Managing Team Permissions & Access

How to configure Collaborator permissions, review who has access to your project, and maintain security best practices.

Reason for revision: the published body lists a permission row as "Documents — View files / Upload
files", while the real row label is **Documents / Files**, and the panel includes **SOV Mapping**,
which the published table omits. The revision also describes what the Documents / Files setting now
enforces on the Files page.

---

Overview

As the project Owner you decide who has a seat on your project and what they can do. Roles do most
of the work; a Collaborator's access can then be tuned feature by feature.

Configuring Collaborator permissions

When you invite or edit a **Collaborator**, each feature area can be set to read or write:

| Feature area | Read | Write |
|---|---|---|
| Budget | View line items and totals | Add and edit budget items |
| Allowances / Selections | View selections | Choose and update selections |
| Draw Requests | View draw requests | Prepare and submit draws |
| Vendors | View the vendor list | Add and edit vendors |
| To-Dos | View to-dos | Create and update to-dos |
| Documents / Files | View documents and files | Upload and create documents |
| Schedule | View tasks and dates | Create and update tasks |
| SOV Mapping | View the mapping | Change the mapping |

A Collaborator with nothing set defaults to read access.

> **TIP:** Start read-only and grant write access when someone actually needs to enter data. It is
> easier to grant more than to unpick a change that should not have happened.

Where the toggles stop

Permissions control what the page offers. They are not a guarantee about stored files:

  • The **Documents / Files** setting decides the **Files** page. **None** hides it — the Collaborator
  • sees "Files aren't available to you", and typing the address or requesting a file directly is
  • refused as well. Read allows opening and downloading; write also allows uploading, and editing or
  • deleting only their own uploads. Removing or unhiding someone else's file stays with you.
  • A download link already issued keeps working for the few minutes until it expires, even after you
  • switch someone's access off. Turning access off stops new links, not one already copied.
  • **Banker** is read-only throughout, and sees only files that have not been hidden from the
  • client view.
  • A **Client** seat is separate again: read-only money views, and uploads and deletions limited to
  • their own files.

Security practices worth keeping

**Review access monthly.** Open your team panel and remove anyone whose work on the project has
finished.

**Label your invitations.** "Mike — plumber", "Sarah — designer" makes the list readable months
later.

**Be sparing with write access.** Most consultants only need to read.

**Understand the Banker role.** It gives a lender read-only financial visibility without vendor
contact details, which protects your vendor relationships while the bank gets what it needs.

Activity log

Team actions are recorded — who changed what, and when, including budget modifications and
expense entries.

> **WARNING:** Activity records cannot be edited or deleted.

Troubleshooting

**"Permission denied".** Check the person's role, then a Collaborator's feature settings, then that
they are looking at the right project — the sidebar project selector decides which project every
page is showing.

**An invitation link does not work.** Links last seven days, are single use, and stop working once
revoked. Create a new one.

**Someone cannot see data they expect.** Some data is role-restricted by design; Bankers cannot see
vendor contact details. See [Understanding Roles](/help/account/understanding-roles).