Browse articles

How permissions work

Understand Account, Project, and Team access levels, where defaults apply, and why a visible level may still be limited.

What you'll achieve

Choose an access level and understand the access it will give a person.

You'll end up with: You can set account, project, and team access in the right place and check the effective result.

Monument uses three kinds of access level. Each answers a different question.

Access levelWhat it controlsWhere you define it
AccountWhat a person can do across the practice, such as manage staff, see Business finances, use Rates, and create reports.Permissions → Account
ProjectWhat they can see or change on a project or task branch: Revenue, Expenses, Tasks, Resources, Time, Budget usage, and Practice targets.Permissions → Project
TeamWhich colleagues' profiles, time, leave, and assignments they can work with.Permissions → Team

You define an access level once in Permissions. A person's Access section assigns an Account level. Project Members assigns a Project level. Team membership assigns a Team level. These assignment controls do not create another copy of the level.

Account access follows the person

Monument finds a person's Account level in this order:

  1. An access level chosen for that person.
  2. The default on their practice Role, such as Architect.
  3. The firm's default Account level.

An explicit choice stays with the person if their practice Role changes. An inherited choice follows the Role or firm default. The picker shows real access levels; the resolved level and its source tell you which rule supplied it. A practice Role alone does not open a project.

The built-in Director level has full practice and access-control authority. Office administrator manages billing, staff and teams, contacts, and timesheet corrections, but it is not a Director. Project owner and Team member are narrower Account levels. A custom level may combine ordinary capabilities, but it does not become a Director. Only a Director can change Account assignments or a practice Role assignment that can change inherited Account access.

An Account level also sets Project visibility and Access level when assigned. The latter supplies the Project level when an allocation or matching people rule brings the person into a project. With all-project visibility, a project floor can also apply. Check the effective project result before assuming its Revenue and Expenses settings will be visible.

Project access has a source and a boundary

Project access can come from a manual Members grant, project ownership, a matching people rule, allocation, or the all-project floor. The source matters. A manual grant is a deliberate project decision. Automatic grants are limited by Account Business finances for Revenue and Expenses. A person with Business finances Hidden may have a Project level that says Revenue View but still receive Revenue Hidden from an allocation.

The Project access-level table marks the Project owner default and Project lead default. Project ownership uses the Revenue and Expenses values in the Project owner default directly. There is no second ownership-finance switch. A Project lead gets the Project lead default when their team is assigned. Manual Project grants remain separate.

Project grants can apply to one task branch instead of the whole project. Confidential projects and financial office access can limit the result further. Project Viewer gives View for Tasks, Resources, and Time and hides Revenue and Expenses. Own time entry may still be available where the person's other time and task rules permit it.

Team access and personal work

Team levels control access to other people in the team. Lead, Member, and Viewer levels separate profiles, time, leave, and assignments. A person's own time and leave are also subject to their task visibility and workflow rules. A Team level does not itself grant Project Revenue or Business finances. The Team table marks the Team member default used when a team membership has no explicit level.

Deleting an access level requires a replacement. Existing people, assignments, and defaults using the deleted level move to that replacement. The protected Director Account level cannot be deleted because the firm must retain a Director identity.

Reports and financial offices

An Account level can allow all saved reports or select categories and reports. Selection only makes a report available for consideration. Its data must still be reachable through that person's Account, Project, Team, branch, and office access. Reports View permits running available reports. Reports Edit adds creating and editing definitions where the creator rule allows it. A report can be selected yet unavailable because its data is hidden.

Financial office restrictions are another limit. An Account level may cover all offices or a selected set. A person may also have an individual office restriction. The effective range is the offices admitted by both. Selecting no offices intentionally hides financial data.

A worked example

At Northlight Architects, Sarah Chen has the Team member Account level from her Architect practice Role. An allocation brings her into Riverside Civic Library at Project Viewer. She can read its tasks and record her own time where allowed. Viewer hides Revenue and Expenses. If a Director changes her Project level to one with Revenue View, an allocation alone may still leave Revenue Hidden while her Account Business finances is Hidden. A manual Project grant has different finance treatment. Preview Sarah's effective access on the project to check the real result.

The Account-level Reports available preview assumes allocation at that level's default Project access. It cannot know Sarah's exact ownership, manual grants, task branch, or office restrictions. Use a person's permission preview to check those details. Preview is read-only; Act-as is a separate mode.

When a result looks wrong

  • A level says Revenue View, but the person sees no money. Check whether the Project grant came from allocation or ownership, then check Account Business finances and financial offices.
  • A saved report is missing. Check both the report selection and access to its data.
  • A Role change did not change someone's Account level. Check for an explicit Account choice.
  • A project is missing. Check its assignment or people rule, task branch, and confidential status. Being able to open Projects does not reveal every project.

Settings → Practice defaults contains budget, milestone, utilisation, and expense-approval settings. Access levels and their defaults live in Permissions. Continue with staff permissions and project access for the assignment workflows.

Search Monument help

Search help articles and open a result.