Onboarding Guides
Employees: Roles & Permissions
Last updated
Control access, and assign website logins.
Settings > Roles
A Role is a reusable permission template. Instead of setting permissions person-by-person, you define a role once (what it can see and do) and then assign that role to as many employees as you like.
1. Getting There
Click your profile avatar (top-right) and choose Settings.
On the Account Settings screen, click the ROLES tab.
2. How the Roles Screen Works
Role selector (dropdown): pick the role you want to view or edit. Default roles include Admin, Manager, Viewer, and any custom roles (e.g., New Team Member).
+ button: create a new role.
Permission grid: each module shows a Visible checkbox plus action checkboxes (create, edit, delete, etc.). Tick what the role may do.
Save: commits your changes to that role.
Example — “Viewer”: typically only the Visible boxes are checked, giving read-only access. “Admin” has every box checked.
3. Permissions You Can Control (By Module)
Each module below has a Visible toggle (whether the role sees it at all) and the listed action permissions:
Module | Action permissions |
|---|---|
Photos | Delete Photo(s), Edit Photo Metadata |
Livemap | Create Filtered View(s) |
Sites | Add new site(s), Delete site(s), Edit site data |
Map Builder | Add / Delete / Edit maps, Add/Edit/Delete Account Layer(s) |
Employees | Create, Delete, Edit employees, Add/Assign Roles |
Materials | Create, Delete, Edit materials |
Services | Create, Delete, Edit services |
Routes | Create, Delete, Edit routes |
API Integrations | Manage API Integrations |
Report Generator / Snow Estimator | Visible (access only) |
Form Builder | Create, Delete, Edit forms |
Service History | Add/Edit/Approve/Reject, Approve Rejected, Reject Approved, Lock, Unlock, Quickbooks Invoice/Bill |
Pricing Contracts | Add, Edit, Delete pricing contracts |
Invoice Dashboard | Create, Delete, Edit invoices |
Site Leads | Add, Edit, Delete site leads |
Vehicle List / Assignments | Create/Edit/Delete vehicles; Add/Edit/Delete assignments |
Equipment | Create, Edit, Delete equipment |
Contractors | Create, Delete, Edit contractors |
Clients | Create, Delete, Edit clients |
Activities | Create, Delete, Edit activities |
Companies | Create, Delete, Edit companies |
Worker History / Snow Command Center | Visible (access only) |
4. Creating a New Role (Step by Step)
On the ROLES tab, click the + button.
Give the role a name.
Work down each module, ticking Visible plus the specific actions the role should have.
Click Save. The new role now appears in the role dropdown — and in the User Role lists used when assigning web access.
Settings > Permissions
Where Roles define what access looks like, the Permissions tab manages who actually has a website login. It is your list of web-account users.
1. Getting There
Avatar (top-right) > Settings.
Click the PERMISSIONS tab.
2. The User Permissions List
A table of everyone who can log in to the web app, with columns Name, Email, Role, and Actions. A search box helps you find users quickly. Per-user actions:
Action | What it does |
|---|---|
Edit (pencil) | Change the user's Default Page, User Role, and the “Restrict user to assigned sites” option. |
Change Password (key) | Set a new password for that user. |
Delete (trash) | Remove the user's web login. |
3. Adding a Web Login User
Click the + button next to “User Permissions.”
Select Employee — choose an existing employee, or use the + beside it to create a new employee on the spot.
User Password — a strong password is generated automatically; share it securely with the user (they can change it later).
Select default page — the landing screen after login (e.g., Photos, Sites).
Select User Role — pick a role from the list (these come straight from Settings > Roles).
Restrict user to assigned sites — tick this to limit the user to only the sites assigned to them.
Click Save. The person can now sign in with their email and the password you set.
4. Roles VS Permissions - Which Do I Use?
I want to… | Go to… |
|---|---|
Define what a type of user can see and do | Settings > Roles (create/edit the role template) |
Give a specific person a login | Settings > Permissions > Add User (or the employee record's Website Login Permissions) |
Change someone's password | Settings > Permissions (key icon) |
Change someone's role or landing page | Settings > Permissions (pencil) or the employee record |
Stop someone from logging in | Settings > Permissions (delete the user) — the employee record can remain |
End-to-End: Onboarding a New Team Member
A complete walkthrough that ties all three areas together.
Confirm the right role exists. In Settings > Roles, check that a suitable role is defined (e.g., Manager). If not, create one and Save.
Create the employee. CRM > Employees > + New Employee. Enter at least their name and email; add title, branch, mobile, and any routes or pay rates. Save.
Grant web access. Either on the employee record set User Role + Default Page under Website Login Permissions, or go to Settings > Permissions > + Add User, pick the employee, set the password, default page, and role, and (optionally) restrict to assigned sites. Save.
Set mobile-app behavior. On the employee record, enable Track time with the app (and Crew Leader if relevant) and set site-creation/camera options as needed.
Hand off credentials. Share the login email and password securely. The new user lands on the default page you chose, with access governed by their role.
Verify. Open the Web Accounts view in CRM > Employees to confirm the person now has a login, and check Settings > Permissions shows the correct role.
Quick reference
Roles = permission templates (Settings > Roles).
Permissions = the actual login users and their passwords (Settings > Permissions).
Employees = the people records; assign a User Role here to give web access.
Web Accounts view = quick list of who can log in.
Was this helpful?
Your feedback helps us make every guide clearer.