Account and access
Roles, seats, and permissions.
Access has four layers: your seat class, a separate role in each app, any record-level role or grant, and the current record state. Passing one layer never skips the next.
Roles are assigned separately for each business. Being a Bill admin in Acme does not make you a Bill admin in GNA, and being a Hive admin does not grant Pact or Tabs access. Connected links and Wren follow the same intersection of permissions.
Seat class comes first
Full seat
- What it enables
- Can receive any role supported by an enabled app and is intended for people who operate, approve, manage, or configure the business.
- Important limits
- The seat class is only a ceiling. The person's app role and record-level access still decide what they can see and change.
Light seat
- What it enables
- Assigned work and self-service surfaces. Current light grants are Work Member, Tabs Employee, Crew Employee, Loop Agent, Ties Viewer, Hive Cashier or Technician, Ride Driver, and Auto Technician.
- Important limits
- No light app role is currently available for Bill, Pact, RSVP, or Rent. Light users cannot be granted an admin, finance, or configuration role.
External actor
- What it enables
- Uses a purpose-specific portal, guest, or token flow, such as a Rent occupant, Ride customer, Pact signer, public booker, or Work project guest.
- Important limits
- Not an employee seat. The portal, link, token, or guest membership permits only its named external purpose. Legacy Rent Tenant and Ride Customer labels describe these identities, not staff jobs.
| Role or class | What it enables | Important limits |
|---|---|---|
| Full seat | Can receive any role supported by an enabled app and is intended for people who operate, approve, manage, or configure the business. | The seat class is only a ceiling. The person's app role and record-level access still decide what they can see and change. |
| Light seat | Assigned work and self-service surfaces. Current light grants are Work Member, Tabs Employee, Crew Employee, Loop Agent, Ties Viewer, Hive Cashier or Technician, Ride Driver, and Auto Technician. | No light app role is currently available for Bill, Pact, RSVP, or Rent. Light users cannot be granted an admin, finance, or configuration role. |
| External actor | Uses a purpose-specific portal, guest, or token flow, such as a Rent occupant, Ride customer, Pact signer, public booker, or Work project guest. | Not an employee seat. The portal, link, token, or guest membership permits only its named external purpose. Legacy Rent Tenant and Ride Customer labels describe these identities, not staff jobs. |
A new full-seat invite currently receives the tenant-admin default role in each subscribed app. Review those app roles after inviting someone and narrow them to the person’s actual job. A new light seat receives only the default self-service roles; in Hive that default is Cashier, which an admin can change to Technician.
How role inheritance works
Owner
- What it enables
- The target top tier for people ultimately responsible for one business. On migrated app surfaces it includes the Admin and Member baseline.
- Important limits
- Not a platform super-admin, cross-business, or cross-app grant. Several legacy app gates are still migrating; use the app matrix below before assigning Owner.
Admin
- What it enables
- Includes the app's standard operational baseline plus that app's settings and management controls.
- Important limits
- Does not inherit another app's role. Some private or sensitive records still require a matching object grant or field policy.
Member
- What it enables
- The app's standard authenticated work for records assigned or visible to that person.
- Important limits
- Does not inherit admin settings, exports, approvals, or sensitive fields unless the app grants them separately.
Specialist
- What it enables
- A member-level job role such as Hive Cashier, Hive Technician, or Loop Agent, with a deliberately focused surface.
- Important limits
- Specialist does not mean admin. Access outside that job remains closed unless another explicit grant applies.
| Role or class | What it enables | Important limits |
|---|---|---|
| Owner | The target top tier for people ultimately responsible for one business. On migrated app surfaces it includes the Admin and Member baseline. | Not a platform super-admin, cross-business, or cross-app grant. Several legacy app gates are still migrating; use the app matrix below before assigning Owner. |
| Admin | Includes the app's standard operational baseline plus that app's settings and management controls. | Does not inherit another app's role. Some private or sensitive records still require a matching object grant or field policy. |
| Member | The app's standard authenticated work for records assigned or visible to that person. | Does not inherit admin settings, exports, approvals, or sensitive fields unless the app grants them separately. |
| Specialist | A member-level job role such as Hive Cashier, Hive Technician, or Loop Agent, with a deliberately focused surface. | Specialist does not mean admin. Access outside that job remains closed unless another explicit grant applies. |
hive: shop-floor roles
Hive also applies the business's enabled capabilities, so a role does not make a disabled rental, repair, or POS surface appear.
Owner / Admin / Super admin
- What it enables
- Full Hive operation: catalog and inventory administration, customers, proposals, purchasing, vendors, reports, settings, consignment, repair, sales, trials, rentals, web orders, shipping, discounts, and one-sale tax exemptions.
- Important limits
- Limited to this business and its enabled Hive capabilities. Financial or agreement context from another app still requires access to that app.
Cashier
- What it enables
- Counter work: dashboard, catalog lookup, scan, customers, manual stock adjustments, register and sales, charges and payment links, trials, rentals, web orders, shipping, and the shared due-date queue.
- Important limits
- No repair bench, inventory administration, procurement, vendors, reports, or settings. Cannot authorize discounts or one-sale tax exemptions.
Technician
- What it enables
- Bench work: dashboard, catalog lookup, scan, manual stock adjustments, repair tickets, and the shared due-date queue.
- Important limits
- No counter sales or payments, customers, trials, rentals, web orders, shipping, procurement, reports, or settings. Cannot authorize discounts or tax exemptions.
Member
- What it enables
- Basic inventory support: dashboard, catalog lookup, scan, customers, and manual stock adjustments.
- Important limits
- No register, payments, repair bench, trials, rentals, web orders, procurement administration, reports, settings, discounts, or tax overrides.
| Role or class | What it enables | Important limits |
|---|---|---|
| Owner / Admin / Super admin | Full Hive operation: catalog and inventory administration, customers, proposals, purchasing, vendors, reports, settings, consignment, repair, sales, trials, rentals, web orders, shipping, discounts, and one-sale tax exemptions. | Limited to this business and its enabled Hive capabilities. Financial or agreement context from another app still requires access to that app. |
| Cashier | Counter work: dashboard, catalog lookup, scan, customers, manual stock adjustments, register and sales, charges and payment links, trials, rentals, web orders, shipping, and the shared due-date queue. | No repair bench, inventory administration, procurement, vendors, reports, or settings. Cannot authorize discounts or one-sale tax exemptions. |
| Technician | Bench work: dashboard, catalog lookup, scan, manual stock adjustments, repair tickets, and the shared due-date queue. | No counter sales or payments, customers, trials, rentals, web orders, shipping, procurement, reports, or settings. Cannot authorize discounts or tax exemptions. |
| Member | Basic inventory support: dashboard, catalog lookup, scan, customers, and manual stock adjustments. | No register, payments, repair bench, trials, rentals, web orders, procurement administration, reports, settings, discounts, or tax overrides. |
work: tenant roles and project roles
Admin / Super admin
- What it enables
- Standard Work access plus tenant workflows, forms, integrations, reports, client sign-offs, audit activity, and administrative settings. Tenant admins can resolve tenant-local visibility while operating the workspace.
- Important limits
- The bypass is tenant-local. Cross-business reads and writes still require membership in the other business, and every write names one business.
Owner (migration in progress)
- What it enables
- Owner-level project visibility and administration on Work surfaces that use the standardized suite policy.
- Important limits
- Several older Work settings and administration gates still check Admin or Super admin literally. Use Admin for a person who needs dependable tenant-wide administration until that migration is complete.
Member
- What it enables
- Daily focus, planner, tasks, boards, projects, teams, labels, schedules, and personal settings, subject to assignment and project or team visibility.
- Important limits
- Does not see every private project. Access needs assignment or watch access, explicit project membership, qualifying team membership, or tenant-public visibility.
Accounting
- What it enables
- Work finance and review surfaces for each business where the person has the Work accounting grant, including scoped receivables actions such as sending invoices and recording offline payments.
- Important limits
- Not a general Work admin. Invoice creation and voiding and bank-link administration remain admin-only, and project visibility rules still apply.
Project / Team Owner, Admin, or Member
- What it enables
- Controls management inside that exact project or team. Owners and admins manage its membership and structure; members participate in work they can see.
- Important limits
- An object role does not grant tenant-admin rights or access to another project or team.
| Role or class | What it enables | Important limits |
|---|---|---|
| Admin / Super admin | Standard Work access plus tenant workflows, forms, integrations, reports, client sign-offs, audit activity, and administrative settings. Tenant admins can resolve tenant-local visibility while operating the workspace. | The bypass is tenant-local. Cross-business reads and writes still require membership in the other business, and every write names one business. |
| Owner (migration in progress) | Owner-level project visibility and administration on Work surfaces that use the standardized suite policy. | Several older Work settings and administration gates still check Admin or Super admin literally. Use Admin for a person who needs dependable tenant-wide administration until that migration is complete. |
| Member | Daily focus, planner, tasks, boards, projects, teams, labels, schedules, and personal settings, subject to assignment and project or team visibility. | Does not see every private project. Access needs assignment or watch access, explicit project membership, qualifying team membership, or tenant-public visibility. |
| Accounting | Work finance and review surfaces for each business where the person has the Work accounting grant, including scoped receivables actions such as sending invoices and recording offline payments. | Not a general Work admin. Invoice creation and voiding and bank-link administration remain admin-only, and project visibility rules still apply. |
| Project / Team Owner, Admin, or Member | Controls management inside that exact project or team. Owners and admins manage its membership and structure; members participate in work they can see. | An object role does not grant tenant-admin rights or access to another project or team. |
bill: receivables and billing
Owner / Admin / Super admin
- What it enables
- Full billing workspace plus settings and admin-only proposal and invoice lifecycle controls, including draft editing and send, void, or delete controls when state permits.
- Important limits
- Paid, voided, or otherwise locked records have additional state rules. A link from Work or Hive supplies context, not authority.
Accounting
- What it enables
- Billing workspace and tenant billing export for day-to-day financial review.
- Important limits
- Does not inherit admin settings or admin-only proposal and invoice lifecycle controls merely because it can read financial data.
Member
- What it enables
- Standard billing workspace and time-entry participation available to an authenticated Bill user.
- Important limits
- No admin settings or admin-only proposal and invoice mutation controls. Record state, engagement collaboration, and assignment can narrow actions further.
| Role or class | What it enables | Important limits |
|---|---|---|
| Owner / Admin / Super admin | Full billing workspace plus settings and admin-only proposal and invoice lifecycle controls, including draft editing and send, void, or delete controls when state permits. | Paid, voided, or otherwise locked records have additional state rules. A link from Work or Hive supplies context, not authority. |
| Accounting | Billing workspace and tenant billing export for day-to-day financial review. | Does not inherit admin settings or admin-only proposal and invoice lifecycle controls merely because it can read financial data. |
| Member | Standard billing workspace and time-entry participation available to an authenticated Bill user. | No admin settings or admin-only proposal and invoice mutation controls. Record state, engagement collaboration, and assignment can narrow actions further. |
pact: documents and signatures
Admin
- What it enables
- All tenant documents, including restricted documents, plus template administration, approvals, settings, packets, and tenant export.
- Important limits
- Signer identity and signing authority still come from the signing ceremony. A connected Work or Hive link does not bypass Pact access.
Owner (migration in progress)
- What it enables
- All tenant documents, including restricted documents, and ordinary document, template, packet, and contact work.
- Important limits
- Pact's legacy settings navigation and export gate still require Admin (or a previously stored Super admin). Use Admin for full tenant administration until those gates migrate.
Member
- What it enables
- Open tenant-visible documents, restricted documents they created, and restricted documents with an active user or email grant. Members can manage document work they are authorized to open.
- Important limits
- Cannot see every restricted document or use tenant-admin settings, approval, and export controls.
Legacy Super admin
- What it enables
- Previously stored Pact Super admin rows retain the current Admin-level settings and export gates.
- Important limits
- Not a role a tenant admin can newly assign in AUTH.
Token signer
- What it enables
- Review and sign the specific document ceremony addressed by the signing link.
- Important limits
- Not an app member and cannot browse the business's Pact workspace or other documents.
| Role or class | What it enables | Important limits |
|---|---|---|
| Admin | All tenant documents, including restricted documents, plus template administration, approvals, settings, packets, and tenant export. | Signer identity and signing authority still come from the signing ceremony. A connected Work or Hive link does not bypass Pact access. |
| Owner (migration in progress) | All tenant documents, including restricted documents, and ordinary document, template, packet, and contact work. | Pact's legacy settings navigation and export gate still require Admin (or a previously stored Super admin). Use Admin for full tenant administration until those gates migrate. |
| Member | Open tenant-visible documents, restricted documents they created, and restricted documents with an active user or email grant. Members can manage document work they are authorized to open. | Cannot see every restricted document or use tenant-admin settings, approval, and export controls. |
| Legacy Super admin | Previously stored Pact Super admin rows retain the current Admin-level settings and export gates. | Not a role a tenant admin can newly assign in AUTH. |
| Token signer | Review and sign the specific document ceremony addressed by the signing link. | Not an app member and cannot browse the business's Pact workspace or other documents. |
loop: internal and external communication
Admin
- What it enables
- External inbox and sending, contacts, templates, voice when enabled, internal chat, messaging and provider settings, and tenant export.
- Important limits
- Message consent, channel availability, exact thread access, and space membership still apply.
Owner (migration in progress)
- What it enables
- Customer inbox and sending, contacts, templates, voice when enabled, internal chat, and chat administration.
- Important limits
- Several older provider, credit, event-operations, and export gates still check Admin literally. Use Admin when those controls are required.
Agent
- What it enables
- Operate the customer inbox, send messages, manage contacts and templates, use voice when enabled, and participate in internal chat.
- Important limits
- No tenant export or provider administration. A light-seat Agent cannot create or curate space context even though it can use existing communication and chat surfaces.
Viewer
- What it enables
- Read-only review of customer threads where the Loop review surface is available.
- Important limits
- Cannot compose customer messages, operate the queue, use internal chat, or change messaging configuration.
Member
- What it enables
- Internal direct messages and existing chat-space participation.
- Important limits
- No customer-message sending. Some full-seat navigation still exposes the external queue, but its write actions require Agent, Owner, or Admin.
Space Owner / Admin / Member
- What it enables
- Controls one internal space: owners and admins manage its membership and settings; members participate.
- Important limits
- A space role does not grant Loop tenant administration or external-inbox authority.
| Role or class | What it enables | Important limits |
|---|---|---|
| Admin | External inbox and sending, contacts, templates, voice when enabled, internal chat, messaging and provider settings, and tenant export. | Message consent, channel availability, exact thread access, and space membership still apply. |
| Owner (migration in progress) | Customer inbox and sending, contacts, templates, voice when enabled, internal chat, and chat administration. | Several older provider, credit, event-operations, and export gates still check Admin literally. Use Admin when those controls are required. |
| Agent | Operate the customer inbox, send messages, manage contacts and templates, use voice when enabled, and participate in internal chat. | No tenant export or provider administration. A light-seat Agent cannot create or curate space context even though it can use existing communication and chat surfaces. |
| Viewer | Read-only review of customer threads where the Loop review surface is available. | Cannot compose customer messages, operate the queue, use internal chat, or change messaging configuration. |
| Member | Internal direct messages and existing chat-space participation. | No customer-message sending. Some full-seat navigation still exposes the external queue, but its write actions require Agent, Owner, or Admin. |
| Space Owner / Admin / Member | Controls one internal space: owners and admins manage its membership and settings; members participate. | A space role does not grant Loop tenant administration or external-inbox authority. |
ties: customer relationships
Admin / Super admin
- What it enables
- Full CRM operation plus custom fields, settings, snapshots, administrative automation, and tenant export.
- Important limits
- Connected Work, Hive, and Loop history is still filtered by the viewer's permission in each owning app.
Owner (migration in progress)
- What it enables
- Normal CRM operation across customers, contacts, jobs, leads, campaigns, tags, and relationship activity.
- Important limits
- Older custom-field, settings, snapshot, automation, and export gates still require Admin. Use Admin for full CRM administration.
Member / Staff / Agent
- What it enables
- Create and update customers, contacts, jobs, leads, campaigns, tags, and normal relationship activity.
- Important limits
- No tenant-admin settings, custom-field administration, snapshots, or export.
Viewer
- What it enables
- Read-only customer, reporting, and conversation-history access. Viewing a conversation or marking a notification read may advance only that viewer's personal read state. This is the Ties role available to a light seat.
- Important limits
- Cannot create, update, delete, send, merge, convert, save views, or change CRM configuration. Unknown roles also fail the same server-side write checks.
| Role or class | What it enables | Important limits |
|---|---|---|
| Admin / Super admin | Full CRM operation plus custom fields, settings, snapshots, administrative automation, and tenant export. | Connected Work, Hive, and Loop history is still filtered by the viewer's permission in each owning app. |
| Owner (migration in progress) | Normal CRM operation across customers, contacts, jobs, leads, campaigns, tags, and relationship activity. | Older custom-field, settings, snapshot, automation, and export gates still require Admin. Use Admin for full CRM administration. |
| Member / Staff / Agent | Create and update customers, contacts, jobs, leads, campaigns, tags, and normal relationship activity. | No tenant-admin settings, custom-field administration, snapshots, or export. |
| Viewer | Read-only customer, reporting, and conversation-history access. Viewing a conversation or marking a notification read may advance only that viewer's personal read state. This is the Ties role available to a light seat. | Cannot create, update, delete, send, merge, convert, save views, or change CRM configuration. Unknown roles also fail the same server-side write checks. |
tabs: expenses and accounts payable
Admin
- What it enables
- All expenses and vendor bills, approvals, payment and reconciliation work, vendors, reports, settings, exports, and admin-only void or override controls.
- Important limits
- Approval separation-of-duties and document lifecycle rules can still prevent an action on the admin's own submission.
Owner (migration in progress)
- What it enables
- The target top-level Tabs role is accepted by AUTH.
- Important limits
- Tabs navigation and privilege predicates still use the legacy Admin label, so Owner does not yet provide dependable admin access. Use Admin until migration is complete.
Accounting
- What it enables
- All tenant expenses and bills, approvals, payment scheduling and mark-paid work, reconciliation, vendors, reports, export, and intake.
- Important limits
- No tenant settings or admin-only void and override controls. Self-approval is allowed only under configured fallback rules.
Manager
- What it enables
- Enter spend, see operational dashboard, vendors, and reports, and approve other people's expenses and bills in scope.
- Important limits
- Cannot pay or reconcile bills, change Tabs settings, use admin overrides, or normally approve their own submission. The main expense list remains limited to their own spend.
Employee
- What it enables
- Enter, import, submit, and follow their own expenses and vendor bills; use receipt intake and assigned cards.
- Important limits
- Cannot see everyone else's spend, approve, pay, reconcile, report across the tenant, or change settings.
Member (migration in progress)
- What it enables
- The target standard self-service role is accepted by AUTH.
- Important limits
- Tabs navigation and several scope checks still expect Employee. Use Employee for dependable self-service until migration is complete.
| Role or class | What it enables | Important limits |
|---|---|---|
| Admin | All expenses and vendor bills, approvals, payment and reconciliation work, vendors, reports, settings, exports, and admin-only void or override controls. | Approval separation-of-duties and document lifecycle rules can still prevent an action on the admin's own submission. |
| Owner (migration in progress) | The target top-level Tabs role is accepted by AUTH. | Tabs navigation and privilege predicates still use the legacy Admin label, so Owner does not yet provide dependable admin access. Use Admin until migration is complete. |
| Accounting | All tenant expenses and bills, approvals, payment scheduling and mark-paid work, reconciliation, vendors, reports, export, and intake. | No tenant settings or admin-only void and override controls. Self-approval is allowed only under configured fallback rules. |
| Manager | Enter spend, see operational dashboard, vendors, and reports, and approve other people's expenses and bills in scope. | Cannot pay or reconcile bills, change Tabs settings, use admin overrides, or normally approve their own submission. The main expense list remains limited to their own spend. |
| Employee | Enter, import, submit, and follow their own expenses and vendor bills; use receipt intake and assigned cards. | Cannot see everyone else's spend, approve, pay, reconcile, report across the tenant, or change settings. |
| Member (migration in progress) | The target standard self-service role is accepted by AUTH. | Tabs navigation and several scope checks still expect Employee. Use Employee for dependable self-service until migration is complete. |
crew: people and sensitive fields
Tenant admin / tenant-scoped Super admin
- What it enables
- Tenant roster, hiring, offers, onboarding, employee records, time and time-off administration, documents, reports, imports, data, and HR settings.
- Important limits
- Only inside the active business. A tenant-scoped Super admin is normalized to Tenant admin; platform-wide support authority is separate.
Owner (migration in progress)
- What it enables
- The target top-level Crew role is accepted by AUTH.
- Important limits
- Crew's HR administration checks still use Tenant admin. Use Tenant admin for dependable HR administration until migration is complete.
Admin (migration in progress)
- What it enables
- The target Crew admin label is accepted by AUTH.
- Important limits
- Crew's HR administration checks still use Tenant admin. Use Tenant admin until migration is complete.
Read-only admin
- What it enables
- Broad HR reporting and employee visibility, including sensitive fields, inside the active business without ordinary employee-edit authority.
- Important limits
- No ordinary employee edits or HR write actions, and no access to another business. An active business context is required; a legacy assignment without one is denied. The role is planned to become Admin plus a tenant-scoped viewer modifier.
Manager
- What it enables
- Own HR self-service plus direct-report directory, documents, time, time-off review, positions, and team work. Direct-report compensation and date of birth use hold-to-reveal.
- Important limits
- Limited to self and the management chain. Direct-report bank and SSN fields stay hidden; no tenant HR settings, offers, onboarding administration, imports, or exports.
Employee
- What it enables
- Own profile, tasks, time, time off, pay preview, and employee documents.
- Important limits
- Cannot browse or edit other employees or access tenant HR administration.
Member (migration in progress)
- What it enables
- The target Crew self-service role is accepted by AUTH.
- Important limits
- Crew's self and manager visibility checks still expect Employee or Manager. Use Employee for dependable self-service until migration is complete.
| Role or class | What it enables | Important limits |
|---|---|---|
| Tenant admin / tenant-scoped Super admin | Tenant roster, hiring, offers, onboarding, employee records, time and time-off administration, documents, reports, imports, data, and HR settings. | Only inside the active business. A tenant-scoped Super admin is normalized to Tenant admin; platform-wide support authority is separate. |
| Owner (migration in progress) | The target top-level Crew role is accepted by AUTH. | Crew's HR administration checks still use Tenant admin. Use Tenant admin for dependable HR administration until migration is complete. |
| Admin (migration in progress) | The target Crew admin label is accepted by AUTH. | Crew's HR administration checks still use Tenant admin. Use Tenant admin until migration is complete. |
| Read-only admin | Broad HR reporting and employee visibility, including sensitive fields, inside the active business without ordinary employee-edit authority. | No ordinary employee edits or HR write actions, and no access to another business. An active business context is required; a legacy assignment without one is denied. The role is planned to become Admin plus a tenant-scoped viewer modifier. |
| Manager | Own HR self-service plus direct-report directory, documents, time, time-off review, positions, and team work. Direct-report compensation and date of birth use hold-to-reveal. | Limited to self and the management chain. Direct-report bank and SSN fields stay hidden; no tenant HR settings, offers, onboarding administration, imports, or exports. |
| Employee | Own profile, tasks, time, time off, pay preview, and employee documents. | Cannot browse or edit other employees or access tenant HR administration. |
| Member (migration in progress) | The target Crew self-service role is accepted by AUTH. | Crew's self and manager visibility checks still expect Employee or Manager. Use Employee for dependable self-service until migration is complete. |
Connected Crew panels and Wren never expose an individual pay rate. Even for a compensation-authorized role, aggregate labor cost and covered hours are withheld when fewer than three distinct employees contribute.
rent: property operations and occupant access
Owner / Property manager
- What it enables
- Full property operation: properties, units, leases, occupants, payments, expenses, vendors, work orders, documents, reports, and settings.
- Important limits
- Tenant-scoped to the active business. Public signing links and occupant access remain limited to their named purpose.
Tenant (occupant)
- What it enables
- Own occupant portal for lease information, documents, payments and payment methods, insurance, co-tenants, and maintenance requests.
- Important limits
- Requires a linked Occupant record and cannot enter the property-management workspace or another occupant's portal.
Admin (not currently usable)
- What it enables
- AUTH still lists this target label during role standardization.
- Important limits
- Rent's remote role validator currently rejects it. Assign Property manager for operational administration.
Member (not currently usable)
- What it enables
- AUTH still lists this target label during role standardization.
- Important limits
- Rent's remote role validator currently rejects it. Occupant access uses Tenant plus a linked Occupant record; there is no general member workspace today.
| Role or class | What it enables | Important limits |
|---|---|---|
| Owner / Property manager | Full property operation: properties, units, leases, occupants, payments, expenses, vendors, work orders, documents, reports, and settings. | Tenant-scoped to the active business. Public signing links and occupant access remain limited to their named purpose. |
| Tenant (occupant) | Own occupant portal for lease information, documents, payments and payment methods, insurance, co-tenants, and maintenance requests. | Requires a linked Occupant record and cannot enter the property-management workspace or another occupant's portal. |
| Admin (not currently usable) | AUTH still lists this target label during role standardization. | Rent's remote role validator currently rejects it. Assign Property manager for operational administration. |
| Member (not currently usable) | AUTH still lists this target label during role standardization. | Rent's remote role validator currently rejects it. Occupant access uses Tenant plus a linked Occupant record; there is no general member workspace today. |
ride: fleet, dispatch, and driver roles
Admin / Staff
- What it enables
- Broad fleet and dispatch operation. Both can enter the management and dispatch surfaces; Admin and legacy Staff also pass current billing and fleet-administration gates.
- Important limits
- Still tenant-scoped. Some especially sensitive development and integration controls check Admin literally.
Dispatcher
- What it enables
- Dispatch board, reservation and recurring-trip operations, calendar, live map, incidents, customer messaging, and trip coordination.
- Important limits
- Can enter the management layout but does not pass Admin or Staff-only billing, vehicle-financial, and certain fleet-configuration gates.
Driver
- What it enables
- Driver-specific schedule, assigned trip detail and status updates, driver messages, and profile.
- Important limits
- No dispatch board or fleet administration. This is the Ride role available to a light seat.
Customer (legacy identity label)
- What it enables
- Represents an older signed-in customer identity.
- Important limits
- Current customer booking, trip lookup, and live status are primarily public token or link flows, not an internal app seat. Do not use Customer for an employee.
Owner (migration in progress)
- What it enables
- The target top-level Ride role is accepted by AUTH.
- Important limits
- Ride route gates still use Admin, Staff, Dispatcher, and Driver. Use Admin for dependable top-level access until migration is complete.
Member (migration in progress)
- What it enables
- The target standard Ride role is accepted by AUTH.
- Important limits
- Current operator layouts do not define a general Member surface. Choose Staff, Dispatcher, or Driver according to the person's job.
| Role or class | What it enables | Important limits |
|---|---|---|
| Admin / Staff | Broad fleet and dispatch operation. Both can enter the management and dispatch surfaces; Admin and legacy Staff also pass current billing and fleet-administration gates. | Still tenant-scoped. Some especially sensitive development and integration controls check Admin literally. |
| Dispatcher | Dispatch board, reservation and recurring-trip operations, calendar, live map, incidents, customer messaging, and trip coordination. | Can enter the management layout but does not pass Admin or Staff-only billing, vehicle-financial, and certain fleet-configuration gates. |
| Driver | Driver-specific schedule, assigned trip detail and status updates, driver messages, and profile. | No dispatch board or fleet administration. This is the Ride role available to a light seat. |
| Customer (legacy identity label) | Represents an older signed-in customer identity. | Current customer booking, trip lookup, and live status are primarily public token or link flows, not an internal app seat. Do not use Customer for an employee. |
| Owner (migration in progress) | The target top-level Ride role is accepted by AUTH. | Ride route gates still use Admin, Staff, Dispatcher, and Driver. Use Admin for dependable top-level access until migration is complete. |
| Member (migration in progress) | The target standard Ride role is accepted by AUTH. | Current operator layouts do not define a general Member surface. Choose Staff, Dispatcher, or Driver according to the person's job. |
auto: repair-shop roles
Admin
- What it enables
- Full repair-shop operation plus tax and numbering settings, operational pricing configuration, refunds, payments, and tenant export.
- Important limits
- Tenant-scoped. Record state and payment-provider status can still prevent an action.
Owner (migration in progress)
- What it enables
- Normal authenticated shop-record access.
- Important limits
- Auto's admin and manager predicates still check legacy role labels, so Owner does not currently inherit tax, export, pricing, refund, or payment authority. Use Admin for full administration.
Auto manager
- What it enables
- Normal shop operation plus labor rates, parts markup, canned jobs, customer sources, parts administration, refunds, and taking payments.
- Important limits
- No Admin-only tax and numbering settings or tenant export.
Service advisor
- What it enables
- Front-desk customer, vehicle, scheduling, estimate, repair-order, invoicing, and payment work.
- Important limits
- Cannot issue refunds or change manager pricing, parts, tax, or export settings.
Technician
- What it enables
- Technician dashboard plus repair-order, inspection, parts, and lookup work. Light seats receive a narrowed repair, parts, and lookup navigation.
- Important limits
- Cannot take payments, issue refunds, or change manager and Admin settings. Some full-seat shop pages are not yet role-trimmed.
Member
- What it enables
- Standard authenticated shop records and operations.
- Important limits
- No payment, refund, manager-pricing, tax, or export authority. Unlike Technician, Member is a full-seat role and does not receive the light-seat navigation trim.
| Role or class | What it enables | Important limits |
|---|---|---|
| Admin | Full repair-shop operation plus tax and numbering settings, operational pricing configuration, refunds, payments, and tenant export. | Tenant-scoped. Record state and payment-provider status can still prevent an action. |
| Owner (migration in progress) | Normal authenticated shop-record access. | Auto's admin and manager predicates still check legacy role labels, so Owner does not currently inherit tax, export, pricing, refund, or payment authority. Use Admin for full administration. |
| Auto manager | Normal shop operation plus labor rates, parts markup, canned jobs, customer sources, parts administration, refunds, and taking payments. | No Admin-only tax and numbering settings or tenant export. |
| Service advisor | Front-desk customer, vehicle, scheduling, estimate, repair-order, invoicing, and payment work. | Cannot issue refunds or change manager pricing, parts, tax, or export settings. |
| Technician | Technician dashboard plus repair-order, inspection, parts, and lookup work. Light seats receive a narrowed repair, parts, and lookup navigation. | Cannot take payments, issue refunds, or change manager and Admin settings. Some full-seat shop pages are not yet role-trimmed. |
| Member | Standard authenticated shop records and operations. | No payment, refund, manager-pricing, tax, or export authority. Unlike Technician, Member is a full-seat role and does not receive the light-seat navigation trim. |
rsvp: bookable resources and appointments
Admin
- What it enables
- Create and manage people, room, and equipment resources; booking links and availability; pending booking decisions; scheduling defaults; calendar and meeting integrations; and tenant export.
- Important limits
- Tenant-scoped. Public customers can only use the booking or cancellation token they receive.
Owner (migration in progress)
- What it enables
- Tenant schedule review and management of booking links, availability, and pending requests for resources owned by that user.
- Important limits
- RSVP's legacy admin and export predicates still require Admin (or a previously stored Super admin). Use Admin for tenant-wide resource creation and settings.
Member
- What it enables
- Review the tenant schedule and manage booking links, availability, and pending requests for resources assigned to that user.
- Important limits
- Cannot create tenant resources, change scheduling defaults, administer another person's resource, or export the tenant.
Legacy Super admin
- What it enables
- Previously stored RSVP Super admin rows retain the current Admin-level scheduling and export gates.
- Important limits
- Not a role a tenant admin can newly assign in AUTH.
Public booker
- What it enables
- Use one public booking link and the resulting cancellation or calendar links.
- Important limits
- Not a seat or app member and cannot browse the business schedule.
| Role or class | What it enables | Important limits |
|---|---|---|
| Admin | Create and manage people, room, and equipment resources; booking links and availability; pending booking decisions; scheduling defaults; calendar and meeting integrations; and tenant export. | Tenant-scoped. Public customers can only use the booking or cancellation token they receive. |
| Owner (migration in progress) | Tenant schedule review and management of booking links, availability, and pending requests for resources owned by that user. | RSVP's legacy admin and export predicates still require Admin (or a previously stored Super admin). Use Admin for tenant-wide resource creation and settings. |
| Member | Review the tenant schedule and manage booking links, availability, and pending requests for resources assigned to that user. | Cannot create tenant resources, change scheduling defaults, administer another person's resource, or export the tenant. |
| Legacy Super admin | Previously stored RSVP Super admin rows retain the current Admin-level scheduling and export gates. | Not a role a tenant admin can newly assign in AUTH. |
| Public booker | Use one public booking link and the resulting cancellation or calendar links. | Not a seat or app member and cannot browse the business schedule. |
tsks: legacy task subscription
TSKS was merged into Work. It remains in AUTH for existing subscriptions and audit history, but new businesses cannot subscribe to it.
Owner / Admin
- What it enables
- Legacy tenant task access now opens Work's task surfaces and supplies the tenant-admin task role when no Work role is present.
- Important limits
- No separate TSKS app remains. Project and task visibility, membership, assignment, and tenant boundaries still apply in Work.
Member
- What it enables
- Create and update tasks in businesses where the person has active membership and a Work or legacy TSKS Member role, subject to task and project visibility.
- Important limits
- Cannot use tenant-admin-only project or team controls. New access should normally be assigned through Work rather than TSKS.
| Role or class | What it enables | Important limits |
|---|---|---|
| Owner / Admin | Legacy tenant task access now opens Work's task surfaces and supplies the tenant-admin task role when no Work role is present. | No separate TSKS app remains. Project and task visibility, membership, assignment, and tenant boundaries still apply in Work. |
| Member | Create and update tasks in businesses where the person has active membership and a Work or legacy TSKS Member role, subject to task and project visibility. | Cannot use tenant-admin-only project or team controls. New access should normally be assigned through Work rather than TSKS. |
Connected context never widens a role
A Hive order can point to a Bill invoice, Pact agreement, Tabs cost, Crew time entry, Loop issue, and Ties customer. Each app still checks the role and exact record before returning its part. If one source is outside your permission, that source is withheld rather than replaced with a nearby record.
Wren receives that same authorized intersection. Read visibility does not give Wren action authority; a supported write is confirmed and authorized again by its owning app when it runs. See How the apps connect and Working across multiple businesses for the graph and tenant boundaries.