ClientManagerBlazor · Reference · extracted from source, not guessed
Admin Customization & Permissions
What an Administrator can change about how ClientManager looks and works for their business, and how roles decide what each person can see and do: the side menu, the tabs on each record, and specific buttons.
Two kinds of settings are covered here.Permissions decide what a given person may reach, based on their roles. Site customizations change the app for everyone at your site, whatever their role. The last section shows how the two work together.
Part 1 · Role-based access
1. How access works
Access is built from three pieces:
Roles are named groups, such as "Estimator" or "Project Manager". Each site has its own roles.
Permissions are the things a role can be given: a side-menu page, a tab on a record, or a special action.
Grants connect the two. When you tick a box for a role, that role is granted that permission.
The rules are simple:
Nothing is allowed until it is granted. A new role starts with no access. If a box is not ticked, people in that role do not get it.
Roles add up. A person with more than one role gets everything any of their roles allows.
Administrators get everything, whatever is ticked. This means a mistake on the Roles screen can never lock the Administrators out. The few exceptions are listed in section 2.
Roles are deactivated, not deleted. You can only deactivate a role once nobody has it.
Changes apply right away for everyone with that role once you click Save.
Staff logins only: roles apply to staff logins. Client Portal and Vendor Portal logins use the separate portal and can't open staff pages. If one tries, they see "This page is for staff only."
2. The Roles & Permissions screen
Where:Site Admin → Roles & Permissions. Only Administrators can use this screen. Anyone else who opens it sees "Only Administrators can manage roles and permissions."
Left column
Roles: every active role at your site. The badge shows how many users have it. Click a role to load its settings.
New Role: opens a dialog with Role Name and Full access to Document Library (see section 5). A new role has no access until you tick boxes and save.
Users in selected Role: a read-only list of the people who have the selected role.
Right side, for any role except Administrators
Rename: opens the same dialog, where you can also change the Document Library option.
Deactivate: blocked while anyone still has the role. You'll see a message asking you to reassign those users under Site Settings → Users first.
Save: saves every checkbox below it.
Four groups of checkboxes, from top to bottom:
Side-menu pages, grouped by menu category (section 3).
Tabs on each type of record, one box per tab (section 4).
HR Full Access (view all employees' employment details) (section 5).
You can't rename or deactivate the Administrators role. It already has access to everything, so its screen only shows the five items that even Administrators must be granted:
Checkbox
What it opens
Query Builder
The Query Builder page (side menu: Reports & Analysis).
Franchise Dashboard
The Franchise Dashboard page (side menu: Reports & Analysis).
QuickBooks Actions
The QuickBooks connection section at the top of the QuickBooks Actions page (side menu: Financials).
QuickBooks Mapping
The QuickBooks Mapping tab on the QuickBooks Actions page.
QuickBooks Sync
The QuickBooks Sync tab on the QuickBooks Actions page.
If someone lacks one of these grants, the page or tab shows a message saying it needs an explicit grant, even for Administrators. The QuickBooks Actions menu entry appears when a person holds any of the three QuickBooks grants.
3. Side-menu access (full list)
These are all the side-menu checkboxes on the Roles screen, grouped as the screen groups them. For each item a role has:
Ticked: the item appears in the menu, and the page opens.
Not ticked: the item is left out of the menu. If the person types or bookmarks the page address, they see: "You don't have access to this page yet. If you need it, ask your site administrator to grant permission."
A menu group with no allowed items is hidden completely. The same rules apply to the category overview pages and to the More panel on phones.
Group on Roles screen
Checkbox
Where it appears
Project Management
Projects Dashboard
Side menu, Project Management
Project Management
Projects
Side menu, Project Management
Project Management
Service Requests
Side menu, Project Management
Project Management
Cost Database
Side menu, Project Management
My Tasks
My Tasks
The My Tasks button in the top bar (not a side-menu link). The page only opens for roles with this grant. New users are sent to My Tasks at every sign-in until they click "I'm all set", so give this to every role.
Customer Relationship
Companies
Side menu, Customer Relationship (this is also the home page)
Customer Relationship
People
Side menu, Customer Relationship
Customer Relationship
People Dashboard
The Customer Relationship overview page and the phone More panel (not a side-menu link)
Sales and Marketing
Leads
Side menu, Sales and Marketing
Sales and Marketing
Campaigns
Side menu, Sales and Marketing
Sales and Marketing
Opportunities
Side menu, Sales and Marketing
Sales and Marketing
Mailer Designer
Side menu, Sales and Marketing
Sales and Marketing
Service Catalog
Side menu, Sales and Marketing
Sales and Marketing
Programs
Side menu, Sales and Marketing
Human Resource
Employees
Side menu, Human Resource
Human Resource
Org Chart
Side menu, Human Resource
Human Resource
Reporting Chart
Side menu, Human Resource
Human Resource
Timesheets
Side menu, Human Resource
Human Resource
Expense Management
Side menu, Human Resource
Human Resource
Policy Library
Side menu, Human Resource
Human Resource
Leave Management
Side menu, Human Resource
Events
Event Info
Side menu, Events
Communications
Messages
Side menu, Communications
Communications
Communications
Side menu, Communications
Communications
Dates To Remember
Side menu, Utilities group
Asset Management
Assets
Side menu, Asset Management
Asset Management
Real Estate
Side menu, Asset Management
Financials
Journal Entries
Side menu, Financials
Financials
Chart of Accounts
Side menu, Financials
Financials
QuickBooks Actions
Side menu, Financials explicit grant
Utilities
Document Templates
Side menu, Utilities
Utilities
Document Library
Side menu, Utilities
Utilities
Data Import
Side menu, Utilities
Utilities
All Attachments
Side menu, Utilities
Utilities
Knowledge Base
Side menu, Utilities
Utilities
Notification History
Side menu, Utilities
Utilities
PDF Design & Fill
Side menu, Utilities
Utilities
PDF Toolkit
Side menu, Utilities
Utilities
Query Builder
Side menu, Reports & Analysis group explicit grant
Reports & Analysis
Reports
Side menu, Reports & Analysis
Reports & Analysis
Report Designer
Side menu, Reports & Analysis
Reports & Analysis
Cross-Tab Analysis
Side menu, Reports & Analysis
Reports & Analysis
Franchise Dashboard
Side menu, Reports & Analysis explicit grant
Reference Admin
Reference Admin
Side menu, a single Reference Admin link
Custom Fields
Company
Side menu, Site Admin → Custom Fields
Custom Fields
Person
Side menu, Site Admin → Custom Fields
Custom Fields
Employee
Side menu, Site Admin → Custom Fields
Custom Fields
Project
Side menu, Site Admin → Custom Fields
Custom Fields
Lead
Side menu, Site Admin → Custom Fields
Custom Fields
Site
Side menu, Site Admin → Custom Fields
Site Admin
Site Settings
Side menu, Site Admin
Site Admin
Current Users
Side menu, Site Admin
explicit grant marks the items that Administrators must also be granted (section 2). You grant them to other roles here in the same way.
Menu entries you don't grant
Roles & Permissions and Role Checklists appear under Site Admin for Administrators. They have no checkbox of their own.
The top bar's Help, Submit Ticket, SMS, Email and My Tasks buttons are always shown. The page behind each one still follows the grants above.
Treat Site Settings as an administrator-level grant. It opens every Site Settings tab, including Users, where logins and their roles are managed. Only give it to people you would trust with the whole site.
4. Tab access on records
The second block of checkboxes on the Roles screen has one group per record type, headed "Record tabs". A role only sees a tab it has been granted. Administrators see every tab.
The first tab is always shown. That is the record's own edit form, such as the Project or Company details.
A tab grant does not open the page. It only matters if the role can already reach that kind of record through its side-menu grant.
Tabs hidden with Tab Order stay hidden, even when a role is granted them (section 10).
Projects, Contacts, History, Attachments, Notes, Custom Info
Employee tabs have one more check. Dependents, Important Dates, Leave Balances, Health Info, Benefits and Certifications & Degrees are employment details. A person only sees them when the record is their own, the employee is somewhere below them in the reporting chain, or they have HR Full Access (section 5). The same rule applies to the Org Structure panel on the employee form. On the Employees screen, only Administrators can open an existing employee record, and Administrators see every tab.
Records with no tab checkboxes, such as Service Requests, Timesheets and Cost Database items, follow page access only. If a role can open the page, it sees the whole record.
5. Special permissions and actions
Setting
Where you set it
What it allows
Grant Client/Vendor Portal Access
Roles screen, last checkbox
Letting clients and vendors in. It covers:
the Create Portal Access button on a Person.
the Is Client, Is Vendor and Can Access Project boxes on a Project's resources. These boxes decide which projects a portal login can see.
Without it, a role can still edit people and projects. The Person form shows "No portal access. Ask an administrator to set it up." instead of the button, and those three boxes are read-only.
HR Full Access (view all employees' employment details)
Roles screen, checkbox above the portal one
Lets a role see every employee's employment details and restricted tabs, not just its own and its reports' (see section 4).
Full access to Document Library
Roles screen → New Role or Rename dialog
People in this role see every Document Library entry, including ones restricted to a different role. They still need the Document Library side-menu grant to open the library.
6. Administrator-only and role-name checks
Some features don't use checkboxes. They check whether the person is an Administrator, or whether they have a role with a specific name.
Administrators only
Feature
What non-Administrators get
Roles & Permissions
A notice that only Administrators can manage roles.
Reference Admin: adding, editing, hiding lists and values
View only: "editing reference lists requires the Administrator role."
Currency list (linked from Reference Admin)
View only.
Leave Management → Leave Types
View only.
Leave Management → Leave Approvals
Administrators see every request. Others only see requests from employees who report directly to them.
Employee → Leave Balances → Grant / Adjust
The button is hidden.
Employees: opening an existing employee for editing
Names are plain text, and the Edit button is hidden.
Timesheets
Others only see and create their own timesheets. Only Administrators can edit someone else's timesheet, or Approve or Reject a submitted one.
Notification History: Delete
The Delete button is hidden.
Checks by role name
These look for roles named exactly Staff or Terminators. Renaming those roles changes who passes.
Campaign expenses (Campaigns page): only Administrators, Staff or Terminators can add or edit expenses. Everyone else can view them.
Service Catalog: Delete: only Administrators, Staff or Terminators. Everyone else can view and edit, but not delete.
Document Library entries
An entry can be restricted to one role. Only people in that role, or in a role with Full access to Document Library, can see it. For everyone else it doesn't appear in the list at all.
7. Giving people roles
Where:Site Admin → Site Settings → Users.
The grid shows Username, Email, Mobile Phone, Roles, Active and the linked Employee.
New User (the + button): pick the Person, enter their Email (this is also their username), and optionally a Mobile Phone. Then tick any Roles. Active is ticked for you, and so is the role named "Users" if your site has one. The new person gets an email with a link to set their own password.
Edit: change email, phone, Active, and roles. Reset Password sets a new password, unless the login also signs in to other ClientManager sites. In that case only the owner can change it, using Forgot Password.
Tick as many roles as you need. Their access adds up (section 1).
To see who has a particular role, select it on the Roles & Permissions screen and look at Users in selected Role.
Portal logins are different. A client or vendor gets a portal login from the Person record (Create Portal Access), not from this Users list. Staff roles don't apply to portal logins.
Part 2 · Site customizations
8. Site Settings, tab by tab
Where:Site Admin → Site Settings. Anyone whose role has the Site Settings grant can open it. Everything here applies to your whole site. The order of these tabs, and whether most of them show, can be changed with Tab Order.
Tab
What you can set, and what it affects
Site Info
Basics: Site Name (required), Site Organization, Primary Contact Email, Phone, Website.
Scheduling Default: Default Time Zone, Business Hours Start and End, and Business Days. Event Info uses these to set the time zone and limit which days and times can be picked.
Location Address and Billing Address.
Information Defaults:
Default Country pre-fills Country on every new Company, Person, Project, Property and Lead. It can still be changed on each record.
Default State Code.
Phone Number Format formats phone numbers, but only on records whose Country is USA or Canada. Leave it unset, or pick Free Text, to never format numbers.
Default Markups: Material, Labor, Sub and Equipment percentages.
Site Additional Info: Site EIN, Currency, Fiscal Start Month, Subscription Start, Subscription Expiration.
Audit Details: read only.
Logo
Upload one image, any size. It is shown in the side menu and on generated documents, such as proposals and invoices. Delete Logo removes it. Save a Site Name on Site Info first.
Document Header/Footer
The header and footer added to every generated document. Each has Left, Center and Right boxes.
Header boxes can insert Logo, Name, Address, Email and Website.
Footer boxes can insert Name, Page # and Total Pages.
Reload Default resets a section to the default layout.
Reopening this tab always starts from the default layout. Save replaces what is live.
Google API Keys: Google Maps API Key, Map API Key, Google Translate API Key, Translate API Key.
Twilio (SMS): Account SID, Auth Token.
Brevo (Email Marketing): API Key, used to sync Campaign recipients and track opens, clicks and bounces back to Leads. After you save a key, a Webhook URL appears for you to paste into Brevo.
Live Chat (Tawk.to): Property ID and Widget ID. When both are filled in, the chat widget shows for everyone at your site.
Leave Allotment Method: Lump Sum. Accrual is marked "Coming soon".
Key fields are masked and have a show/hide eye button.
Payments
Connect a Stripe account so clients can pay invoices online from the Client Portal. It shows Connect your Stripe account, Onboarding incomplete with Continue Setup, or Connected with a masked account number. Connecting is optional.
Email Settings
A list of outgoing mail server settings. Each has a Description, SMTP Host, Port, User, Password and Enable SSL, and can be edited or deleted.
Custom Fields
The values of your site's own custom fields, in four sections: Custom Text Fields, Custom Dates, Custom Checkboxes, Custom Choice Fields. The fields themselves are defined under Custom Fields → Site.
Attachments
Upload site-wide files, with a Type, Description and Notes applied to each upload batch.
Acronyms
A list of Acronyms, each with a Description.
Useful Links
Links with a Description, URL and Notes.
Tax Rates
Tax rates with a Description, Rate (%) and Active flag.
Knowledge Base
Your own help articles, each with a Title, Category, Text, and an optional Link and Attachment.
Build your company's structure as a tree, any number of levels deep. Use Add Root Node, or select a node and use Add Child, Rename, Move or Deactivate. Each node has a Level Name and a Description. Deactivating hides a node from pickers and grids. Employees or child nodes linked to it aren't changed.
Notifications
Choose which users are alerted when a client submits a Warranty Request or sends a Portal Message. If nobody is ticked for a category, every staff member is alerted.
Login History
Sign-in activity for your site, filtered by a date range. Four views: Login History (time, user, success, failure reason, IP address, location, logout time, browser), Access Count per user, By Region, and Login Map.
9. Side Menu (hide menu entries)
Where:Site Settings → Side Menu. Applies to every user at your site.
Every menu entry has a checkbox, grouped like the real menu. Untick any area your business doesn't use, such as Programs or Real Estate, and click Save. The change appears after the page is refreshed.
Show All Again brings every entry back.
Site Settings is marked "(always shown)" and can't be unticked, so you can always get back to this screen.
This screen also covers the entries without role checkboxes: Roles & Permissions, Role Checklists, and one QuickBooks Actions entry for all three QuickBooks grants.
This is not a permission. Hiding an entry only removes it from the side menu. Someone whose role allows the page can still open it by its address. To actually stop people reaching a page, untick it for their role on Roles & Permissions.
10. Tab Order (reorder and hide tabs)
Where:Site Settings → Tab Order. Applies to every user at your site.
Pick an Entity: Project, Person, Employee, Site Settings, Company, Lead, Opportunity, Asset, Campaign, Communication or Property.
Order: drag tabs, or use the up and down arrow buttons. The first tab in the list is locked in place.
Visible: untick a tab to hide it for everyone, such as Warranty on Project. The first tab can't be hidden. On Site Settings, Tab Order itself can't be hidden.
Click Save.
A tab hidden here is hidden for every user, including Administrators, whatever their roles allow. A tab left visible here is then shown only to roles granted it (section 4).
11. Reference Admin (lookup lists)
Where:Reference Admin in the side menu. It lists the dropdown lists used across the app, on two tabs: Standard, and Extended (lists with extra fields such as rates or dates). Anyone with the Reference Admin grant can browse the lists. Only Administrators can change them.
Mine and Shared values. Each list mixes your site's own values (Mine) with shared defaults (Shared). You can add, edit and delete your own values. Shared values can't be edited.
Hide a shared value. Open a Shared value and click Hide. It disappears from your site's dropdowns and lists, and shows a Hidden badge in Reference Admin. Click Unhide to bring it back.
Allow inline quick-add from dropdowns elsewhere in the app. This per-list checkbox, with its own Save, decides whether people can add a new value straight from a dropdown.
Depending on the list, a value may also have a Display Order or a Color. Every value has an Active flag.
Separate pages: Leave Types are managed under Leave Management → Leave Types. Currency has its own page, linked from the bottom of Reference Admin.
12. Custom Fields
Where:Site Admin → Custom Fields, with one entry each for Company, Person, Employee, Project, Lead and Site. Each entry has its own role grant. Definitions apply to your whole site.
Company, Person, Employee, Project and Site each have four tabs: Text Fields, Date Fields, Checkbox Fields and Choice Fields. Lead has one list of Lead fields.
Each field has a Description, Display Order and Active flag. Most fields also have Required. Checkbox fields have Default Checked instead.
Choice fields have an Options button, where you can add options and turn them on or off.
Project fields only:Limit to Project Category shows the field only on projects in that category, such as Construction & Remodeling. Leave it blank to show the field on every project. A category covers every Project Type within it.
People fill in these fields on the record's Custom Fields (or Custom Info) tab, so that tab's grant and visibility decide who sees them.
13. Role Checklists and Current Users
Role Checklists
Where:Site Admin → Role Checklists. These are onboarding steps and ongoing duties assigned by role. Each checklist has a Checklist Name and a Role (the role can't be changed after saving). Every user with that role sees it on their own My Tasks page.
Current Users
Where:Site Admin → Current Users. Shows who is connected right now, when they connected, and for how long. Use Refresh to update it. Closing a tab removes that person from the list.
14. Personal preferences
These settings belong to each person. They don't affect anyone else, and an Administrator doesn't set them.
Preference
Where
Scope
Choose Columns
Projects, Companies, People, Employees, Assets and Real Estate grids, the Estimate grids, and the Chart of Accounts grid
Saved for that person, per grid. It picks which extra columns show and in what order.
Reset Columns
Grids that have the button
Clears that person's saved column order and widths for that grid.
Collapse side menu
The chevron button at the top of the side menu
Remembered in that browser.
My Profile
Click your picture in the top bar
That person's own name, phone and other details.
Part 3 · Putting it together
15. How the layers stack
Side-menu entries
Site Side Menu setting. If the entry is unticked under Site Settings → Side Menu, nobody sees it in the menu. This check comes first.
Role grant. Otherwise, the entry shows if the person is an Administrator or any of their roles is granted it. For Query Builder, Franchise Dashboard and QuickBooks Actions, an explicit grant is required even for Administrators.
Opening the page directly. Only the role grant counts here, not the Side Menu setting. A person without the grant sees "You don't have access to this page yet."
Tabs on a record
Page access. The person must be able to open that kind of record at all.
Tab Order visibility. A tab hidden there is gone for everyone, including Administrators.
Tab grant. The tab shows if the person is an Administrator or one of their roles is granted it. The first tab always shows.
Employee details rule. On Employee records, the restricted tabs also need the record to be the person's own or a report's, or the person needs HR Full Access.
Buttons and actions
Special permissions (portal access, HR Full Access, Document Library full access) come from the role settings in section 5. Administrators always have the first two.
Administrator-only and role-name checks (section 6) apply on top. Grants can't change them.
Personal preferences (section 14) only change how grids look for that one person. They never add or remove access.
Worked example
Dana has two roles: Estimator and Users. The site's settings:
Estimator is granted Projects, plus the Project tabs Dashboard, Estimates, Notes and Warranty.
Users is granted Companies, People and My Tasks.
Under Site Settings → Side Menu, the Administrator unticked Programs. Under Tab Order, they hid Warranty on Project.
What Dana sees:
Side menu: Projects (from Estimator), Companies and People (from Users). Programs would be hidden anyway, but Dana was never granted it. Leads isn't granted, so opening its address shows "You don't have access to this page yet."
A Project: the Project form, then Dashboard, Estimates and Notes. Warranty is granted but hidden by Tab Order, so it doesn't show. Resources, Invoices & Payments and the other tabs aren't granted, so they don't show either.
Project resources: neither role has Grant Client/Vendor Portal Access, so Is Client, Is Vendor and Can Access Project are read-only.
Grids: Dana's Choose Columns picks on Projects apply only to Dana.
An Administrator at the same site would see every menu entry except Programs, and every Project tab except Warranty. They would still need explicit grants for Query Builder, Franchise Dashboard and the QuickBooks items.