Roles and access
APEX controls access by role. Every person in your Company account holds exactly one role, and that role decides what they can see and change. Partners (your outside AV integrators) do not hold a Company role at all; they sign in to a separate, scoped portal. See "Partners" below.
This page lists the six roles and the boundary of each. For step-by-step instructions on inviting users or changing a role, see the related how-to guides.
The six roles
Roles are listed from most to least access. Read "Can do" as the reach of the role and "Cannot do" as the hard limits the platform enforces, not just convention.
| Role | Can do | Cannot do |
|---|---|---|
| Owner | Everything in the account, including user and role management, account settings, and billing or ownership | Reach into any other Company's data |
| Administrator | Full workspace management, including the Administration area: invite users, manage non-owner roles, and change settings | Change the Owner, delete the account, or change billing or ownership |
| Project Manager | Manage projects, tasks, plans and baselines, the team, visits, and equipment across the workspace | Reach the Administration area (users, roles, account settings, billing) |
| Field Operations | Field work and documentation on assigned projects: site visits, equipment updates, on-site status | The Administration area, and work on projects they are not assigned to |
| Auditor | Read-only oversight across the whole workspace, including projects, visits, reports, and licenses | Any write action, and the Administration area |
| Viewer | Read-only on the projects they are assigned to | Any write action, and anything outside their assigned projects |
NOTE
Owner and Administrator manage the workspace and can reach the Administration area. Project Manager and Field Operations are the working write roles but cannot reach Administration. Auditor and Viewer are read-only. The "view as" tool, available to owners and admins, lets a manager preview the product as a lower role to confirm what it can see.
How access is enforced
Role checks run on every request before APEX returns any data, so a role cannot reach a screen or an action outside its limits even by editing a URL. Two finer rules sit on top of the role:
- Project assignment. Field Operations and Viewer are scoped to the projects they are assigned to. A workspace role and a project assignment are checked together, so a Viewer added to a project still cannot write to it.
- Partner scope. Partner users are pinned to their own organization and to the specific projects they are invited to. A partner signed in for one Company cannot see another Company's data, even when the same partner works with both.
Choosing a role
Use this as a default mapping when you invite someone.
| The person | Give them |
|---|---|
| You, or a co-owner of the account | Owner |
| Runs the operation, manages users, partners, and settings | Administrator |
| Manages projects, schedules, and the team | Project Manager |
| Does on-site work and field documentation | Field Operations |
| Needs read-only oversight across everything (compliance, leadership) | Auditor |
| Stakeholder who only needs to view their projects | Viewer |
WARNING
The Owner role can change billing and delete the account. Grant it only to people who carry that responsibility. To move ownership, change the existing Owner's role rather than handing out a second Owner login.
Partners
Partners are outside AV integrators you invite to a project. They do not hold any of the six roles above. Instead, they sign in to the Partner portal, which shows only the projects, equipment, visits, and threads tied to the work you invited them to. They never see your full account. For what a partner can and cannot do inside a project, see the Partner portal reference.