LupinusBuildContact
← All guides
Guide 11 · Roles & Permissions

Controlling access across the company workspace

LupinusBuild uses role-aware permissions so financial, administrative, office, field, and read-only access can be separated across the company workspace.

Available roles

LupinusBuild currently defines six company roles. Each role is evaluated by the application before protected actions are made available.

Primary Admin

Executive-level access to company administration, team management, financials, and operational workflows.

CFO

Executive-level financial and operational access, including company, team, expense, and project-financial management.

Admin

Broad operational administration across customers, quotes, projects, tasks, files, and materials without executive financial access.

Manager

Operational management access for creating and editing customer, quote, project, task, file, and material workflows.

Field User

Field-oriented access for project viewing, task execution, file uploads, material activity, and project-status updates.

Viewer

Read-only access to supported company, customer, quote, project, and team information.

Executive access

Primary Admin and CFO are treated as executive-access roles. Executive access controls several higher-sensitivity areas of the workspace.

Company management
Team management
Financial visibility
Expense management
Project financial management
Executive quote financial metrics
Financial separation

Operational access does not automatically provide executive financial access. This allows project execution and sensitive financial information to be controlled separately.

Permission matrix

The following matrix reflects the current application permission rules.

CapabilityPrimary AdminCFOAdminManagerField UserViewer
Company managementYesYes————
Team managementYesYes————
View financialsYesYes————
Manage expensesYesYes————
Create / edit quotesYesYesYesYes——
Delete quotesYesYesYes———
Create / edit customersYesYesYesYes——
Delete customersYesYesYes———
Create / edit projectsYesYesYesYes——
Delete projectsYesYesYes———
Manage project financialsYesYes————
Create tasksYesYesYesYesYes—
Assign tasksYesYesYesYes——
Complete tasksYesYesYesYesYes—
Delete tasksYesYesYesYes——
Upload project filesYesYesYesYesYes—
Delete project filesYesYesYesYes——
Create materialsYesYesYesYesYes—
Edit / delete materialsYesYesYesYes——
Update material statusYesYesYesYesYes—
Update project statusYesYesYesYesYes—

Field User access

Field User is an operational role rather than a read-only role. Field Users can view customers, quotes, projects, and the team list while also participating in selected project workflows.

Create project tasks
Complete and reopen tasks
Upload project files
Create material records
Update material status
Update project status

Field Users cannot assign or delete tasks, delete project files, edit or delete materials, create or edit quotes, create or edit customers, or create or edit projects under the current permission rules.

Viewer access

Viewer is the application's view-only role.

Viewers can access supported customer, quote, project, and team information, but the operational create, edit, delete, status, upload, assignment, and completion permissions documented here are not granted to Viewer accounts.

Permission model

LupinusBuild evaluates individual capabilities instead of relying only on a broad role name. This is why actions such as creating a task, assigning a task, completing a task, and deleting a task can have different permission requirements.

The same principle applies to project files, materials, customer records, quotes, projects, company administration, and financial access.

Pilot permission model

LupinusBuild is currently in pilot. Roles and individual permissions may continue to evolve as the product expands to additional company workflows.

Continue with workspace administration
Administration →