Help Article
Team Management
Understanding Permissions
Design permission sets that protect sensitive financial data while giving your team the access they need
5 min read
Updated August 28, 2026
Overview
AtomicSam uses a layered permission system: a Job Hierarchy determines your base access level, and optional Service Roles add specific capabilities.
Job Hierarchy (Mutually Exclusive)
Each user has exactly one role in the hierarchy:
| Role | Access Level |
|---|---|
| Owner | Full access to everything including billing and subscription |
| Admin | Full access except subscription management |
| Client Manager | Manages assigned clients and their jobs |
| Job Manager | Manages assigned jobs |
| Contributor | Logs time and views assigned work only |
| Contractor | External contributor with limited access |
Service Roles (Additive)
Service roles add specific capabilities on top of your hierarchy role:
- Finance — access to invoicing, billing exports, and financial reports
- Sales — access to quotes, proposals, and pipeline views
Permission Sets
For fine-grained control, you can create custom permission sets that toggle individual capabilities (e.g., "can see rates & margins", "can manage costs", "can void invoices").
- Go to Settings → Permissions.
- Create or edit a permission set.
- Toggle individual permissions on or off.
- Assign the permission set to users.
⚠️ Warning: Be careful with "See Rates & Margins" — this reveals financial data like staff cost rates and job margins. Only enable for trusted roles.