Launching August 2026Apply for beta access →Skip to content

Roles and access

APEX controls access by role. Every person in your Company account holds exactly one role, and that role decides what they can see and change. Partners (your outside AV integrators) do not hold a Company role at all; they sign in to a separate, scoped portal. See "Partners" below.

This page lists the six roles and the boundary of each. For step-by-step instructions on inviting users or changing a role, see the related how-to guides.

The six roles

Roles are listed from most to least access. Read "Can do" as the reach of the role and "Cannot do" as the hard limits the platform enforces, not just convention.

RoleCan doCannot do
OwnerEverything in the account, including user and role management, account settings, and billing or ownershipReach into any other Company's data
AdministratorFull workspace management, including the Administration area: invite users, manage non-owner roles, and change settingsChange the Owner, delete the account, or change billing or ownership
Project ManagerManage projects, tasks, plans and baselines, the team, visits, and equipment across the workspaceReach the Administration area (users, roles, account settings, billing)
Field OperationsField work and documentation on assigned projects: site visits, equipment updates, on-site statusThe Administration area, and work on projects they are not assigned to
AuditorRead-only oversight across the whole workspace, including projects, visits, reports, and licensesAny write action, and the Administration area
ViewerRead-only on the projects they are assigned toAny write action, and anything outside their assigned projects

NOTE

Owner and Administrator manage the workspace and can reach the Administration area. Project Manager and Field Operations are the working write roles but cannot reach Administration. Auditor and Viewer are read-only. The "view as" tool, available to owners and admins, lets a manager preview the product as a lower role to confirm what it can see.

How access is enforced

Role checks run on every request before APEX returns any data, so a role cannot reach a screen or an action outside its limits even by editing a URL. Two finer rules sit on top of the role:

  • Project assignment. Field Operations and Viewer are scoped to the projects they are assigned to. A workspace role and a project assignment are checked together, so a Viewer added to a project still cannot write to it.
  • Partner scope. Partner users are pinned to their own organization and to the specific projects they are invited to. A partner signed in for one Company cannot see another Company's data, even when the same partner works with both.

Choosing a role

Use this as a default mapping when you invite someone.

The personGive them
You, or a co-owner of the accountOwner
Runs the operation, manages users, partners, and settingsAdministrator
Manages projects, schedules, and the teamProject Manager
Does on-site work and field documentationField Operations
Needs read-only oversight across everything (compliance, leadership)Auditor
Stakeholder who only needs to view their projectsViewer

WARNING

The Owner role can change billing and delete the account. Grant it only to people who carry that responsibility. To move ownership, change the existing Owner's role rather than handing out a second Owner login.

Partners

Partners are outside AV integrators you invite to a project. They do not hold any of the six roles above. Instead, they sign in to the Partner portal, which shows only the projects, equipment, visits, and threads tied to the work you invited them to. They never see your full account. For what a partner can and cannot do inside a project, see the Partner portal reference.