Administration
Included

Roles & Permissions

Understand what Admins, Managers, Supervisors, and Employees can access, how project assignments narrow visibility, and how module entitlements affect available workflows.

Four permission layers

  • Company role, project assignment, module entitlement, and record state all combine before an action is allowed.

Assignment narrows access

  • Non-Admin users only see and act on projects where they have an active assignment.

Server enforcement

  • Hidden navigation improves usability, but API routes and services enforce permissions independently.

Overview

Prospeno permissions are layered. A user must pass every layer that applies to the action they are trying to perform.

1. Company role

  • The user’s general capability across the workspace — Admin, Manager, Supervisor, or Employee.

2. Project assignment

  • Which projects a non-Admin user may access, supervise, or work on.

3. Module entitlement

  • Whether an optional paid workflow such as Materials or Salaries & Payroll is active for the company.

4. Record state and ownership

  • Whether the specific record is Draft, Submitted, Approved, Paid, disabled, or owned by another user.

All required layers must allow the action

Access is granted only when all required permission layers allow the action.

Core role comparison

  • Capability

    Company settings

    Admin

    Yes — /settings and company profile

    Manager

    No — route blocked

    Supervisor

    No — route blocked

    Employee

    No — route blocked

  • Capability

    User management

    Admin

    Yes — create, edit, disable, reset access

    Manager

    No — /employees blocked; API lists managed-project staff only

    Supervisor

    No

    Employee

    Own profile only

  • Capability

    Project visibility

    Admin

    All company projects

    Manager

    Assigned projects only

    Supervisor

    Assigned operational projects

    Employee

    Assigned projects only

  • Capability

    Financial visibility

    Admin

    Company-wide financial modules, cashflow, rates, profit

    Manager

    Project financials on assigned/managed projects; no company cashflow or reports

    Supervisor

    Limited; supervisor expense amounts may be masked

    Employee

    No company-wide financial access

  • Capability

    Record creation

    Admin

    Broad company and project operations

    Manager

    Assigned-project operations; company-paid expenses where allowed

    Supervisor

    Field attendance and assigned operational workflows

    Employee

    Own attendance, assigned work, supported submissions

  • Capability

    Approvals

    Admin

    Expense, liquidation, payroll, office budget, and other Admin approvals

    Manager

    Labor and materials on managed projects; not expense approval

    Supervisor

    Generally submit only; no central approval authority

    Employee

    Submit only; no approvals

  • Capability

    Module management

    Admin

    Yes — Module Marketplace, Subscription, Wallet

    Manager

    No — routes blocked

    Supervisor

    No

    Employee

    No

  • Capability

    Mobile / Field access

    Admin

    Yes where supported

    Manager

    Yes — mobile check-in and assigned field workflows

    Supervisor

    Yes — primary operational channel

    Employee

    Yes — employee portal and kiosk where enabled

Permission matrix

Admin

Admin capabilities

  • Company-wide project visibility and project creation
  • Company settings, users, roles, and access control
  • Module Marketplace activation, Subscription, and Wallet
  • Dashboard, Reports, Collections, and company financial administration
  • Expense approval, payroll runs, budget-release approval, and liquidation approval
  • Project Command Center financial visibility including profit views where implemented
  • Employee rate visibility and workforce administration

Admin limits

  • Actions still require an active company account and user record.
  • Paid workflows still require the module to be entitled.
  • Record state may block edits even for Admins.
  • Plan limits still apply to users and active projects.
  • Cannot disable self or remove the last active Admin.
  • Platform Super Admin actions remain outside the company workspace.

Manager

What Managers can do

  • View and operate on assigned projects through Projects, Labor, and Project Command Center
  • Manage project members on projects where they are assigned as Project Manager
  • Approve attendance and overtime on projects they manage
  • Approve or fulfill Materials & Requisition requests on managed projects when the module is enabled
  • Submit and manage company-paid expenses where implemented
  • Submit project expenses on accessible projects
  • Use Project Assignments when granted sidebar access
  • Use mobile check-in and assigned field workflows

Manager restrictions

  • Cannot create company projects — only Admins can create projects
  • Cannot access Dashboard, Reports, Collections, Wallet, Subscription, Modules, or Settings routes
  • Cannot access /employees user administration in the web route policy
  • Cannot approve project or company expenses — expense approval is Admin-only
  • Cannot view company payroll, salaries administration, budget releases, or company-wide cashflow
  • Cannot assign company Admin accounts through project assignment rules
  • Profit visibility is limited to projects they manage; viewer assignments do not grant profit access

Supervisor

What Supervisors can do

  • Access assigned projects through the supervisor portal and allowed labor routes
  • Use mobile or kiosk attendance on assigned projects where enabled
  • View labor, timesheet, locations, and project-labor surfaces on the allow list
  • View materials requests on allowed expense/material routes when entitled
  • Submit or view own operational records according to assignment

Supervisor restrictions

  • No company settings, user administration, modules, wallet, or subscription access
  • No project creation or company-wide project list
  • No collections, billing, reports, dashboard, or payroll administration
  • No expense approval authority
  • No project-member assignment authority by default
  • Expense amount visibility may be masked on some supervisor-facing lists

Supervisor is an operational role, not a finance or company-administration role.

Employee

What Employees can do

  • Use the employee portal at /my-work for assigned project context
  • Record own attendance through mobile or kiosk where enabled
  • Submit supported project expenses and operational records on assigned work
  • View own profile and supported own-record workflows
  • View own payslip surfaces only where Salaries & Payroll is enabled and exposed to the user

Employee restrictions

  • No company-wide financial visibility
  • No approvals queue or approval authority
  • No user, settings, module, wallet, or subscription administration
  • No web manual attendance routes outside allowed employee portal paths
  • No project creation, assignment management, or profit dashboards

Super Admin boundary

  • Super Admin is a platform-administration role used by Prospeno operators.
  • It is not assigned by company Admins and is not part of normal company staffing.
  • It may manage plans, limits, Wallet top-ups, or platform support tasks.
  • Company users should not expect Super Admin access in their workspace.

Role vs project assignment

Role

Controls general capability across the company.

  • Admin
  • Manager
  • Supervisor
  • Employee

Project assignment

Controls which projects a non-Admin user may access or participate in.

  • Manager, Supervisor, Employee, Viewer, or labor assignment on a specific project
  • Creating a Manager does not automatically assign every project.
  • Removing an assignment does not change the user’s company role.
  • Disabling a user blocks access while preserving assignment history.
  • Assignment does not create attendance, labor, payroll, or expenses by itself.

Role vs module entitlement

Role permission

  • Determines whether the user is allowed to use a type of workflow.

Module entitlement

  • Determines whether the company has that workflow active and billed.

An Admin may be allowed to manage payroll, but Salaries & Payroll must still be active for the company.

  • Salaries & Payroll — payroll runs, payslips, and salary expense administration
  • Materials & Requisition — material requests, approvals, and fulfillment
  • Budget Releases & Liquidation — cash advances, liquidations, and released-budget expenses
  • Kiosk Attendance — shared kiosk check-in mode
  • Custom Branding — branded company login experience
  • Quotation Builder — quotation authoring and customer-facing quote workflows

UI visibility vs server enforcement

  • Hidden buttons and sidebar items improve usability but are not the only security control.
  • Sensitive actions are also enforced in API routes, services, and database policies.
  • Users should not assume a manually entered URL bypasses permissions.
  • Route access, company scope, role, module state, assignment, and record ownership may all be validated.

Financial visibility

  • Surface

    Project contract value / estimated profit

    Admin

    Yes

    Manager

    On managed projects via canViewProfit rules

    Supervisor

    No

    Employee

    No

  • Surface

    Labor cost on projects

    Admin

    Yes

    Manager

    On accessible projects

    Supervisor

    Limited operational view

    Employee

    Own work only

  • Surface

    Project expenses

    Admin

    Yes

    Manager

    On accessible projects

    Supervisor

    Assigned scope; amounts may be masked

    Employee

    Own/submitted scope

  • Surface

    Company expenses

    Admin

    Yes

    Manager

    Submit/manage where allowed

    Supervisor

    Limited view routes

    Employee

    No

  • Surface

    Collections / billings

    Admin

    Yes

    Manager

    Route blocked

    Supervisor

    No

    Employee

    No

  • Surface

    Payroll / salaries admin

    Admin

    Yes

    Manager

    Route blocked

    Supervisor

    No

    Employee

    Own payslip only where exposed

  • Surface

    Wallet

    Admin

    Yes

    Manager

    Route blocked

    Supervisor

    No

    Employee

    No

  • Surface

    Subscription billing

    Admin

    Yes

    Manager

    Route blocked

    Supervisor

    No

    Employee

    No

Permission matrix

Exact fields visible on a page may still vary by screen, but server checks remain authoritative.

Approval permissions

  • Category

    Attendance

    Submit

    Employee / Supervisor / Manager / Admin on assigned work

    Review / approve

    Admin or Project Manager on that project

    Reopen / void / protected actions

    Admin or project manager edit rules; approval route required for status change

    Module dependency

    Core platform

  • Category

    Overtime

    Submit

    According to labor workflow

    Review / approve

    Admin or Project Manager via canManageProject

    Reopen / void / protected actions

    Follows attendance / labor record state

    Module dependency

    Core platform

  • Category

    Project expenses

    Submit

    Assigned users on accessible projects

    Review / approve

    Admin only

    Reopen / void / protected actions

    Admin may reopen to Pending where supported

    Module dependency

    Core platform

  • Category

    Company expenses

    Submit

    Admin or Manager

    Review / approve

    Admin only

    Reopen / void / protected actions

    Protected review transitions

    Module dependency

    Core platform

  • Category

    Materials

    Submit

    Assigned operational users

    Review / approve

    Admin or Manager on managed project

    Reopen / void / protected actions

    Admin-only correction on completed requests

    Module dependency

    Materials & Requisition

  • Category

    Budget Releases

    Submit

    Admin workflows

    Review / approve

    Admin only

    Reopen / void / protected actions

    Admin-controlled lifecycle

    Module dependency

    Budget Releases & Liquidation

  • Category

    Liquidation

    Submit

    Recipient or Admin

    Review / approve

    Admin only

    Reopen / void / protected actions

    Admin reopen where supported

    Module dependency

    Budget Releases & Liquidation

  • Category

    Office Budget Requests

    Submit

    Permitted submitters

    Review / approve

    Admin only

    Reopen / void / protected actions

    Admin revise / cancel flows

    Module dependency

    Office Budget Requests

  • Category

    Payroll

    Submit

    System-generated from approved inputs

    Review / approve

    Admin only

    Reopen / void / protected actions

    Admin void / status changes

    Module dependency

    Salaries & Payroll

  • Category

    Quotations

    Submit

    Permitted authoring roles when module enabled

    Review / approve

    Follow quotation workflow statuses

    Reopen / void / protected actions

    Status-dependent edit restrictions

    Module dependency

    Quotation Builder

Status table

Creation and editing permissions

Creation authority (high level)

Admin only

  • Projects
  • Users
  • Payroll runs
  • Collections / billings
  • Budget releases

Admin or assigned Project Manager

  • Project member assignments
  • Project batch labor on managed projects

Assigned operational users

  • Attendance
  • Project expenses
  • Materials requests
  • Own profile updates

State restrictions

  • Draft records are generally editable by permitted creators.
  • Submitted records move into review flows and may become read-only for submitters.
  • Approved records are locked against casual edits.
  • Paid, completed, or voided records require protected Admin or module-specific workflows.
  • Historical records should not be casually overwritten.

Sensitive administration

Generally Admin-only surfaces

  • Company settings and workspace configuration
  • User administration and role changes
  • Subscription, Wallet, and Module Marketplace
  • Custom Branding activation
  • Payroll approval and company financial controls
  • Collections, reports, and dashboard administration

Documented exceptions

  • Managers may submit company-paid expenses but cannot approve them.
  • Managers may approve materials and labor on projects they manage.
  • Managers may manage project assignments on projects where they are the assigned Project Manager.

Changing a user’s role

  1. 1

    Open Users

    Go to /employees as a company Admin.

  2. 2

    Select the user

    Open the employee row or edit drawer.

  3. 3

    Review current responsibilities

    Check assignments, approvals, and financial exposure.

  4. 4

    Choose the lowest appropriate role

    Select Admin, Manager, Supervisor, or Employee.

  5. 5

    Save the change

    Admin-only update through the employee API.

  6. 6

    Review project assignments separately

    Role changes do not remove or add project assignments automatically.

  7. 7

    Verify module and financial access

    Confirm the user can still reach only the intended surfaces.

  • Only company Admins can change another user’s role.
  • A user cannot change their own access role unless they remain an Admin editing permitted fields.
  • Demoting the last active Admin is blocked.
  • Role changes update the company profile immediately in the database.
  • The web client reads role from workspace bootstrap; affected users may need refresh or sign-in again to see navigation changes.
  • Audit references remain on the user record after role changes.

Least-privilege guidance

  • Assign the lowest role needed for the person’s responsibilities.
  • Avoid shared accounts.
  • Limit Admin access to trusted operators.
  • Disable former employees promptly in Users & Access.
  • Separate approval and submission duties where practical.
  • Review project assignments after promotions or role changes.
  • Review module access after plan or staffing changes.
  • Use supported workflows rather than manual workarounds.

Known permission boundaries

Global role and tenant scope

Every permission check is scoped to the user’s company_id. Users cannot access another company’s records through normal workspace routes.

Project assignment lifecycle
  • Active assignments grant project access according to role_in_project.
  • Removed or inactive assignments stop future access but preserve history.
  • Viewer assignments may allow read-only visibility without operational actions.
Financial masking

Some supervisor-facing expense lists mask amounts even when the user can open the record context.

Employee and supervisor roles do not receive company profit dashboards.

Module-gated routes

Module routes such as materials, payroll, quotations, and kiosk surfaces require both role permission and active module entitlement.

Record ownership

Many workflows allow users to edit or withdraw their own pending records while approvers handle company-wide review queues.

Session refresh after role change

Navigation and route guards use the role returned by workspace bootstrap. After an Admin changes a user’s role, that user may need to refresh the workspace or sign in again before sidebar and route access fully match the new role.

Mobile role behavior

Employee and Supervisor accounts are oriented to mobile field workflows. Manager mobile access follows assigned project policy. Server APIs enforce the same role and assignment checks as the web app.

Important limitations

  • Role does not automatically assign projects.
  • Project assignment does not change the company role.
  • Active module entitlement is separate from role permission.
  • UI visibility alone is not the security boundary.
  • Managers do not automatically receive Admin access.
  • Supervisors are not company finance administrators.
  • Employees cannot approve their own records unless explicitly supported.
  • Record status may restrict actions even when the role normally permits them.
  • Role changes may require workspace refresh or sign-in again according to current client behavior.
  • Historical records and audit references should remain preserved after access changes.
  • Super Admin is a platform role and cannot be assigned by company Admins.

Where to find help

Use the ? button in the web application for the current page guide, Getting Started, Module Guides, and Contact Support.

Related links

Jump to the module, marketplace, or broader help resources.

Roles & Permissions Guide — Prospeno Docs