Skip to content

Access Levels & Permissions (RBAC)

Planmaster gives Company Administrators total control over what each staff member can view and modify. Role-Based Access Control (RBAC) secures confidential financial accounts, client contracts, and employee payroll data while giving site engineers the exact operational tools they need.

Access this section from the sidebar under Settings > Roles.

Roles List


The 17 Permission Categories (Full Security Matrix)

Planmaster secures the platform across 17 distinct resource modules containing 65 granular permission toggles:

Resource Module Permissions Available What it Protects in Everyday Terms
๐Ÿ—๏ธ Projects (projects) create, read, update, delete, manage_members Starting projects, setting budgets, and assigning site teams.
๐Ÿ“‹ Tasks (tasks) create, read, update, delete Daily site assignments, status updates, and blocker reporting.
๐Ÿ“ BOQ (boq) create, read, update, delete Contractual quantities, unit rates, and executed volume entries.
โœ… Checklists (checklists) template_manage, template_read, create, read, update, delete, fill Building/editing safety & QA checklist templates, attaching them to projects, and filling out or deleting the results.
๐Ÿ“ฆ Inventory (inventory) create, read, update, delete, transfer_request, transfer_approve Catalog management, stock transfer requisitions, and warehouse sign-offs.
๐Ÿงพ Invoices (invoices) create, read, update, delete, record_payment Client billing, payment recording, and UTR tracking.
๐Ÿ’ฐ Finance (finance) create, read, update, delete Site expense logging, cashbook entries, and voucher editing (the company Ledger).
๐Ÿ‘ฅ Clients (clients) create, read, update, delete Customer accounts, contact numbers, and billing addresses.
๐Ÿ‘ท Employees (employees) create, read, update, delete Staff directory, emergency contacts, and compensation details.
๐Ÿ›๏ธ Departments (departments) create, read, update, delete Setting up and editing organizational divisions.
๐ŸŽ–๏ธ Designations (designations) create, read, update, delete Setting up and editing professional job titles.
๐Ÿ”ข ID Sequences (id_sequences) read, update Configuring auto-numbering prefixes and zero-padding for employee codes.
๐Ÿ“‘ Custom Lists (picklists) read, update Managing dropdown options for local_body_type and project_type.
๐Ÿ” Roles (rbac) create, read, update, delete Authoring and customizing security roles.
๐Ÿ‘ค Users (users) create, read, update, delete Inviting new team members, resetting passwords, and deactivating seats.
๐Ÿ” Audit Logs (audit) read Viewing the chronological compliance audit trail of user actions.
๐Ÿ“Š Reports (reports) read Accessing executive management summaries and cross-project analytics.

Documents & Company have no dedicated permission module

Unlike the modules above, project Documents and the Company profile page are not controlled by their own toggle in the Roles permission matrix.


Creating a Custom Role (e.g., Storekeeper or Billing Clerk)

While standard roles (Admin, Engineer, General User) meet the needs of most construction companies, you can create tailored roles in minutes:

Example: Setting Up a Storekeeper Role

A warehouse manager needs to view materials and approve transfers, but should not see client invoices or company bank balances:

  1. Go to Settings > Roles in the left sidebar.
  2. Click New Role.
  3. Name the role: STOREKEEPER.
  4. In the permissions selector:
  5. Under inventory: Check inventory.read, inventory.update, and inventory.transfer_approve.
  6. Under documents: Check documents.read.
  7. Under projects: Check projects.read.
  8. Leave invoices, ledger, and users unchecked.
  9. Click Create Role.

Verifying Your Effective Permissions

Wondering what actions your current login is permitted to perform? - Click your initials in the top right header, and select My Profile (or go to Account > My Profile). - Scroll to the My permissions section. Planmaster displays a complete, categorized breakdown of every action granted by your assigned role.