Guide
    Team Management

    Understand roles and permissions

    Learn how hierarchy roles, service roles, and individual permissions work together. This helps you give staff the right level of access to do their jobs without seeing sensitive information.

    5 min read
    Updated August 28, 2026

    This guide explains the different types of roles and permissions in AtomicSam. Understanding how they combine helps you control who can see and do what in your organization.

    Setting up roles correctly is key to your organization's security and efficiency. It ensures staff members can work on their assigned jobs while protecting sensitive client or financial data that isn't relevant to their work.

    Before you start

    • You must have Administrator permissions to manage roles and permissions for other staff members.

    Understand the types of roles

    You use a combination of two role types to define a staff member's position and capabilities. You can use our default roles or create your own.

    Role TypePurposeAssignmentExample
    Hierarchy RoleDefines a person's position in the company structure.You assign one role per staff member.Manager, Team Lead, Individual Contributor
    Service RoleDefines a person's skills or the services they provide.You can assign many roles per staff member.Designer, Plumber, Accountant

    Hierarchy roles are mainly used for reporting lines, approvals, and routing new jobs to the right team. Service roles are mainly used to assign specific tasks to people with the right skills.

    Assign roles and permissions

    You manage all access for a staff member from their profile.

    1. Navigate to Settings โ†’ Staff.
    2. Select the staff member you want to edit.
    3. Open the Roles & Permissions tab.
    4. In the Hierarchy Role section, select one role from the dropdown menu.
    5. In the Service Roles section, select all roles that match the staff member's skills.
    6. Review the Individual Permissions section to make any specific adjustments.
    7. Select Save.

    How access is calculated

    A staff member's total access is a combination of all their assigned roles and any individual permissions.

    Access is always additive. If any role or individual permission grants an ability, the staff member gets that ability. For example, if a staff member's Hierarchy Role does not allow them to create quotes, but one of their Service Roles does, they will be able to create quotes. The most permissive setting always wins.

    ๐Ÿ’ก Tip: Start with roles that grant the least amount of access needed for the job. Add individual permissions only when necessary for exceptions. This approach keeps your security model simple and easier to manage.

    Good to know

    • Individual permissions give granular control. They are useful for one-off exceptions where you need to grant a specific ability without creating an entirely new role. You might use this if a Team Lead needs to approve invoices for their team, which is not part of their standard role.
    • Contractors have limited visibility. When you create a staff member, you can set their employment type to Contractor. By default, contractors can only see jobs and tasks they are explicitly assigned to, regardless of their other roles or permissions.
    • You can create custom roles. If the default roles do not fit your organization, you can create new ones. Go to Settings โ†’ Roles & Permissions to build custom Hierarchy and Service roles that match your business structure.

    โš ๏ธ Heads up: The ability to see job costs, staff rates, and profit margins is controlled by a specific permission. Access to this financial data is never granted by default, even to managers. You must explicitly grant the See Rates and Margins permission to a role or an individual staff member.

    What's next