Skip to content

Account and access

Roles, seats, and permissions.

Access has four layers: your seat class, a separate role in each app, any record-level role or grant, and the current record state. Passing one layer never skips the next.

Roles are assigned separately for each business. Being a Bill admin in Acme does not make you a Bill admin in GNA, and being a Hive admin does not grant Pact or Tabs access. Connected links and Wren follow the same intersection of permissions.

Seat class comes first

Full seat

What it enables
Can receive any role supported by an enabled app and is intended for people who operate, approve, manage, or configure the business.
Important limits
The seat class is only a ceiling. The person's app role and record-level access still decide what they can see and change.

Light seat

What it enables
Assigned work and self-service surfaces. Current light grants are Work Member, Tabs Employee, Crew Employee, Loop Agent, Ties Viewer, Hive Cashier or Technician, Ride Driver, and Auto Technician.
Important limits
No light app role is currently available for Bill, Pact, RSVP, or Rent. Light users cannot be granted an admin, finance, or configuration role.

External actor

What it enables
Uses a purpose-specific portal, guest, or token flow, such as a Rent occupant, Ride customer, Pact signer, public booker, or Work project guest.
Important limits
Not an employee seat. The portal, link, token, or guest membership permits only its named external purpose. Legacy Rent Tenant and Ride Customer labels describe these identities, not staff jobs.

A new full-seat invite currently receives the tenant-admin default role in each subscribed app. Review those app roles after inviting someone and narrow them to the person’s actual job. A new light seat receives only the default self-service roles; in Hive that default is Cashier, which an admin can change to Technician.

How role inheritance works

Owner

What it enables
The target top tier for people ultimately responsible for one business. On migrated app surfaces it includes the Admin and Member baseline.
Important limits
Not a platform super-admin, cross-business, or cross-app grant. Several legacy app gates are still migrating; use the app matrix below before assigning Owner.

Admin

What it enables
Includes the app's standard operational baseline plus that app's settings and management controls.
Important limits
Does not inherit another app's role. Some private or sensitive records still require a matching object grant or field policy.

Member

What it enables
The app's standard authenticated work for records assigned or visible to that person.
Important limits
Does not inherit admin settings, exports, approvals, or sensitive fields unless the app grants them separately.

Specialist

What it enables
A member-level job role such as Hive Cashier, Hive Technician, or Loop Agent, with a deliberately focused surface.
Important limits
Specialist does not mean admin. Access outside that job remains closed unless another explicit grant applies.

hive: shop-floor roles

Hive also applies the business's enabled capabilities, so a role does not make a disabled rental, repair, or POS surface appear.

Owner / Admin / Super admin

What it enables
Full Hive operation: catalog and inventory administration, customers, proposals, purchasing, vendors, reports, settings, consignment, repair, sales, trials, rentals, web orders, shipping, discounts, and one-sale tax exemptions.
Important limits
Limited to this business and its enabled Hive capabilities. Financial or agreement context from another app still requires access to that app.

Cashier

What it enables
Counter work: dashboard, catalog lookup, scan, customers, manual stock adjustments, register and sales, charges and payment links, trials, rentals, web orders, shipping, and the shared due-date queue.
Important limits
No repair bench, inventory administration, procurement, vendors, reports, or settings. Cannot authorize discounts or one-sale tax exemptions.

Technician

What it enables
Bench work: dashboard, catalog lookup, scan, manual stock adjustments, repair tickets, and the shared due-date queue.
Important limits
No counter sales or payments, customers, trials, rentals, web orders, shipping, procurement, reports, or settings. Cannot authorize discounts or tax exemptions.

Member

What it enables
Basic inventory support: dashboard, catalog lookup, scan, customers, and manual stock adjustments.
Important limits
No register, payments, repair bench, trials, rentals, web orders, procurement administration, reports, settings, discounts, or tax overrides.

work: tenant roles and project roles

Admin / Super admin

What it enables
Standard Work access plus tenant workflows, forms, integrations, reports, client sign-offs, audit activity, and administrative settings. Tenant admins can resolve tenant-local visibility while operating the workspace.
Important limits
The bypass is tenant-local. Cross-business reads and writes still require membership in the other business, and every write names one business.

Owner (migration in progress)

What it enables
Owner-level project visibility and administration on Work surfaces that use the standardized suite policy.
Important limits
Several older Work settings and administration gates still check Admin or Super admin literally. Use Admin for a person who needs dependable tenant-wide administration until that migration is complete.

Member

What it enables
Daily focus, planner, tasks, boards, projects, teams, labels, schedules, and personal settings, subject to assignment and project or team visibility.
Important limits
Does not see every private project. Access needs assignment or watch access, explicit project membership, qualifying team membership, or tenant-public visibility.

Accounting

What it enables
Work finance and review surfaces for each business where the person has the Work accounting grant, including scoped receivables actions such as sending invoices and recording offline payments.
Important limits
Not a general Work admin. Invoice creation and voiding and bank-link administration remain admin-only, and project visibility rules still apply.

Project / Team Owner, Admin, or Member

What it enables
Controls management inside that exact project or team. Owners and admins manage its membership and structure; members participate in work they can see.
Important limits
An object role does not grant tenant-admin rights or access to another project or team.

bill: receivables and billing

Owner / Admin / Super admin

What it enables
Full billing workspace plus settings and admin-only proposal and invoice lifecycle controls, including draft editing and send, void, or delete controls when state permits.
Important limits
Paid, voided, or otherwise locked records have additional state rules. A link from Work or Hive supplies context, not authority.

Accounting

What it enables
Billing workspace and tenant billing export for day-to-day financial review.
Important limits
Does not inherit admin settings or admin-only proposal and invoice lifecycle controls merely because it can read financial data.

Member

What it enables
Standard billing workspace and time-entry participation available to an authenticated Bill user.
Important limits
No admin settings or admin-only proposal and invoice mutation controls. Record state, engagement collaboration, and assignment can narrow actions further.

pact: documents and signatures

Admin

What it enables
All tenant documents, including restricted documents, plus template administration, approvals, settings, packets, and tenant export.
Important limits
Signer identity and signing authority still come from the signing ceremony. A connected Work or Hive link does not bypass Pact access.

Owner (migration in progress)

What it enables
All tenant documents, including restricted documents, and ordinary document, template, packet, and contact work.
Important limits
Pact's legacy settings navigation and export gate still require Admin (or a previously stored Super admin). Use Admin for full tenant administration until those gates migrate.

Member

What it enables
Open tenant-visible documents, restricted documents they created, and restricted documents with an active user or email grant. Members can manage document work they are authorized to open.
Important limits
Cannot see every restricted document or use tenant-admin settings, approval, and export controls.

Legacy Super admin

What it enables
Previously stored Pact Super admin rows retain the current Admin-level settings and export gates.
Important limits
Not a role a tenant admin can newly assign in AUTH.

Token signer

What it enables
Review and sign the specific document ceremony addressed by the signing link.
Important limits
Not an app member and cannot browse the business's Pact workspace or other documents.

loop: internal and external communication

Admin

What it enables
External inbox and sending, contacts, templates, voice when enabled, internal chat, messaging and provider settings, and tenant export.
Important limits
Message consent, channel availability, exact thread access, and space membership still apply.

Owner (migration in progress)

What it enables
Customer inbox and sending, contacts, templates, voice when enabled, internal chat, and chat administration.
Important limits
Several older provider, credit, event-operations, and export gates still check Admin literally. Use Admin when those controls are required.

Agent

What it enables
Operate the customer inbox, send messages, manage contacts and templates, use voice when enabled, and participate in internal chat.
Important limits
No tenant export or provider administration. A light-seat Agent cannot create or curate space context even though it can use existing communication and chat surfaces.

Viewer

What it enables
Read-only review of customer threads where the Loop review surface is available.
Important limits
Cannot compose customer messages, operate the queue, use internal chat, or change messaging configuration.

Member

What it enables
Internal direct messages and existing chat-space participation.
Important limits
No customer-message sending. Some full-seat navigation still exposes the external queue, but its write actions require Agent, Owner, or Admin.

Space Owner / Admin / Member

What it enables
Controls one internal space: owners and admins manage its membership and settings; members participate.
Important limits
A space role does not grant Loop tenant administration or external-inbox authority.

ties: customer relationships

Admin / Super admin

What it enables
Full CRM operation plus custom fields, settings, snapshots, administrative automation, and tenant export.
Important limits
Connected Work, Hive, and Loop history is still filtered by the viewer's permission in each owning app.

Owner (migration in progress)

What it enables
Normal CRM operation across customers, contacts, jobs, leads, campaigns, tags, and relationship activity.
Important limits
Older custom-field, settings, snapshot, automation, and export gates still require Admin. Use Admin for full CRM administration.

Member / Staff / Agent

What it enables
Create and update customers, contacts, jobs, leads, campaigns, tags, and normal relationship activity.
Important limits
No tenant-admin settings, custom-field administration, snapshots, or export.

Viewer

What it enables
Read-only customer, reporting, and conversation-history access. Viewing a conversation or marking a notification read may advance only that viewer's personal read state. This is the Ties role available to a light seat.
Important limits
Cannot create, update, delete, send, merge, convert, save views, or change CRM configuration. Unknown roles also fail the same server-side write checks.

tabs: expenses and accounts payable

Admin

What it enables
All expenses and vendor bills, approvals, payment and reconciliation work, vendors, reports, settings, exports, and admin-only void or override controls.
Important limits
Approval separation-of-duties and document lifecycle rules can still prevent an action on the admin's own submission.

Owner (migration in progress)

What it enables
The target top-level Tabs role is accepted by AUTH.
Important limits
Tabs navigation and privilege predicates still use the legacy Admin label, so Owner does not yet provide dependable admin access. Use Admin until migration is complete.

Accounting

What it enables
All tenant expenses and bills, approvals, payment scheduling and mark-paid work, reconciliation, vendors, reports, export, and intake.
Important limits
No tenant settings or admin-only void and override controls. Self-approval is allowed only under configured fallback rules.

Manager

What it enables
Enter spend, see operational dashboard, vendors, and reports, and approve other people's expenses and bills in scope.
Important limits
Cannot pay or reconcile bills, change Tabs settings, use admin overrides, or normally approve their own submission. The main expense list remains limited to their own spend.

Employee

What it enables
Enter, import, submit, and follow their own expenses and vendor bills; use receipt intake and assigned cards.
Important limits
Cannot see everyone else's spend, approve, pay, reconcile, report across the tenant, or change settings.

Member (migration in progress)

What it enables
The target standard self-service role is accepted by AUTH.
Important limits
Tabs navigation and several scope checks still expect Employee. Use Employee for dependable self-service until migration is complete.

crew: people and sensitive fields

Tenant admin / tenant-scoped Super admin

What it enables
Tenant roster, hiring, offers, onboarding, employee records, time and time-off administration, documents, reports, imports, data, and HR settings.
Important limits
Only inside the active business. A tenant-scoped Super admin is normalized to Tenant admin; platform-wide support authority is separate.

Owner (migration in progress)

What it enables
The target top-level Crew role is accepted by AUTH.
Important limits
Crew's HR administration checks still use Tenant admin. Use Tenant admin for dependable HR administration until migration is complete.

Admin (migration in progress)

What it enables
The target Crew admin label is accepted by AUTH.
Important limits
Crew's HR administration checks still use Tenant admin. Use Tenant admin until migration is complete.

Read-only admin

What it enables
Broad HR reporting and employee visibility, including sensitive fields, inside the active business without ordinary employee-edit authority.
Important limits
No ordinary employee edits or HR write actions, and no access to another business. An active business context is required; a legacy assignment without one is denied. The role is planned to become Admin plus a tenant-scoped viewer modifier.

Manager

What it enables
Own HR self-service plus direct-report directory, documents, time, time-off review, positions, and team work. Direct-report compensation and date of birth use hold-to-reveal.
Important limits
Limited to self and the management chain. Direct-report bank and SSN fields stay hidden; no tenant HR settings, offers, onboarding administration, imports, or exports.

Employee

What it enables
Own profile, tasks, time, time off, pay preview, and employee documents.
Important limits
Cannot browse or edit other employees or access tenant HR administration.

Member (migration in progress)

What it enables
The target Crew self-service role is accepted by AUTH.
Important limits
Crew's self and manager visibility checks still expect Employee or Manager. Use Employee for dependable self-service until migration is complete.

Connected Crew panels and Wren never expose an individual pay rate. Even for a compensation-authorized role, aggregate labor cost and covered hours are withheld when fewer than three distinct employees contribute.

rent: property operations and occupant access

Owner / Property manager

What it enables
Full property operation: properties, units, leases, occupants, payments, expenses, vendors, work orders, documents, reports, and settings.
Important limits
Tenant-scoped to the active business. Public signing links and occupant access remain limited to their named purpose.

Tenant (occupant)

What it enables
Own occupant portal for lease information, documents, payments and payment methods, insurance, co-tenants, and maintenance requests.
Important limits
Requires a linked Occupant record and cannot enter the property-management workspace or another occupant's portal.

Admin (not currently usable)

What it enables
AUTH still lists this target label during role standardization.
Important limits
Rent's remote role validator currently rejects it. Assign Property manager for operational administration.

Member (not currently usable)

What it enables
AUTH still lists this target label during role standardization.
Important limits
Rent's remote role validator currently rejects it. Occupant access uses Tenant plus a linked Occupant record; there is no general member workspace today.

ride: fleet, dispatch, and driver roles

Admin / Staff

What it enables
Broad fleet and dispatch operation. Both can enter the management and dispatch surfaces; Admin and legacy Staff also pass current billing and fleet-administration gates.
Important limits
Still tenant-scoped. Some especially sensitive development and integration controls check Admin literally.

Dispatcher

What it enables
Dispatch board, reservation and recurring-trip operations, calendar, live map, incidents, customer messaging, and trip coordination.
Important limits
Can enter the management layout but does not pass Admin or Staff-only billing, vehicle-financial, and certain fleet-configuration gates.

Driver

What it enables
Driver-specific schedule, assigned trip detail and status updates, driver messages, and profile.
Important limits
No dispatch board or fleet administration. This is the Ride role available to a light seat.

Customer (legacy identity label)

What it enables
Represents an older signed-in customer identity.
Important limits
Current customer booking, trip lookup, and live status are primarily public token or link flows, not an internal app seat. Do not use Customer for an employee.

Owner (migration in progress)

What it enables
The target top-level Ride role is accepted by AUTH.
Important limits
Ride route gates still use Admin, Staff, Dispatcher, and Driver. Use Admin for dependable top-level access until migration is complete.

Member (migration in progress)

What it enables
The target standard Ride role is accepted by AUTH.
Important limits
Current operator layouts do not define a general Member surface. Choose Staff, Dispatcher, or Driver according to the person's job.

auto: repair-shop roles

Admin

What it enables
Full repair-shop operation plus tax and numbering settings, operational pricing configuration, refunds, payments, and tenant export.
Important limits
Tenant-scoped. Record state and payment-provider status can still prevent an action.

Owner (migration in progress)

What it enables
Normal authenticated shop-record access.
Important limits
Auto's admin and manager predicates still check legacy role labels, so Owner does not currently inherit tax, export, pricing, refund, or payment authority. Use Admin for full administration.

Auto manager

What it enables
Normal shop operation plus labor rates, parts markup, canned jobs, customer sources, parts administration, refunds, and taking payments.
Important limits
No Admin-only tax and numbering settings or tenant export.

Service advisor

What it enables
Front-desk customer, vehicle, scheduling, estimate, repair-order, invoicing, and payment work.
Important limits
Cannot issue refunds or change manager pricing, parts, tax, or export settings.

Technician

What it enables
Technician dashboard plus repair-order, inspection, parts, and lookup work. Light seats receive a narrowed repair, parts, and lookup navigation.
Important limits
Cannot take payments, issue refunds, or change manager and Admin settings. Some full-seat shop pages are not yet role-trimmed.

Member

What it enables
Standard authenticated shop records and operations.
Important limits
No payment, refund, manager-pricing, tax, or export authority. Unlike Technician, Member is a full-seat role and does not receive the light-seat navigation trim.

rsvp: bookable resources and appointments

Admin

What it enables
Create and manage people, room, and equipment resources; booking links and availability; pending booking decisions; scheduling defaults; calendar and meeting integrations; and tenant export.
Important limits
Tenant-scoped. Public customers can only use the booking or cancellation token they receive.

Owner (migration in progress)

What it enables
Tenant schedule review and management of booking links, availability, and pending requests for resources owned by that user.
Important limits
RSVP's legacy admin and export predicates still require Admin (or a previously stored Super admin). Use Admin for tenant-wide resource creation and settings.

Member

What it enables
Review the tenant schedule and manage booking links, availability, and pending requests for resources assigned to that user.
Important limits
Cannot create tenant resources, change scheduling defaults, administer another person's resource, or export the tenant.

Legacy Super admin

What it enables
Previously stored RSVP Super admin rows retain the current Admin-level scheduling and export gates.
Important limits
Not a role a tenant admin can newly assign in AUTH.

Public booker

What it enables
Use one public booking link and the resulting cancellation or calendar links.
Important limits
Not a seat or app member and cannot browse the business schedule.

tsks: legacy task subscription

TSKS was merged into Work. It remains in AUTH for existing subscriptions and audit history, but new businesses cannot subscribe to it.

Owner / Admin

What it enables
Legacy tenant task access now opens Work's task surfaces and supplies the tenant-admin task role when no Work role is present.
Important limits
No separate TSKS app remains. Project and task visibility, membership, assignment, and tenant boundaries still apply in Work.

Member

What it enables
Create and update tasks in businesses where the person has active membership and a Work or legacy TSKS Member role, subject to task and project visibility.
Important limits
Cannot use tenant-admin-only project or team controls. New access should normally be assigned through Work rather than TSKS.

Connected context never widens a role

A Hive order can point to a Bill invoice, Pact agreement, Tabs cost, Crew time entry, Loop issue, and Ties customer. Each app still checks the role and exact record before returning its part. If one source is outside your permission, that source is withheld rather than replaced with a nearby record.

Wren receives that same authorized intersection. Read visibility does not give Wren action authority; a supported write is confirmed and authorized again by its owning app when it runs. See How the apps connect and Working across multiple businesses for the graph and tenant boundaries.