Managing Team Permissions & Access
How to configure Collaborator permissions, review who has access to your project, and maintain security best practices.
Reason for revision: the published body lists a permission row as "Documents — View files / Upload
files", while the real row label is **Documents / Files**, and the panel includes **SOV Mapping**,
which the published table omits. The revision also describes what the Documents / Files setting now
enforces on the Files page.
---
Overview
As the project Owner you decide who has a seat on your project and what they can do. Roles do most
of the work; a Collaborator's access can then be tuned feature by feature.
Configuring Collaborator permissions
When you invite or edit a **Collaborator**, each feature area can be set to read or write:
| Feature area | Read | Write |
|---|---|---|
| Budget | View line items and totals | Add and edit budget items |
| Allowances / Selections | View selections | Choose and update selections |
| Draw Requests | View draw requests | Prepare and submit draws |
| Vendors | View the vendor list | Add and edit vendors |
| To-Dos | View to-dos | Create and update to-dos |
| Documents / Files | View documents and files | Upload and create documents |
| Schedule | View tasks and dates | Create and update tasks |
| SOV Mapping | View the mapping | Change the mapping |
A Collaborator with nothing set defaults to read access.
> **TIP:** Start read-only and grant write access when someone actually needs to enter data. It is
> easier to grant more than to unpick a change that should not have happened.
Where the toggles stop
Permissions control what the page offers. They are not a guarantee about stored files:
- The **Documents / Files** setting decides the **Files** page. **None** hides it — the Collaborator
- sees "Files aren't available to you", and typing the address or requesting a file directly is
- refused as well. Read allows opening and downloading; write also allows uploading, and editing or
- deleting only their own uploads. Removing or unhiding someone else's file stays with you.
- A download link already issued keeps working for the few minutes until it expires, even after you
- switch someone's access off. Turning access off stops new links, not one already copied.
- **Banker** is read-only throughout, and sees only files that have not been hidden from the
- client view.
- A **Client** seat is separate again: read-only money views, and uploads and deletions limited to
- their own files.
Security practices worth keeping
**Review access monthly.** Open your team panel and remove anyone whose work on the project has
finished.
**Label your invitations.** "Mike — plumber", "Sarah — designer" makes the list readable months
later.
**Be sparing with write access.** Most consultants only need to read.
**Understand the Banker role.** It gives a lender read-only financial visibility without vendor
contact details, which protects your vendor relationships while the bank gets what it needs.
Activity log
Team actions are recorded — who changed what, and when, including budget modifications and
expense entries.
> **WARNING:** Activity records cannot be edited or deleted.
Troubleshooting
**"Permission denied".** Check the person's role, then a Collaborator's feature settings, then that
they are looking at the right project — the sidebar project selector decides which project every
page is showing.
**An invitation link does not work.** Links last seven days, are single use, and stop working once
revoked. Create a new one.
**Someone cannot see data they expect.** Some data is role-restricted by design; Bankers cannot see
vendor contact details. See [Understanding Roles](/help/account/understanding-roles).