Roles & permissions

    Control exactly what every role can see and do

    TimeMagick uses role-based permissions to decide what each role can see, create, change and delete. The permission matrix covers 40 modules, from timelines and approvals to reports, invoices and project channels, each with View, Create, Update and Delete controls where they apply.

    1-month free trial

    How the permission model works

    Permissions are set per role. For each role, every permission module has up to four actions: View, Create, Update and Delete. With 40 modules, that is a matrix of up to 160 permission controls per role.

    1. Role

    Choose a role

    Owner and CLIENT are locked system roles. Custom roles, such as Project Manager, Engineer, Sales or Contractor, are yours to create and edit.

    2. Permission module

    Pick a product area

    40 modules, from Timeline and Tracked Time to Reports, Export Report, Invoice and Project Channel.

    3. Actions

    Set what the role can do

    View, Create, Update and Delete. Some modules only offer the actions that apply to them.

    Actions follow the module

    Not every module needs all four actions. In the Role Permission screen, dashboard modules such as Admin Dashboard show a View control only, while modules such as Clients and Projects have View, Create, Update and Delete.

    If a role doesn't have access to a screen, TimeMagick redirects to a dedicated no-access page.

    Illustrative example of one role's settings, not a default configuration.

    The Role Permission screen

    Choose a role from the role selector, search the permission list, and switch each action on or off. Changes apply to every member who holds that role.

    TimeMagick Role Permission screen with a role selector and View, Create and Update toggles for modules such as Team, Clients, Projects and All Projects
    Role Permission screen in TimeMagick.

    Permissions follow the product, not just Admin and User

    Instead of one admin switch, access is split by product capability. A few examples of modules that TimeMagick keeps separate:

    Reading reports vs. exporting them

    Reports and Export Report are separate modules. Reading a report and extracting it as a formatted Excel file are separate rights.

    Projects vs. All Projects

    TimeMagick exposes Projects and All Projects as two separate permission modules, next to Projects Overview, Project Task and Custom Project Status.

    Project Channel vs. All Project Channels

    Project communication has two separate permission modules of its own, so channel access is configured alongside project access.

    Lunch: member view vs. admin view

    Members claim meal allowances in a monthly calendar; admins review a member-by-day grid for the whole team. The two views are separate permissions.

    All 40 permission modules

    The full list of modules in the Role Permission matrix, grouped here by area.

    Dashboards & activity (6)

    • Admin Dashboard
    • Member's Dashboard
    • Timeline
    • Member's Timeline
    • KPIs
    • Apps & URLs usage

    People & access (4)

    • Member
    • Team
    • Roles
    • Roles & Permission

    Clients & projects (6)

    • Clients
    • Projects
    • All Projects
    • Projects Overview
    • Project Task
    • Custom Project Status

    Time & approvals (4)

    • Manual Time
    • Tracked Time
    • Member's TimeSheet
    • Personal Timesheet

    Expenses (7)

    • Company Expenses
    • Company Expenses Approval
    • Recurring Expenses
    • Recurring Expenses Approval
    • Recurring Expense Payment History
    • Lunch (Member view)
    • Lunch (Admin view)

    Reports & billing (3)

    • Reports
    • Export Report
    • Invoice

    Communication (2)

    • Project Channel
    • All Project Channels

    Settings (8)

    • Profile Setting
    • Company Setting
    • Work Setting
    • Project Setting
    • Project Folder Setting
    • Activity Setting
    • Apps & URLs Setting
    • Billing Accounts

    Members, Teams, Roles and Client Members

    TimeMagick's people model lives on one Members screen with four tabs. Permissions are attached to roles, and every member is assigned a role.

    Members

    Each member has a profile with their team, their role, a flex-hours setting and employee and company tax percentages, and can be activated or deactivated.

    Teams

    Named groups of members, which you can create, edit and delete.

    Roles

    Owner and CLIENT are locked system roles. Custom roles can be created, edited and deactivated, and each role has its own permission settings.

    Client Members

    External users linked to one or more of your clients. They hold the CLIENT role and use their own client-facing workspace.

    Why access control matters in a connected system

    In TimeMagick, time tracking, projects, billing and profitability work from the same project data. That means one workspace holds very different kinds of information, and not everyone needs all of it.

    Role-based permissions let you give each role the parts of that shared system it actually needs, module by module, instead of choosing between full access and none.

    What lives in the same workspace

    • Tracked time, timelines and timesheets
    • Activity %, productivity % and app and URL usage
    • Projects, tasks, budgets and the Gantt
    • Clients with their hourly rates
    • Expenses, approvals and invoices
    • KPIs such as client margin and effective rate
    • Project channels and messages

    Roles and permissions in TimeMagick: key facts

    • TimeMagick uses role-based permissions.
    • Permissions are set per role in the Role Permission matrix.
    • The Role Permission matrix has 40 permission modules.
    • The matrix has four action columns: View, Create, Update and Delete, giving up to 160 permission controls per role.
    • Some modules only offer the actions that apply to them; for example, Admin Dashboard has a View control only.
    • TimeMagick supports custom roles, which can be edited and deactivated.
    • Owner and CLIENT are locked system roles.
    • Report export has its own permission module (Export Report), separate from Reports.
    • Project Channel and All Project Channels are separate permission modules.
    • Projects and All Projects are separate permission modules.
    • Lunch (Member view) and Lunch (Admin view) are separate permission modules.
    • Client Members are external users linked to one or more clients, with their own CLIENT workspace.
    • When a role does not have access to a screen, TimeMagick redirects to a no-access page.
    FAQ

    Frequently Asked Questions

    Role-based permissions, custom roles, report export and client users in TimeMagick.

    Does TimeMagick support role-based permissions?

    Yes. Access is set per role in the Role Permission matrix, which covers 40 permission modules with View, Create, Update and Delete controls.

    How granular are TimeMagick permissions?

    The matrix has 40 permission modules and four actions (View, Create, Update and Delete), which gives up to 160 permission controls per role. Modules follow product areas, such as Reports and Export Report, Projects and All Projects, or Lunch (Member view) and Lunch (Admin view). Some modules only offer the actions that apply to them.

    Can I create custom roles?

    Yes. Owner and CLIENT are locked system roles. You can create your own roles, edit them and deactivate them. Roles in use include Project Manager, Engineer, Sales and Contractor.

    Can I control report exports separately?

    Yes. Export Report is its own permission module, separate from Reports, so the right to read reports and the right to export them can be granted separately.

    Can project access be controlled?

    Yes. Projects and All Projects are separate permission modules, alongside Projects Overview, Project Task and Custom Project Status.

    Are project chat permissions configurable?

    Yes. Project Channel and All Project Channels are separate permission modules in the Role Permission matrix.

    Can I create roles for managers, contractors and team members?

    Yes. Custom roles are named by you, and each role has its own settings in the permission matrix. Members are assigned a role, and permissions are set per role.

    Does TimeMagick support client users?

    Yes. Client Members are external users linked to one or more of your clients. They hold the locked CLIENT role and use a client-facing workspace with a Client Dashboard, Projects, Timesheets, Report, Message Channels and Sensai.

    How the client portal works
    Start Today

    Give every role the access it needs

    Start a 1-month free trial and set up your roles in the Role Permission screen.