How the assistant respects permissions
The assistant can only do what your role allows — the same permission rules that govern the app govern the assistant.
The assistant is a faster way to do the work you're already allowed to do — never a way to do more.
It acts as you
When the assistant makes a change, it's acting on your behalf, within your access:
- It only sees projects and data you can see.
- It can only create or edit what your role permits.
- Clients and vendors get an assistant scoped to their limited access too.
If your role can't create invoices, the assistant can't either when you ask — that ability simply isn't available to it.
Permissions are as fine-grained for the assistant as they are for you. Creating and sending are separate permissions on several record types, so a role set to View & Edit on Requests can have the assistant draft a bid request but not send it — sending needs the Edit & Send level.
Areas it stays out of by design
A few surfaces are off-limits to the assistant regardless of role — handle these directly:
- Billing and subscription
- Team, members, and roles — the assistant can look these up (members, roles, the permission catalog) but never change them
- Account and organization settings
- Connecting or disconnecting integrations
- The plan/takeoff canvas and file markup (hands-on visual tools) — it can read existing markup, but not draw it
- Uploading files — it can read, move, and organize files you already uploaded
Note