Help Article
    Team Management

    Understanding Permissions

    Design permission sets that protect sensitive financial data while giving your team the access they need

    5 min read
    Updated August 28, 2026

    Overview

    AtomicSam uses a layered permission system: a Job Hierarchy determines your base access level, and optional Service Roles add specific capabilities.

    Job Hierarchy (Mutually Exclusive)

    Each user has exactly one role in the hierarchy:

    RoleAccess Level
    OwnerFull access to everything including billing and subscription
    AdminFull access except subscription management
    Client ManagerManages assigned clients and their jobs
    Job ManagerManages assigned jobs
    ContributorLogs time and views assigned work only
    ContractorExternal contributor with limited access

    Service Roles (Additive)

    Service roles add specific capabilities on top of your hierarchy role:

    • Finance — access to invoicing, billing exports, and financial reports
    • Sales — access to quotes, proposals, and pipeline views

    Permission Sets

    For fine-grained control, you can create custom permission sets that toggle individual capabilities (e.g., "can see rates & margins", "can manage costs", "can void invoices").

    1. Go to Settings → Permissions.
    2. Create or edit a permission set.
    3. Toggle individual permissions on or off.
    4. Assign the permission set to users.
    ⚠️ Warning: Be careful with "See Rates & Margins" — this reveals financial data like staff cost rates and job margins. Only enable for trusted roles.