Roles & Permissions
Roles decide what each person on your team can see and do inside TimberCloud. Every user is assigned one role, and each role carries a set of permissions — from "can this person see prices?" to "can they issue refunds?" This page explains how role-based access works, walks the permission catalog in plain language, and clears up a point that trips people up: the difference between what your plan unlocks and what your role allows.
Availability: Build plan and up. Role editing lives under Settings → Company → Permissions, a Build feature. On Free and Commerce your company is a single Admin user, so there are no roles to manage. See Subscriptions & Plans.
How role-based access works
Access is granted per role, not per person. You define the roles once, tick the permissions each role should have, and then assign a role to each user on the Users page. Change a role's permissions and everyone holding that role is updated at once.
Every new company starts with seven ready-made roles — Admin, Management, Employee, Sales, Shop, Driver, and Customer. Those seven are marked System roles: you can retune their permissions, but you can't delete or rename them. For what each is meant for, see Users.
Note: Admin always has every permission, and its checkboxes are locked on — you can't take access away from Admin. That's the guardrail behind the "at least one Admin" rule.
Creating and editing roles
Open Settings → Company → Permissions. You'll see a grid: roles down the left, permissions across the top, grouped into category tabs (for example Page Access, Order Management, and Payment Management).
To create a role
- Click Add Role.
- Give it a name (for example "Front Office" or "Installer").
- Click Create. The new role appears in the grid with no permissions yet.
To set permissions
- Pick a category tab.
- Tick or untick the boxes for each role in that category.
- Click Save Changes. Repeat per category — each tab saves the whole grid.
To delete a role
- Click the trash icon next to any custom (non-System) role. If people are still assigned to it, TimberCloud warns you first; those users then need to be reassigned to another role.
Tip: Build roles around jobs, not people. A "Shop Lead" or "Estimator" role you can reuse beats hand-tuning one person's access — and it's far easier to audit later.
The permission catalog
Permissions are grouped into categories. Below are the ones with real teeth — the toggles that change what a person can see or do. Unticking a box removes that ability for every user in the role.
Money and financial visibility
| Permission | What it does when the role lacks it |
|---|---|
| View Prices | Hides every money value across the dashboard — order totals, line-item prices, payments, product prices, revenue widgets — replacing each with a dash (—). Use it for shop-floor or delivery roles that shouldn't see pricing. |
| View Customer Financials | Hides a customer's aggregate money picture: their Lifetime Value and Balance stats, the Payments tab, the balance-due rollups, and "amount due" badges. Per-order totals still show. This is separate from View Prices — a role can keep seeing an individual order's price but not the customer's overall financial standing. |
| Issue Credits | Required to post a credit (a manual balance adjustment) to a customer. Without it, the credit action is unavailable. |
Note: View Prices and View Customer Financials are independent switches. Turn off View Prices to blank all money everywhere; turn off only View Customer Financials to let a role price individual orders while keeping a customer's total balance and payment history private.
Payments
| Permission | Effect |
|---|---|
| Post Payments | Lets the role record a payment against an order (the core "take a payment" permission). The server also checks it when a transaction is refunded. |
| Refund Payments | Controls the Refund button — it appears only for roles that hold this permission. |
| Authorize Payments | Controls approving a pending (employee-initiated) payment and editing a recorded offline payment — those actions appear only for roles that hold this permission. |
Order actions
| Permission | Effect |
|---|---|
| Archive Order | Lets the role archive an order out of the active list. |
| Duplicate Order | Lets the role copy an existing order into a new one. |
| Manage Product Order | Controls whether the role can manage a product's ordering details on an order. |
| Manage Tracking | Lets the role add or edit shipment tracking on an order. |
Page access
Page Access permissions decide which whole sections a role can open. The important ones:
| Permission | Effect |
|---|---|
| Reports Page | Grants access to the Reports dashboards. |
| Designer Page | Grants access to the 3D Kitchen Designer page and the "Open Designer" button. This one is also plan-gated — it only takes effect on Build and up (see the two-layer model below). |
| Orders, Customers, Users, Purchasing, Shop, Shipping, Reviews, Settings | Each opens or hides its matching left-nav section for the role. |
Dashboard tiles
A set of dashboard permissions — Overview, Orders, Production, and Deliveries — decide which tiles a role sees on the home dashboard. Turn on only the tiles a given role should land on. For example, a Driver role might keep Deliveries but not Production.
Note: The AI Assistant permission only appears in the grid when AI is enabled for your company. If you don't use the AI features, it's hidden.
Two layers of gating: plan vs. role
A feature can be locked for two completely different reasons. Keeping them straight saves a lot of confusion.
| Layer | What it controls | What you see when it's locked |
|---|---|---|
| Plan gating | Whether your subscription tier includes the feature at all. | The nav item still appears, but with a padlock and a blurred preview. Clicking it opens an upgrade prompt. Every tier sees every nav item — your plan decides which are live. |
| Role gating | Whether your role is allowed to use a feature your plan already includes. | The item is simply hidden, or its values are masked (money shown as —). No upgrade prompt — this is about permissions, not plan. |
These layers are independent:
- Plan-locked: A Commerce shop opening Reports sees a padlocked, blurred teaser — Reports is a Build feature. Upgrading unlocks it.
- Role-hidden: On a Build shop, an Employee whose role lacks Reports Page doesn't see Reports at all — no padlock, no teaser. An Admin flips the permission and it appears.
- Both at once: The 3D Kitchen Designer needs Build (plan) and the Designer Page permission (role). Miss either and it stays out of reach.
Tip: If someone reports a "missing" feature, check both layers. A padlock means upgrade the plan; a feature that's simply absent means grant the permission on their role.
A note on TimberCloud Support access
Occasionally a TimberCloud support specialist may enter your dashboard to help troubleshoot. While they're active, a clear, non-dismissible banner is shown so it's never a surprise. Support acts with Admin-level access (or can mirror one of your own roles to reproduce an issue), never occupies a seat or appears in your team list, and any change they make is attributed to them in that record's history. Plan gating still applies — support can't unlock features your plan doesn't include.
Next Steps
- Users — add people and assign them roles
- Customer Claims — approve or deny customer account requests
- Company Settings — where the Permissions grid and registration settings live
- Subscriptions & Plans — which features each plan unlocks
- Managing Customers — the customer records Customer logins link to