📋 Overview
Not everyone on your team needs access to everything in Structur. Your field crew doesn't need to see financial data. Your bookkeeper doesn't need to manage project schedules. Giving every team member full access to every feature creates unnecessary risk and clutters the experience for people who only need a focused set of tools to do their job.
Settings > Permissions is where you control exactly what each role can see and do across every module in Structur. You set access levels per feature for each role, and every user assigned that role automatically inherits those permissions. Change a role's permissions once and it updates for every team member holding that role instantly.
Structur comes with nine default roles ready to use out of the box. If those don't match how your company is structured, you can create custom roles, starting from scratch or copying an existing role's permissions as a starting point, rename existing ones, and delete roles you don't need. Only Super Admins and the account Owner can access Permissions settings. Every change is logged in a Recent Activity feed at the bottom of each role's page, so you can see who changed what and when.
🔍 Understanding Permissions
⚡ What It Does
Settings > Permissions allows you to:
View permissions for any role, select any role from the dropdown to see its current access level for every feature in the platform, along with a plain-language description of what that level means for each feature
Set four access levels per feature, choose Access Denied, View Only, Collaborate, or Full Access for each feature on a per-role basis
Bulk-set an entire section at once, use Set All Permissions on any section to apply one access level across every feature in that section in a single action
Configure permissions across all platform sections, Preconstruction, Project Management, Financial Management, Task Boards, Company Operations, Systems Accelerator, and Settings
Create custom roles, add new roles with any name, either starting from scratch or copying an existing role's permissions as a base
Edit role names, rename any default or custom role except Super Admin
Delete roles, remove roles that are no longer needed
Search features, use the search bar to quickly find a specific feature without scrolling
Review Recent Activity, see a log of permission changes for the current role, including who made the change and when
📅 When to Use It
Permissions is most valuable when you need to:
Restrict financial data to only the team members who need to see it
Give field crew access to daily logs and timesheets without exposing estimating or billing features
Create a custom role for a job title that doesn't match any of the nine defaults, using an existing similar role as a starting point
Update permissions after a team member changes responsibilities
Review what a specific role can access before assigning it to a new hire
Quickly lock down or open up an entire section at once instead of adjusting features one by one
Check the Recent Activity log to see what permission changes were made recently and by whom
📝 Step-by-Step Instructions
1. Open Settings > Permissions
Click Settings in the left sidebar
Click Permissions in the Settings sidebar
Settings opens as a pop-up window. The Permissions page shows a role selector dropdown in the top left, a search bar and + New Role button in the top right, and the full feature list organized by section below.
Note: Only Super Admins and the account Owner can access Settings > Permissions.
2. View Permissions for a Role
Click the role selector dropdown
Select the role you want to review
The page updates to show the current access level for every feature assigned to that role, along with a short description under the role name (for example, "Bookkeeper role") and a plain-language description next to each feature explaining exactly what the current access level allows.
Features are organized into seven sections: Preconstruction (Leads Pipeline, Embed Form, Overview, General, Intake, Ballparks, Takeoff, Estimates, Proposals, Bid Packages), Project Management (Projects Pipeline, Tasks, Daily Logs, Schedules, Timesheets, Submittals, Checklists, RFI's, Files, Punchlists, Emails, Meetings, Selections), Financial Management (Allowances, Budget, Subcontracts, Purchase Orders, Bills, Lien Waivers, Expenses, Change Orders, Invoices, Receipts), Task Boards, Company Operations (Org Chart, Employee Handbook, Standard Operating Procedures, Human Resources, Admin), Systems Accelerator (Video Training, Templates, Resources, My Program), and Settings (Company, Users, Groups, Permissions, Clients, Vendors, Cost Codes, Billing, Integrations, Affiliate Area).
Note: A few features, currently Punchlists, Meetings, Selections, Purchase Orders, and Lien Waivers, are marked Coming soon. These are shown for visibility but aren't configurable yet since the features themselves haven't shipped.
3. Edit Permissions for a Role
Select the role you want to edit from the dropdown
Find the feature you want to change. Use the Search bar at the top to locate a specific feature quickly
Click the access level badge next to the feature to open the access options
Select the appropriate access level:
🔴 Access Denied, no access to this feature
🟠 View Only, can view but not make changes
🔵 Collaborate, can create and edit, but not delete or manage settings
🟢 Full Access, full control, including delete and settings
Repeat for each feature you want to update
Changes save automatically as you make them.
Note: Permissions changes take effect immediately for all users currently assigned to that role. You do not need to log users out or resend invitations.
4. Set All Permissions for a Whole Section
Instead of updating features one at a time, you can set an entire section to one access level in a single action.
Select the role you want to edit
Find the section you want to update (for example, Financial Management)
Click Set All Permissions in the top right of that section
Choose Access Denied, View Only, Collaborate, or Full Access
Every feature in that section updates to the selected level immediately. You can still adjust individual features afterward if a section needs one or two exceptions.
5. Create a New Role
Click + New Role in the top right of the Permissions page
The Create New Role modal opens
Enter a Role name (required)
Select Copy permissions from, choose Start from scratch for a blank role, or select an existing role to copy its current permissions as your starting point
Enter a Description (optional), a short note on what this role can do
Click Create
The new role now appears in the role selector dropdown. Select it to review or adjust its permissions feature by feature.
6. Rename or Delete a Role
Role management now happens directly from the role dropdown rather than a separate configuration screen. Select the role you want to rename or remove, then use the options available for that role to update its name or delete it.
Note: The Super Admin role cannot be renamed or deleted. All other roles, including the nine defaults, can be renamed.
Important: Before deleting a role, make sure no active users are assigned to it. Reassign those users to a different role first in Settings > Users.
7. Review Recent Activity
Scroll to the bottom of any role's Permissions page to see its Recent Activity log, a running list of permission changes made to that role, showing who made the change, which feature changed, the before and after access level, and how long ago it happened.
⭐ Best Practices
Start by reviewing the default roles before customizing, the nine default roles cover most construction team structures. Adjust their permissions before creating new roles from scratch.
Copy an existing role when creating a similar one, if a new role is close to an existing one, use Copy permissions from instead of configuring every feature manually.
Restrict financial access to only those who need it, Budget, Invoices, Bills, Expenses, and Change Orders should be Full Access for your bookkeeper and project managers, but Access Denied or View Only for field crew and estimators who don't need financial visibility.
Use View Only for roles that need awareness without edit rights, a superintendent who needs to see the schedule but shouldn't change it is a good candidate for View Only on Schedules.
Use Set All Permissions to quickly lock down a section, if a role should have no access to an entire section (like Financial Management), set the whole section to Access Denied in one action instead of feature by feature.
Set permissions for a new custom role immediately after creating it, even when copying from an existing role, review the result and adjust before assigning it to any users.
Check Recent Activity after a permissions issue is reported, it's the fastest way to see whether a recent change is the cause.
Audit permissions periodically, as your team and workflows evolve, role permissions can become outdated. Review them at least once a year or after any significant change to your team structure.
Only assign Super Admin to users who genuinely need full platform access, Super Admin has Full Access to everything including Settings. Limit it to owners and senior administrators.
❓ Common Questions
Q: Who can access Settings > Permissions?
A: Only Super Admins and the account Owner can view and edit Settings > Permissions.
Q: What are the four access levels?
A: Access Denied (no access to this feature), View Only (can view but not make changes), Collaborate (can create and edit, but not delete or manage settings), and Full Access (full control, including delete and settings).
Q: What does "Coming soon" mean next to a feature?
A: That feature isn't live yet. It's shown in the permissions matrix for visibility, but there's nothing to configure until it ships.
Q: What does Set All Permissions do?
A: It applies one access level to every feature in that section at once, for the role you're currently editing. You can still adjust individual features afterward.
Q: Can I base a new role on an existing one instead of starting from scratch?
A: Yes. When creating a new role, use the Copy permissions from dropdown to select an existing role. The new role starts with that role's current permissions, which you can then adjust.
Q: Can I rename the default roles?
A: Yes, all default roles except Super Admin can be renamed directly from the role dropdown.
Q: Can I delete the default roles?
A: Yes, all default roles except Super Admin can be deleted. Make sure no users are assigned to the role before deleting it.
Q: Do permission changes take effect immediately?
A: Yes. Changes to a role's permissions apply instantly to all users currently holding that role. No logout or re-invitation is required.
Q: What shows up in Recent Activity?
A: A log of permission changes made to the role you're currently viewing, which feature changed, the before and after access level, who made the change, and when. Each role has its own Recent Activity log at the bottom of its page.
Q: Where do I assign a role to a specific user?
A: Roles are assigned in Settings > Users, either when you send an invitation to a new user or by editing an existing user's details.
⚠️ Common Mistakes to Avoid
❌ Don't | ✅ Do |
Give every role Full Access across the board | Set the minimum access level each role genuinely needs to do the job |
Configure a new custom role feature by feature when a similar role already exists | Use Copy permissions from to start with a close match, then adjust |
Adjust a whole section one feature at a time when locking it down entirely | Use Set All Permissions to apply one access level to the whole section at once |
Delete a role while users are still assigned to it | Reassign all users to a different role in Settings > Users before deleting the role |
Assign Super Admin to everyone for simplicity | Reserve Super Admin for owners and senior administrators who need full platform access |
Forget to review permissions after team structure changes | Audit role permissions at least once a year or after any significant change to your team |
Assume View Only means no visibility | View Only means the user can view but not make changes |
Ignore Recent Activity when troubleshooting an access issue | Check it first, it often shows exactly what changed and when |
