Roles and permissions

The difference between an access level and a role, and how to decide what each person can do.

3 minute read

Two things decide what somebody can do in your studio, and confusing them is the only mistake available here.

The access level

This is the hierarchy. Three values, and they are not configurable.

Level What they can do
Owner Everything, including deleting the studio.
Admin Everything except deleting the studio.
Member Whatever you decide.

The first two being fixed is deliberate: somebody has to always be able to undo a configuration that locked everybody out.

The role

This is what you write for your members. A role is a set of permissions you name: "Fitter", "Assistant", "Sales".

You create it once from Studio settings → People and roles, and give it to whoever needs it.

The rule that keeps this readable

Exactly one thing answers, in this order:

  1. The access level, if it is owner or admin.
  2. Permissions written by hand on that person, if there are any.
  3. The role they have been given.
  4. The default permissions, otherwise.

They never add up. There is no "the role plus these two". The consequence is that "why can he do that?" always has a one-word answer rather than a calculation.

One corollary worth knowing: customising a person copies their role's permissions onto them and detaches the role. Editing the role afterwards no longer follows them. That is what you want most of the time, but it is better known in advance.

Deleting a role locks nobody out: its members return to the default permissions.

The permission that deserves a word

See all orders is separate from see orders. The second opens the tab at all; the first decides whether that means every order in the studio or only the ones assigned to them.

That is what makes assignment useful rather than decorative, and it is the setting to look at first when you invite a subcontractor.

What the default allows

A member with no particular role can do everything to do with the work: orders, clients, services, deliveries, payments. What they cannot do is administration: inviting, changing permissions, touching the subscription, deleting the studio.

Restricting somebody is a deliberate gesture rather than the starting point.

Depending on your plan

Writing your own roles is a Team feature. On the others, the access levels and the default permissions are of course still there.

Updated on August 9, 2026

Read next