Detailed guide

Create Role

The role creation form for defining a new reusable permission bundle.

Use this form to create a clean record the first time or safely update an existing one without guessing which field drives downstream behavior.

Quick summary

  • Create a new role only when adjusting an existing role would confuse or over-broaden access.

Put it into practice

  1. Start by defining the audience for the role before selecting permissions. Build a role for a repeatable job profile, not a one-off exception.

    InteractionsRoles page: click New Role and begin with Role Name field.
  2. Select only the permission groups and actions that role must perform. Keep access narrow and explicit.

    InteractionsCreate Role form: review grouped permission checklist and check required items only.
  3. Save and return to roles list to confirm the new custom role appears with expected summary.

    InteractionsCreate Role form: click Create Role, then inspect new role card.
  4. Assign the role to appropriate users and validate access behavior in user administration workflows.

    InteractionsUsers administration: apply role assignment and verify access outcomes.
    Open workflow: Users

What to review

Page header and breadcrumb

Confirms whether you are creating or editing, gives you the back path, and is the quickest way to avoid updating the wrong record.

Primary form sections

The form is grouped so you can complete one block at a time instead of hunting for every field in a single long screen.

Required inputs and field labels

Every required label tells you what must exist before the record can be saved; blank or invalid values should be corrected before moving on.

Validation and inline errors

Use these messages as instructions, not warnings to dismiss. They tell you exactly which field blocks save and why.

Primary save action

Commits the record only after the form validates. Use it after reviewing every section because it is the action that changes workspace data.

Cancel or return action

Leaves the form and takes you back without finishing the workflow. Use it when you opened the wrong record or need to check related data first.

Role identity

Choose a name that explains who the role is for, not just what it can do.

Permission checklist

This checklist defines the actual permission bundle new users may inherit.

Save controls

Save only when the new role is distinct enough to justify its existence.

Projects permissions

These permissions govern whether someone can inspect projects only or actively maintain the project records that the rest of the workspace depends on.

  • View Projects Allows users to open the Projects list and project detail pages so they can inspect status, budget, margin, delivery, and linked commercial context without changing project setup.
  • Manage Projects Allows users to create, edit, archive, and otherwise maintain project records, including project-level setup actions that change the delivery record itself.

At A Glance permissions

These permissions cover the high-level planning and schedule view used to scan project timing across the workspace.

  • View At A Glance Allows users to open the At A Glance planning view and inspect the project timeline across the workspace.
  • Manage At A Glance Reserves control over any schedule-level maintenance actions tied to the At A Glance area, including legacy schedule-management access where that capability is enabled.

Clients permissions

These permissions control access to the customer records that projects, quotes, and invoices attach to.

  • View Clients Allows users to open the Clients list and client detail pages so they can review account information and linked work.
  • Manage Clients Allows users to create, edit, merge-related, or otherwise maintain client records that downstream projects and documents depend on.

Service Catalog permissions

These permissions control the reusable pricing foundation used by estimates, quotes, and delivery planning.

  • View Service Catalog Allows users to open the Service Catalog and inspect reusable offerings, groups, resources, rates, and categories without changing them.
  • Manage Service Catalog Allows users to create and edit Service Catalog records, including the reusable pricing inputs that estimates and quotes depend on.

Time Tracking permissions

These permissions separate logging your own time from reviewing broader timesheet activity and managing corrections or approvals.

  • Log Time Allows users to create and submit time entries, open time-entry forms, and book effort against permitted projects and tasks.
  • View Timesheets Allows users to open timesheet, pending, unsubmitted, and project work-log views so recorded time can be reviewed.
  • Manage Timesheets Allows users to approve, correct, reopen, and broadly manage timesheet records beyond simple self-service logging.

Estimates permissions

These permissions decide who can inspect pricing plans and who can actively change the estimating model behind commercial work.

  • View Estimates Allows users to open estimate records and review pricing assumptions, scope, resources, and totals without editing them.
  • Manage Estimates Allows users to create and edit estimates, change estimate line structure, and update pricing assumptions that drive quotes and margin planning.

Quotes permissions

These permissions cover client-facing quote records, including the specialized resource-reassignment workflow.

  • View Quotes Allows users to open quote records and inspect client-facing commercial details without changing the quote.
  • Manage Quotes Allows users to create, edit, and maintain quote records and the quote workflow built from project estimates.
  • Reassign Quote Resources Allows users to run the quote-resource reassignment workflow when work needs to move between resources without rebuilding the quote manually.

Invoices permissions

These permissions control who can inspect billing records and who can actively change invoice data and billing workflows.

  • View Invoices Allows users to open invoice records and inspect billing status, line items, and payment context without editing the invoice.
  • Manage Invoices Allows users to create, edit, issue, and otherwise maintain invoice records and invoice-linked billing actions.

Expenses permissions

These permissions separate expense visibility and self-service entry logging from full administrative maintenance of expense records.

  • View Expenses Allows users to review expense records and expense history so project cost can be inspected without changing entries.
  • Log Expenses Allows users to create and submit expense entries against the projects they are allowed to charge.
  • Manage Expenses Allows users to approve, edit, delete, and broadly maintain expense records beyond simple entry logging.

Reports permissions

These permissions separate report consumption from ownership of saved report definitions and reporting setup.

  • View Reports Allows users to open the reporting workspace, run report queries, and review saved reports and raw results.
  • Manage Reports Allows users to create, update, and delete saved reports and other report definitions, not just read the reporting output.

Revenue Goal permissions

These permissions control access to Revenue Goal planning, including both the goal calculator and the Capacity-to-Revenue Planner assumptions and outputs.

  • View Revenue Goal Allows users to open the Revenue Goal area and review goal assumptions, targets, and calculated outputs.
  • Manage Revenue Goal Allows users to edit revenue-goal assumptions, targets, and budget items that drive the calculator's outputs.
  • View Capacity-to-Revenue Planner Allows users to open the Capacity-to-Revenue Planner and review monthly capacity, utilisation, and feasibility outputs.
  • Manage Capacity-to-Revenue Planner Allows users to manage saved planner assumptions and operational capacity-planning settings where editing is enabled.

Administration permissions

These permissions unlock workspace administration actions that affect people, access, integrations, and bulk data movement.

  • Manage Users Allows users to open user administration and create users, change assigned roles, activate or deactivate accounts, and reset passwords.
  • Manage Settings Allows users to open and update workspace-wide settings, including defaults, tolerances, tax/VAT rates, and invoice profile fields.
  • Manage Roles Allows users to open role administration and create, edit, or delete custom roles and their permission bundles.
  • Manage Integrations Allows users to configure and maintain connected integrations and the related operational settings and sync controls.
  • Manage Data Import Allows users to open the Data Import area, download templates, upload import files, preview imports, and review import history.

Guardrails

  • New roles should have a complete and intentional permission set before save.
  • Role creation is admin-only.

If it starts drifting

  • If the new role feels too similar to an existing one, reconsider whether a role edit is the cleaner fix.