Skip to content

Roles and permissions ​

Permissions decide what each person can see and do in Site Connect: which menu items appear, which records they can open, and whether they can create, edit or delete. You manage them with permission roles — groups such as admin, manager or employee — and every person belongs to one or more of them.

Menu: System › Permissions

The System menu has two pages with similar names:

  • Permissions — the permission roles and what each one is allowed to do. This is the page that controls access.
  • Roles — a simple list of job-function groups (HR, Finance…). These don't give or take away any access. See Job-function roles below.

Where to find it

Menu: System › Permissions and System › Roles · Address: hub.siteconnect.ai/permissions and hub.siteconnect.ai/rolesWho can use it: The workspace owner and admins. The built-in manager and employee roles can't open these pages.

How access works ​

  • A person's access is everything their roles allow, added together.
  • The workspace owner and anyone with the admin role always have full access, whatever is ticked.
  • Each row of the permission grid matches a menu item. Without View on a row, the matching menu item is hidden.
  • Changes take effect right away. The person's menu updates the next time they reload the page or reopen the app — they don't need to sign out.

The built-in roles ​

Every workspace starts with three permission roles. They're marked System with a lock: you can't rename or delete them, but you can change their permissions and members. On the employee form they appear as Administrator, Manager and Employee.

RoleWhat it can do out of the box
adminEverything, including settings, roles and permissions.
managerEverything in every area, except the Roles and Permissions pages. On the Settings rows it can view and edit.
employeeView on almost every row, so the menu shows nearly everything. Create and edit only where people serve themselves: attendance, leave, approvals, tasks and chat. On Scheduling, view only.

Everyone you add to the workspace gets the employee role. Give extra roles on top of it.

Check what the employee role can see

Because the employee role has View on almost every row, by default crews can also open pages such as Labour cost rates (controlled by the HR reports row) and read-only System pages such as General settings. If that's more than you want, open the employee role and untick View on those rows.

Create a role ​

A role for a job — Foreman, Office, Scheduler — is easier to manage than adjusting people one by one.

  1. Go to System › Permissions.
  2. Select + at the top of the role list, type a name (Permission group name...) and select Create.
  3. The new role opens with nothing ticked. Tick what it needs (see below) and select Save permissions.

Start from a copy

Hover over a role in the list and select Duplicate (the copy icon). You get a copy named "… (Copy)" with the same permissions — for example, copy employee to make a Foreman role, then add a few extra boxes. Hover over a role you created to Rename or Delete it.

Set what a role can do ​

  1. Go to System › Permissions and select the role in the list on the left. It shows how many members it has.
  2. Stay on the Permissions tab. The grid is grouped like the left menu — HR, Projects, Scheduling, Tasks, System and so on. Select a group's header to fold or unfold it; the counter shows how many boxes are ticked.
  3. Tick the boxes you want (columns are explained below).
  4. Select Save permissions. You'll see Permissions saved for ….

Shortcuts: the All box on a group header ticks everything in that group, the box under a column name ticks that column for the section, and the last All column ticks a whole row.

The columns ​

ColumnLets the role…
ViewOpen the page. Where records belong to people, see only their own.
TeamAlso see the records of people in the teams they lead (they're the Team lead of a team in Teams / Departments, or of a team above it).
AllSee everyone's records.
CreateAdd new records.
EditChange records.
DeleteRemove records.
ApproveDoesn't apply to any row in Site Connect — you'll see a dash.

A few rules keep the grid consistent:

  • Ticking All also ticks Team and View; ticking Create, Edit or Delete also ticks View.
  • A dash (—) means the action doesn't apply to that row.
  • Some rows belong to a bigger row and show it with a ⊂ sign — for example Timesheet (monthly) belongs to Timesheet. Ticking the smaller row also ticks the same box on the bigger row, and unticking the bigger row unticks the smaller one.

Which row controls what ​

Rows are named after the menu items they control. The ones Site Connect admins use most:

To control…Use this row
EmployeesThe Employees row in HR
Employee invitationsEmployee invitations
Contracts and Job titlesThe Contracts row
Labour cost rates and a project's Finance tabHR reports (view). Adding or changing rates is limited to admins.
Attendance management, Unallocated hours, Attendance settingsAttendance management
TimesheetsTimesheet and Timesheet (monthly)
Timesheet credit rulesThe Shifts row
Adjustment approvalsAdjustment approvals
Leave, Annual leave, HolidaysThe Leave row, Annual leave, Holidays
Everything under Projects and TasksTask — it appears in both the Projects and Tasks groups, and both control the same permission
SchedulingScheduling (see below)
Approval inbox and Approval templatesThe Approvals row and Approval templates
General settings, Mobile app, Kanban appearanceThe Settings row
StorageThe Storage row — the All box opens the page

Who can build the schedule ​

The Scheduling row has only two boxes:

  • View — open the Scheduling board read-only. People see the published schedule with a View only badge, but no draft tasks, labour costs or other people's worked hours.
  • Edit — build the schedule: create, edit, delete and publish tasks, approve workers' requests, change the board's settings, and see drafts.

Everyone can view the board out of the box: the employee role has View, and admins and the manager role have both boxes. To let someone schedule, give them a role with Scheduling › Edit. People without Edit still see and answer their own scheduled tasks in the mobile app.

Add people to a role ​

You can give someone a role in three places:

  • On the role: select the role, open the Members tab, select Add manually, search (Search employees, departments...) and click the person. Select × on a member to remove them.
  • On the employee form: tick roles under Permissions (Roles) when you add or edit someone — see Employees.
  • On an invitation: choose roles when you invite someone — see Employee invitations.

Approval templates use the same permission roles, for example to limit who can submit a request (By role) or to send a step to a Role. See Approval templates.

Check what someone can do ​

  1. Go to System › Permissions and select the magnifier icon (Look up permissions by user) at the top of the role list.
  2. Search for the person by name or email and select them.

You'll see their roles and every permission they have, grouped by menu area. For the workspace owner and admins, the list includes everything.

See who changed a role ​

Select a role and open the History tab. The Change log lists who did what and when — roles created, renamed, duplicated or deleted, members added or removed, and the permissions granted or revoked.

Job-function roles (the Roles page) ​

System › Roles keeps a list of job-function groups. A new workspace has HR, Finance, Legal, IT and Admin, marked System — their names are fixed and they can't be deleted. Each card shows its description and how many members it has. These roles don't change what anyone can see or do.

  • Create one: select Create role, enter a Role name and Description, then select Create.
  • Add or remove members: open a card, select Add, search for the person and select Add next to them. Use the remove icon next to a member to take them off.
  • Rename or delete: open a role you created, change its name or description and select Save, or select the bin icon to delete it.

Good to know ​

  • Keep the number of admins small — an admin can do everything, including changing permissions.
  • The manager role can change General settings and the Mobile app menu, but not roles or permissions.
  • Deleting a role you created removes it from all its members; their other roles stay.

Site Connect — run your job sites from one place.