Roles & permissions
Understand the built-in roles, see exactly what each one can do, and fine-tune permissions on the editable presets from the Roles tab.
A role decides what a member can see and do. Foreman ships with a set of built-in roles so you can get started without configuring anything — and you can adjust most of them when you need finer control.
Open the Roles tab
- From the sidebar, click Organization.
- Click the Roles tab.
Roles are grouped into Internal Roles, Client Roles, and Vendor Roles. Click any role on the left to see its access matrix on the right.
Don’t see this?
The built-in roles
Every organization comes with these presets. They can't be renamed, deleted, or re-categorized.
- Owner — full access to everything, including billing. There is exactly one owner, and it can't be reassigned.
- Admin — everything the owner can do except manage billing.
- Member — day-to-day work across projects, budgets, records, schedule, and more, but no team, billing, or settings management.
- Field — a lighter set aimed at crews: daily logs, time tracking, tasks, files, and read access to projects.
- Client and Vendor — view-level access for the people outside your company, scoped to only what's shared with them.
See what a role can do
You don't have to memorize the matrix. To check a specific person:
- Go to the Members tab and click their row.
- The panel shows their role under Permissions and a plain-language What they can do summary grouped by area.
Adjust an editable role
Most presets can be fine-tuned — Admin, Member, Field, Client, and Vendor. Only Owner is fully locked.
- On the Roles tab, select the role.
- For each resource row, pick an access level from the segmented control — power increases left to right, starting at None. Most rows offer View and View & Edit; some go further, for example Requests adds Edit & Send (creating a bid request and sending it to vendors are separate permissions), Client Finances adds Edit, Void & Record Payments, and Vendor Agreements adds Edit & Send.
- Where a row offers a scope dropdown, choose All or Only if given access.
Two cards sit above the resource sections:
- Financials (derived) — a read-out, not a knob. It shows whether this role can see Cost, Price, and Margin, derived from the record access you granted: vendor records unlock cost, client records unlock price, and margin needs both.
- Portal (internal roles only) — toggle whether members in this role appear as a project contact in the client or vendor portal by default.
Changes save as you go. Everyone with that role picks up the new permissions the next time they load the app.
Note
Note
Related
- Control which projects a member sees in Project access scope.
- Add or remove the people these roles apply to in Add & remove members.