3.1 Application Roles
Roles are assigned explicitly under Settings → Roles & Permissions or derived from org data (manager, team lead). The role permissions matrix controls page and action access.
| Role | Timesheet / expense visibility |
|---|---|
| Member | Own time, expenses, and PTO only |
| Team Lead | Own data plus team members on their team |
| Manager | Own data plus direct reports, department members, and people on assigned client/project work |
| Admin | All users across the organization |
3.2 Who Can Approve?
Approvers are resolved from org structure and project configuration:
- Employee manager (Team Members)
- Team lead (Teams)
- Department manager (Departments)
- Project approver (Projects)
Workflow settings (Settings → Workflows) control whether employee-side approvers, project approvers, or both may act. If approval is disabled, submit auto-approves immediately.
3.3 SharePoint List Permissions (Security Boundary)
Application role gating controls which pages and buttons appear in the UI only. SharePoint list permissions are the real security boundary. Recommended groups:
| SharePoint group | Suggested access |
|---|---|
| All employees | Contribute: Timesheets, TimeEntries, Expenses, PTORequests; Read: Projects, Clients, Tasks, Holidays |
| Managers | Contribute on approval-related lists |
| Timesheet Admins | Full Control on billing, rates, AppSettings, UserRoles; break inheritance on Invoices, Payments, AuditLogs |
3.4 Permission Resources
The role permissions matrix uses resource keys (dashboard, time_entry, timesheets, approvals, billing, settings, etc.) and actions (view, create, edit, delete, submit, approve, reject, export, import, manage). Admins can customize the matrix under Settings → Roles & Permissions → Role permissions.