Roles & permissions
Understand the built-in roles, see exactly what each one can do, and fine-tune permissions on the editable presets from the Roles tab.
A role decides what a member can see and do. Foreman ships with a set of built-in roles so you can get started without configuring anything — and you can adjust most of them when you need finer control.
Open the Roles tab
- From the sidebar, click Organization.
- Click the Roles tab.
The tab opens on a table of every role — Role, Category (Internal, Client, or Vendor), Type (Preset or Custom), and Members. Search by name, or click Filters and pick a Category to narrow it. Click a role's row to open its access matrix; the back arrow beside the role name returns you to the table.
Don’t see this?
The built-in roles
Every organization comes with these presets. They can't be renamed, deleted, or re-categorized.
- Owner — full access to everything, including billing. There is exactly one owner, and it can't be reassigned.
- Admin — everything the owner can do except manage billing.
- Member — day-to-day work across projects, budgets, records, schedule, and more, but no team, billing, or settings management.
- Field — a lighter set aimed at crews: daily logs, time tracking, to-dos, files, and read access to projects.
- Client and Vendor — view-level access for the people outside your company, scoped to only what's shared with them.
See what a role can do
You don't have to memorize the matrix. To check a specific person:
- Go to the Members tab and click their row.
- The panel shows their role under Permissions and a plain-language What they can do summary grouped by area.
Adjust an editable role
Most presets can be fine-tuned — Admin, Member, Field, Client, and Vendor. Only Owner is fully locked.
- On the Roles tab, select the role.
- For each resource row, pick an access level from the segmented control — power increases left to right, starting at None. Most rows offer View and View & Edit; some go further, for example Requests adds Edit & Send (creating a bid request and sending it to vendors are separate permissions), Client Finances adds Edit, Void & Record Payments, Vendor Agreements adds Edit & Send, and Vendor Finances offers View & Code and Approve & Pay.
- Where a row offers a scope dropdown, choose All or Only if given access.
Note
Two cards sit above the resource sections:
- Financials (derived) — a read-out, not a knob. It shows whether this role can see Cost, Price, and Margin, derived from the record access you granted: vendor records unlock cost, client records unlock price, and margin needs both.
- Portal (internal roles only) — toggle whether members in this role appear as a project contact in the client or vendor portal by default.
Changes save as you go. Everyone with that role picks up the new permissions the next time they load the app.
Note
Note
Related
- Control which projects a member sees in Project access scope.
- Add or remove the people these roles apply to in Add & remove members.