight roles

RoleDescribed asTypical person
OwnerFull access to everythingThe founder or managing director; the account that created the workspace.
AdministratorFull access (except billing owner actions)A trusted deputy or operations head.
AccountantInvoices, payments, accounting & reportsFinance staff or an external bookkeeper.
HR ManagerPeople, timesheets, leave & payrollWhoever runs payroll and the WPS file.
SalesLeads, customers, quotes & ordersAccount managers and the sales desk.
Project ManagerProjects, tasks & timesheetsDelivery leads and site managers.
StaffAssigned tasks, timesheets & toolsEveryone else on the team.
ClientTheir own projects, invoices & estimatesA customer given a login to the portal.

Module matrix

The default access for each role. A tick means the module is in that role's sidebar and its routes open; a blank means it is hidden and redirected. Client is not shown because it uses the portal instead of the module sidebar.

ModuleOwnerAdministratorAccountantHR ManagerSalesProject ManagerStaff
Daily Brief✓✓✓✓✓✓✓
Global Inbox✓✓··✓·✓
Executive Dashboard✓✓·····
Ask AI✓✓·····
CRM & Leads✓✓··✓··
Customers✓✓✓·✓✓·
Suppliers✓✓✓····
Quotations✓✓✓·✓··
Sales & Orders✓✓··✓··
Invoicing✓✓✓·✓··
Contracts✓✓✓·✓··
Payments✓✓✓····
Open Invoices✓✓✓····
Accounting✓✓✓····
Items & Services✓✓✓····
Inventory✓✓·····
Projects✓✓···✓·
Task Board✓✓·✓·✓✓
Timesheets✓✓·✓·✓✓
HR & Payroll✓✓·✓···
Manufacturing✓✓·····
Assets✓✓·····
Chat & Groups✓✓···✓✓
Meetings✓✓··✓✓·
Approvals✓✓·✓···
UAE Compliance✓✓·✓···
Notes✓✓·✓·✓✓
Reminders✓✓·✓✓✓✓
Password Vault✓✓·····
Reports✓✓✓····
Users & Access✓✓·····
Audit Logs✓✓·····
Settings✓✓·····

Executive Dashboard and Ask AI are reserved for Owner and Administrator by default because they expose company-wide figures. My profile is open to everyone regardless of role.

Customising a role

The Users and access page with a card per role and module checkboxes
Users & access: every role has a card. Owner and Administrator are fixed at full access; the other five are editable.
  1. Open Users & Access

    It is in the System group of the sidebar, or under Users & access in your account menu.

  2. Find the role card

    Each editable card shows an N modules badge and a checkbox for every module, grouped the same way as the sidebar.

  3. Tick or untick modules

    Changes apply immediately to the sidebar and the route guard for anyone using that role.

  4. Reset if needed

    Reset to default becomes available once a role differs from the defaults above.

The Users table below the cards lists each person with their team, company and a role selector, so re-assigning someone is a single change.

How access is enforced

  • The sidebar only renders the groups and modules the active role may open.
  • Typing a disallowed URL redirects to the Daily Brief; a Client typing any non-portal URL is returned to the portal.
  • Quick create and search still list every action, but the page they open is subject to the same guard.
  • The Platform Console is separate: it is gated server-side to superadmins, independent of company roles. See Platform Console.

Previewing a role

Open your account menu and pick a role under Log in as (demo). The sidebar shrinks to that role's modules and a Viewing as banner appears until you switch back to Owner. This is the quickest way to check what a new hire will see before you send the invite.

The account menu with the Log in as role list
The role switcher in the account menu.

The client portal

A Client role never sees the company workspace. Its sidebar has five entries and every page is scoped to that customer's own records.

The client portal home with open invoices, total due, active projects and estimates
The portal home: a welcome, four KPIs and recent invoices and estimates for that customer only.
Portal pageShows
Client PortalOpen invoices, total due, active projects, estimates for review, recent invoices and estimates, and a contact card for the account manager.
My ProjectsProjects being delivered for the client with status, progress and budget.
My InvoicesEvery invoice with date, due, amount, outstanding and status, plus View / Pay which opens the hosted pay page.
My EstimatesQuotations awaiting review with Review & sign, which opens the online acceptance page.
StatementA running statement of account with a Print / Export button.
The client statement of account with debit, credit and running balance
The client statement: invoices as debits, payments as credits and a running balance with a closing figure.

Superadmin

Superadmin is not a company role but a platform flag. It is decided by the server from the signed-in account and unlocks the Platform Console, where another superadmin can grant or revoke it with the toggle in the Users section. A superadmin still uses a normal company role inside any workspace.

Sessions and roles

Your login session carries your role from the server. The Log in as switcher is a preview tool for Owners and Administrators; it does not change the session another person holds.