Skip to main content

2-Tier Permissions - Managing Who Can See Your Leads and Projects

Controls who sees leads and projects using a 2-tier system: role permission first, then field assignment for View Only and Collaborate roles.

Written by Support

📋 Overview

Structur gives you precise control over who can access your leads and projects. Rather than a simple on/off switch, the platform uses a two-tier system that first checks a user's role permission, and then checks whether they are assigned to specific leads or projects. This combination gives you the flexibility to keep sensitive jobs private while still giving your team the access they need to do their work.

Understanding how these two tiers work together is essential for setting up your team correctly. A user who cannot see a lead or project is almost always missing either the right role permission, the right field assignment, or both. Once you understand the logic, fixing access issues takes less than a minute.

The two-tier system applies to every lead and project in Structur, including ones created before this system was in place. Review your team's role permissions and field assignments after any major team change to make sure everyone has the right level of access.


🔍 Understanding the Two-Tier Permission System

⚡ What It Does

The two-tier system controls access to the Leads and Projects Pipeline using the following logic:

  • Checks role permission first, the system always looks at the user's organization-level role before anything else

  • Controls pipeline visibility, determines whether a user can see the pipeline at all, and which leads or projects appear inside it

  • Uses field assignments as a filter, for View Only and Collaborate roles, the user only sees leads and projects where they are added to at least one team field

  • Applies company-wide, the logic applies to all leads and projects, both existing and newly created

📅 When to Use It

The two-tier system is most valuable when you want to:

  • Keep certain jobs private from team members who are not involved

  • Give estimators and project managers visibility only into the jobs they are working on

  • Allow senior staff to see everything without manually adding them to every project

  • Block access entirely for roles that should not interact with the pipeline at all


📝 Step-by-Step Instructions

1. Understand Tier 1: Role Permission

The first thing Structur checks is the user's role permission for the Leads and Projects Pipeline. This is set in Settings > Permissions under the user's assigned role.

There are four permission levels:

  • Access Denied, The user cannot access the Leads and Projects Pipeline at all. Even if they are added to fields inside a lead or project, they will not see it. This is the right setting for roles that have no business interacting with the pipeline.

  • Full Access, The user can see every lead and project in the system. No field assignment is needed. Use this for owners, admins, and senior staff who need full visibility.

  • View Only, The user can see leads and projects but cannot edit them. Proceed to Tier 2 to determine which specific leads and projects they can see.

  • Collaborate, The user can see and interact with leads and projects according to their role. Proceed to Tier 2 to determine which specific leads and projects they can see.

Note: Only Super Admins and the Company Owner can access Settings > Permissions to change role settings.


2. Understand Tier 2: Field Assignment

Tier 2 only applies when a user's role is set to View Only or Collaborate. When Tier 2 applies, the user can only see a lead or project if they are added to at least one of the following five fields on that lead or project's General tab:

  1. Sales Reps

  2. Estimators

  3. Project Managers

  4. Superintendents

  5. Additional Members

If a user is not listed in any of these five fields on a given lead or project, they will not see it in the pipeline, regardless of how long they have been on your team.

Note: The Design Team Vendors field on the General tab is not part of the access control system. Adding someone there does not grant them pipeline access.


3. Set a User's Role Permission

  1. Go to Settings in the left sidebar

  2. Click Permissions

  3. Find the role you want to update and click the pencil icon to edit it

  4. Locate the Leads and Projects Pipeline section

  5. Set the permission level to Access Denied, Full Access, View Only, or Collaborate

  6. Click Save

Note: Changes apply immediately to all users assigned to that role.


4. Assign a User to a Lead or Project

This step is only required for users whose role is View Only or Collaborate.

  1. Open the lead or project

  2. Navigate to the General tab

  3. Find the relevant field: Sales Reps, Estimators, Project Managers, Superintendents, or Additional Members

  4. Click the field and select the user's name

  5. The user will now see this lead or project in their pipeline


5. Troubleshoot Access Issues

If a user cannot see a lead or project, work through this checklist:

  1. Go to Settings > Permissions and check the user's role

  2. If their role is set to Access Denied, that is why they cannot see anything. Update the permission level.

  3. If their role is set to View Only or Collaborate, open the specific lead or project they should see

  4. Check the General tab and confirm the user is added to at least one of the five fields

  5. If they are not listed in any field, add them and they will see the lead or project immediately


⭐ Best Practices

  • Start with View Only or Collaborate for most roles, Full Access should be reserved for owners and senior admins. Most team members only need to see the jobs they are assigned to.

  • Add users to field assignments at the start of every job, make it a habit when creating a new lead or project to assign your Sales Rep, Estimator, Project Manager, and Superintendent right away.

  • Use Access Denied intentionally, roles like Bookkeeper or Field Crew may not need to see the pipeline at all. Setting them to Access Denied keeps the pipeline clean and focused.

  • Review permissions after role changes, if you update a user's role, double-check that their new permission level matches what you intended for pipeline access.

  • Use Additional Members for anyone outside the core five, if someone needs to see a project but does not fit neatly into Sales Rep, Estimator, PM, Super, or Admin, use the Additional Members field.

  • Full Access users do not need field assignments, do not waste time adding Full Access users to every lead and project. The system gives them visibility automatically.


❓ Common Questions

Q: A user has View Only permission but still cannot see a project. Why?

A: View Only means Tier 2 applies. The user must also be added to at least one of the five fields on the General tab of that specific project. Open the project, go to the General tab, and add them to the Sales Reps, Estimators, Project Managers, Superintendents, or Additional Members field.


Q: I added a user to the Design Team Vendors field. Why can they not see the project?

A: Design Team Vendors is not part of the access control system. Only the five fields listed above grant pipeline visibility. Add the user to one of those fields instead.


Q: Can a user with Access Denied still receive notifications about a project?

A: No. Access Denied removes all pipeline visibility and access. The user will not see notifications for leads or projects.


Q: Do I need to add Full Access users to every project?

A: No. Full Access users can see all leads and projects automatically. Field assignment is only required for View Only and Collaborate roles.


Q: Does the two-tier system apply to projects that were created before this update?

A: Yes. The logic applies to all leads and projects in the system, including existing ones.


Q: What is the difference between View Only and Collaborate in Tier 2?

A: Both permission levels use the same Tier 2 field assignment logic to determine which leads and projects a user can see. The difference is what they can do once they have access. View Only users can read but not edit. Collaborate users can interact with and edit content according to their role.


Q: Can I give one user Full Access and another user View Only for the same role?

A: No. Permissions are set at the role level, not the individual user level. If you need different access levels for users with similar responsibilities, create separate custom roles with different permission settings.


⚠️ Common Mistakes to Avoid

❌ Don't

✅ Do

Add a user to the Design Team Vendors field expecting them to see the project

Add them to Sales Reps, Estimators, Project Managers, Superintendents, or Additional Members

Set everyone to Full Access for convenience

Reserve Full Access for owners and senior admins only

Forget to assign users to the General tab when creating a new project

Add field assignments at project creation as part of your setup checklist

Assume a user with View Only can see all projects

Remember that View Only triggers Tier 2. They only see projects where they are assigned to a field.

Change a user's role without checking their new permission level

Always verify the Leads and Projects Pipeline permission after any role change

Create one shared admin account for multiple people

Keep accounts individual to maintain a clean audit trail

Did this answer your question?