Roles & Permissions

Roles decide what each person on your team can see and do inside TimberCloud. Every user is assigned one role, and each role carries a set of permissions — from "can this person see prices?" to "can they issue refunds?" This page explains how role-based access works, walks the permission catalog in plain language, and clears up a point that trips people up: the difference between what your plan unlocks and what your role allows.

Availability: Build plan and up. Role editing lives under Settings → Company → Permissions, a Build feature. On Free and Commerce your company is a single Admin user, so there are no roles to manage. See Subscriptions & Plans.

How role-based access works

Access is granted per role, not per person. You define the roles once, tick the permissions each role should have, and then assign a role to each user on the Users page. Change a role's permissions and everyone holding that role is updated at once.

Every new company starts with seven ready-made roles — Admin, Management, Employee, Sales, Shop, Driver, and Customer. Those seven are marked System roles: you can retune their permissions, but you can't delete or rename them. For what each is meant for, see Users.

Note: Admin always has every permission, and its checkboxes are locked on — you can't take access away from Admin. That's the guardrail behind the "at least one Admin" rule.

Creating and editing roles

Open Settings → Company → Permissions. You'll see a grid: roles down the left, permissions across the top, grouped into category tabs (for example Page Access, Order Management, and Payment Management).

To create a role

  1. Click Add Role.
  2. Give it a name (for example "Front Office" or "Installer").
  3. Click Create. The new role appears in the grid with no permissions yet.

To set permissions

  1. Pick a category tab.
  2. Tick or untick the boxes for each role in that category.
  3. Click Save Changes. Repeat per category — each tab saves the whole grid.

To delete a role

  • Click the trash icon next to any custom (non-System) role. If people are still assigned to it, TimberCloud warns you first; those users then need to be reassigned to another role.

Tip: Build roles around jobs, not people. A "Shop Lead" or "Estimator" role you can reuse beats hand-tuning one person's access — and it's far easier to audit later.

The permission catalog

Permissions are grouped into categories. Below are the ones with real teeth — the toggles that change what a person can see or do. Unticking a box removes that ability for every user in the role.

Money and financial visibility

PermissionWhat it does when the role lacks it
View PricesHides every money value across the dashboard — order totals, line-item prices, payments, product prices, revenue widgets — replacing each with a dash (—). Use it for shop-floor or delivery roles that shouldn't see pricing.
View Customer FinancialsHides a customer's aggregate money picture: their Lifetime Value and Balance stats, the Payments tab, the balance-due rollups, and "amount due" badges. Per-order totals still show. This is separate from View Prices — a role can keep seeing an individual order's price but not the customer's overall financial standing.
Issue CreditsRequired to post a credit (a manual balance adjustment) to a customer. Without it, the credit action is unavailable.

Note: View Prices and View Customer Financials are independent switches. Turn off View Prices to blank all money everywhere; turn off only View Customer Financials to let a role price individual orders while keeping a customer's total balance and payment history private.

Payments

PermissionEffect
Post PaymentsLets the role record a payment against an order (the core "take a payment" permission). The server also checks it when a transaction is refunded.
Refund PaymentsControls the Refund button — it appears only for roles that hold this permission.
Authorize PaymentsControls approving a pending (employee-initiated) payment and editing a recorded offline payment — those actions appear only for roles that hold this permission.

Order actions

PermissionEffect
Archive OrderLets the role archive an order out of the active list.
Duplicate OrderLets the role copy an existing order into a new one.
Manage Product OrderControls whether the role can manage a product's ordering details on an order.
Manage TrackingLets the role add or edit shipment tracking on an order.

Page access

Page Access permissions decide which whole sections a role can open. The important ones:

PermissionEffect
Reports PageGrants access to the Reports dashboards.
Designer PageGrants access to the 3D Kitchen Designer page and the "Open Designer" button. This one is also plan-gated — it only takes effect on Build and up (see the two-layer model below).
Orders, Customers, Users, Purchasing, Shop, Shipping, Reviews, SettingsEach opens or hides its matching left-nav section for the role.

Dashboard tiles

A set of dashboard permissions — Overview, Orders, Production, and Deliveries — decide which tiles a role sees on the home dashboard. Turn on only the tiles a given role should land on. For example, a Driver role might keep Deliveries but not Production.

Note: The AI Assistant permission only appears in the grid when AI is enabled for your company. If you don't use the AI features, it's hidden.

Two layers of gating: plan vs. role

A feature can be locked for two completely different reasons. Keeping them straight saves a lot of confusion.

LayerWhat it controlsWhat you see when it's locked
Plan gatingWhether your subscription tier includes the feature at all.The nav item still appears, but with a padlock and a blurred preview. Clicking it opens an upgrade prompt. Every tier sees every nav item — your plan decides which are live.
Role gatingWhether your role is allowed to use a feature your plan already includes.The item is simply hidden, or its values are masked (money shown as —). No upgrade prompt — this is about permissions, not plan.

These layers are independent:

  • Plan-locked: A Commerce shop opening Reports sees a padlocked, blurred teaser — Reports is a Build feature. Upgrading unlocks it.
  • Role-hidden: On a Build shop, an Employee whose role lacks Reports Page doesn't see Reports at all — no padlock, no teaser. An Admin flips the permission and it appears.
  • Both at once: The 3D Kitchen Designer needs Build (plan) and the Designer Page permission (role). Miss either and it stays out of reach.

Tip: If someone reports a "missing" feature, check both layers. A padlock means upgrade the plan; a feature that's simply absent means grant the permission on their role.

A note on TimberCloud Support access

Occasionally a TimberCloud support specialist may enter your dashboard to help troubleshoot. While they're active, a clear, non-dismissible banner is shown so it's never a surprise. Support acts with Admin-level access (or can mirror one of your own roles to reproduce an issue), never occupies a seat or appears in your team list, and any change they make is attributed to them in that record's history. Plan gating still applies — support can't unlock features your plan doesn't include.

Next Steps