← How To Guides
ClientManagerBlazor · Reference · extracted from source, not guessed

Admin Customization & Permissions

What an Administrator can change about how ClientManager looks and works for their business, and how roles decide what each person can see and do: the side menu, the tabs on each record, and specific buttons.

Two kinds of settings are covered here. Permissions decide what a given person may reach, based on their roles. Site customizations change the app for everyone at your site, whatever their role. The last section shows how the two work together.
Part 1 · Role-based access

1. How access works

Access is built from three pieces:

The rules are simple:

Staff logins only: roles apply to staff logins. Client Portal and Vendor Portal logins use the separate portal and can't open staff pages. If one tries, they see "This page is for staff only."

2. The Roles & Permissions screen

Where: Site Admin → Roles & Permissions. Only Administrators can use this screen. Anyone else who opens it sees "Only Administrators can manage roles and permissions."

Left column

Right side, for any role except Administrators

The Administrators role

You can't rename or deactivate the Administrators role. It already has access to everything, so its screen only shows the five items that even Administrators must be granted:

CheckboxWhat it opens
Query BuilderThe Query Builder page (side menu: Reports & Analysis).
Franchise DashboardThe Franchise Dashboard page (side menu: Reports & Analysis).
QuickBooks ActionsThe QuickBooks connection section at the top of the QuickBooks Actions page (side menu: Financials).
QuickBooks MappingThe QuickBooks Mapping tab on the QuickBooks Actions page.
QuickBooks SyncThe QuickBooks Sync tab on the QuickBooks Actions page.

If someone lacks one of these grants, the page or tab shows a message saying it needs an explicit grant, even for Administrators. The QuickBooks Actions menu entry appears when a person holds any of the three QuickBooks grants.

4. Tab access on records

The second block of checkboxes on the Roles screen has one group per record type, headed "Record tabs". A role only sees a tab it has been granted. Administrators see every tab.

RecordTabs you can grant, in default order
ProjectDashboard, Resources, Estimates, Proposals, Schedules, Notes, Communications, Invoices & Payments, Vendor Quotes & POs, Attachments, Addresses, Checklists, Custom Fields, Expenses, Warranty
PersonCustom Fields, Notes, Attachments, Relationships, Credentials, Work History, Education, Training, Skills, Languages, Military Service, Picture, Important Dates
EmployeeCustom Fields, Dependents, Important Dates, Leave Balances, Health Info, Benefits, Certifications & Degrees
CompanyContacts, Addresses, Notes, Communications, Custom Fields, Credentials, Accounts, Insurances, Attachments, Projects, Important Dates
LeadTasks, Notes, Communications, Custom Info, Opportunities
OpportunityNotes
AssetService History, Mileage, Insurance, Attachments
CampaignExpenses, Notes, Leads
CommunicationReplies, Attachments
Property (Real Estate)Projects, Contacts, History, Attachments, Notes, Custom Info

Employee tabs have one more check. Dependents, Important Dates, Leave Balances, Health Info, Benefits and Certifications & Degrees are employment details. A person only sees them when the record is their own, the employee is somewhere below them in the reporting chain, or they have HR Full Access (section 5). The same rule applies to the Org Structure panel on the employee form. On the Employees screen, only Administrators can open an existing employee record, and Administrators see every tab.

Records with no tab checkboxes, such as Service Requests, Timesheets and Cost Database items, follow page access only. If a role can open the page, it sees the whole record.

5. Special permissions and actions

SettingWhere you set itWhat it allows
Grant Client/Vendor Portal AccessRoles screen, last checkboxLetting clients and vendors in. It covers:
  • the Create Portal Access button on a Person.
  • the Is Client, Is Vendor and Can Access Project boxes on a Project's resources. These boxes decide which projects a portal login can see.
Without it, a role can still edit people and projects. The Person form shows "No portal access. Ask an administrator to set it up." instead of the button, and those three boxes are read-only.
HR Full Access (view all employees' employment details)Roles screen, checkbox above the portal oneLets a role see every employee's employment details and restricted tabs, not just its own and its reports' (see section 4).
Full access to Document LibraryRoles screen → New Role or Rename dialogPeople in this role see every Document Library entry, including ones restricted to a different role. They still need the Document Library side-menu grant to open the library.

6. Administrator-only and role-name checks

Some features don't use checkboxes. They check whether the person is an Administrator, or whether they have a role with a specific name.

Administrators only

FeatureWhat non-Administrators get
Roles & PermissionsA notice that only Administrators can manage roles.
Reference Admin: adding, editing, hiding lists and valuesView only: "editing reference lists requires the Administrator role."
Currency list (linked from Reference Admin)View only.
Leave Management → Leave TypesView only.
Leave Management → Leave ApprovalsAdministrators see every request. Others only see requests from employees who report directly to them.
Employee → Leave Balances → Grant / AdjustThe button is hidden.
Employees: opening an existing employee for editingNames are plain text, and the Edit button is hidden.
TimesheetsOthers only see and create their own timesheets. Only Administrators can edit someone else's timesheet, or Approve or Reject a submitted one.
Notification History: DeleteThe Delete button is hidden.

Checks by role name

These look for roles named exactly Staff or Terminators. Renaming those roles changes who passes.

Document Library entries

An entry can be restricted to one role. Only people in that role, or in a role with Full access to Document Library, can see it. For everyone else it doesn't appear in the list at all.

7. Giving people roles

Where: Site Admin → Site Settings → Users.

To see who has a particular role, select it on the Roles & Permissions screen and look at Users in selected Role.

Portal logins are different. A client or vendor gets a portal login from the Person record (Create Portal Access), not from this Users list. Staff roles don't apply to portal logins.
Part 2 · Site customizations

8. Site Settings, tab by tab

Where: Site Admin → Site Settings. Anyone whose role has the Site Settings grant can open it. Everything here applies to your whole site. The order of these tabs, and whether most of them show, can be changed with Tab Order.

TabWhat you can set, and what it affects
Site Info
  • Basics: Site Name (required), Site Organization, Primary Contact Email, Phone, Website.
  • Scheduling Default: Default Time Zone, Business Hours Start and End, and Business Days. Event Info uses these to set the time zone and limit which days and times can be picked.
  • Location Address and Billing Address.
  • Information Defaults:
    • Default Country pre-fills Country on every new Company, Person, Project, Property and Lead. It can still be changed on each record.
    • Default State Code.
    • Phone Number Format formats phone numbers, but only on records whose Country is USA or Canada. Leave it unset, or pick Free Text, to never format numbers.
  • Default Markups: Material, Labor, Sub and Equipment percentages.
  • Site Additional Info: Site EIN, Currency, Fiscal Start Month, Subscription Start, Subscription Expiration.
  • Audit Details: read only.
LogoUpload one image, any size. It is shown in the side menu and on generated documents, such as proposals and invoices. Delete Logo removes it. Save a Site Name on Site Info first.
Document Header/Footer

The header and footer added to every generated document. Each has Left, Center and Right boxes.

  • Header boxes can insert Logo, Name, Address, Email and Website.
  • Footer boxes can insert Name, Page # and Total Pages.
  • Reload Default resets a section to the default layout.

Reopening this tab always starts from the default layout. Save replaces what is live.

Integrations
  • Contact Emails: Alternate Contact Email, Notification Email.
  • Google API Keys: Google Maps API Key, Map API Key, Google Translate API Key, Translate API Key.
  • Twilio (SMS): Account SID, Auth Token.
  • Brevo (Email Marketing): API Key, used to sync Campaign recipients and track opens, clicks and bounces back to Leads. After you save a key, a Webhook URL appears for you to paste into Brevo.
  • Live Chat (Tawk.to): Property ID and Widget ID. When both are filled in, the chat widget shows for everyone at your site.
  • Leave Allotment Method: Lump Sum. Accrual is marked "Coming soon".

Key fields are masked and have a show/hide eye button.

PaymentsConnect a Stripe account so clients can pay invoices online from the Client Portal. It shows Connect your Stripe account, Onboarding incomplete with Continue Setup, or Connected with a masked account number. Connecting is optional.
Email SettingsA list of outgoing mail server settings. Each has a Description, SMTP Host, Port, User, Password and Enable SSL, and can be edited or deleted.
Custom FieldsThe values of your site's own custom fields, in four sections: Custom Text Fields, Custom Dates, Custom Checkboxes, Custom Choice Fields. The fields themselves are defined under Custom Fields → Site.
AttachmentsUpload site-wide files, with a Type, Description and Notes applied to each upload batch.
AcronymsA list of Acronyms, each with a Description.
Useful LinksLinks with a Description, URL and Notes.
Tax RatesTax rates with a Description, Rate (%) and Active flag.
Knowledge BaseYour own help articles, each with a Title, Category, Text, and an optional Link and Attachment.
Tab OrderSee section 10. This tab can never be hidden.
Side MenuSee section 9. This tab can never be hidden.
UsersSee section 7.
Org StructureBuild your company's structure as a tree, any number of levels deep. Use Add Root Node, or select a node and use Add Child, Rename, Move or Deactivate. Each node has a Level Name and a Description. Deactivating hides a node from pickers and grids. Employees or child nodes linked to it aren't changed.
NotificationsChoose which users are alerted when a client submits a Warranty Request or sends a Portal Message. If nobody is ticked for a category, every staff member is alerted.
Login HistorySign-in activity for your site, filtered by a date range. Four views: Login History (time, user, success, failure reason, IP address, location, logout time, browser), Access Count per user, By Region, and Login Map.

9. Side Menu (hide menu entries)

Where: Site Settings → Side Menu. Applies to every user at your site.

This is not a permission. Hiding an entry only removes it from the side menu. Someone whose role allows the page can still open it by its address. To actually stop people reaching a page, untick it for their role on Roles & Permissions.

10. Tab Order (reorder and hide tabs)

Where: Site Settings → Tab Order. Applies to every user at your site.

  1. Pick an Entity: Project, Person, Employee, Site Settings, Company, Lead, Opportunity, Asset, Campaign, Communication or Property.
  2. Order: drag tabs, or use the up and down arrow buttons. The first tab in the list is locked in place.
  3. Visible: untick a tab to hide it for everyone, such as Warranty on Project. The first tab can't be hidden. On Site Settings, Tab Order itself can't be hidden.
  4. Click Save.

A tab hidden here is hidden for every user, including Administrators, whatever their roles allow. A tab left visible here is then shown only to roles granted it (section 4).

11. Reference Admin (lookup lists)

Where: Reference Admin in the side menu. It lists the dropdown lists used across the app, on two tabs: Standard, and Extended (lists with extra fields such as rates or dates). Anyone with the Reference Admin grant can browse the lists. Only Administrators can change them.

12. Custom Fields

Where: Site Admin → Custom Fields, with one entry each for Company, Person, Employee, Project, Lead and Site. Each entry has its own role grant. Definitions apply to your whole site.

People fill in these fields on the record's Custom Fields (or Custom Info) tab, so that tab's grant and visibility decide who sees them.

13. Role Checklists and Current Users

Role Checklists

Where: Site Admin → Role Checklists. These are onboarding steps and ongoing duties assigned by role. Each checklist has a Checklist Name and a Role (the role can't be changed after saving). Every user with that role sees it on their own My Tasks page.

Current Users

Where: Site Admin → Current Users. Shows who is connected right now, when they connected, and for how long. Use Refresh to update it. Closing a tab removes that person from the list.

14. Personal preferences

These settings belong to each person. They don't affect anyone else, and an Administrator doesn't set them.

PreferenceWhereScope
Choose ColumnsProjects, Companies, People, Employees, Assets and Real Estate grids, the Estimate grids, and the Chart of Accounts gridSaved for that person, per grid. It picks which extra columns show and in what order.
Reset ColumnsGrids that have the buttonClears that person's saved column order and widths for that grid.
Collapse side menuThe chevron button at the top of the side menuRemembered in that browser.
My ProfileClick your picture in the top barThat person's own name, phone and other details.
Part 3 · Putting it together

15. How the layers stack

Side-menu entries

Tabs on a record

Buttons and actions

Worked example

Dana has two roles: Estimator and Users. The site's settings:

What Dana sees:

An Administrator at the same site would see every menu entry except Programs, and every Project tab except Warranty. They would still need explicit grants for Query Builder, Franchise Dashboard and the QuickBooks items.