Administration  ·  Reference

User Rights Reference — Every Permission Explained

Standard Time® controls employee access with two independent settings: the Admin checkbox, and a Rights popup with roughly 40 individual permissions. This page explains every right in that popup, why administrators see more of them than everyone else, and how to open the popup for any employee.


What Are User Rights?

The Admin checkbox on the Users page is a coarse, all-or-nothing switch — an administrator can see and edit essentially everything, while a regular employee cannot. User Rights are a much finer-grained layer underneath that switch: roughly 40 individual permissions that control one specific capability each, from "can this person see client billing rates" to "can this person log time without picking a project." Rights are set independently of the Admin checkbox, so you can give a non-administrator selective access to a handful of features, or restrict an administrator's view down to just the modules they need.

Every employee's Rights are opened the same way: from their Properties panel, under User Experience > Rights. See Opening the Rights Popup below for the exact click path, or the User Setup Guide for how this fits into onboarding a new employee.

User Rights popup showing a checkbox list of individual feature permissions an employee can be granted or denied

Admin Status vs. User Rights

The Rights popup adapts to who it's being opened for. Every time it opens for a given employee, Standard Time® checks whether the account being edited is an administrator or a workgroup, and only then adds a block of seven additional "Administrative rights" checkboxes to the top of the list. Non-admin employees never see those seven items at all — the checkboxes are not merely grayed out, they are absent from the popup entirely. Every other right in the list — the base set of roughly 33 — is offered to every employee, admin or not.

Flowchart: Standard Time checks whether the account is an Administrator or Workgroup; if yes, 7 extra administrative rights are added on top of the base 33-right list; if no, only the base list is shown
The Administrative rights property shows more rights for admins than for non-admins — the extra block only gets added when the account being edited is an Administrator or a Workgroup.
Two extra exceptions to know about: Two of the seven administrative rights — Administer users and Administer projects, clients, etc. — are hidden even from an administrator when they are viewing their own account's Rights popup, to prevent an admin from accidentally locking themselves out. They only appear when an admin is editing a different admin's account. Likewise, Superuser access is not offered when you are setting rights on a workgroup, since a workgroup itself cannot act as a Superuser — only an individual user account can.
"Project Management Only" (PMO) can hide rights too. A separate restriction, unrelated to admin status, removes several rights from every user's list when your account has "Project Management Only" mode enabled: Access to Expenses, Access to Invoicing, Access to Inventory, Access to Time Off, Access to Work Orders, Access to stock reports, Can view timesheet approvals, Can bypass locks, and Can add expenses with no accounts. If any of these are missing from your Rights popup, PMO mode is the likely reason.

Workgroup Rights Cascade to Every User Below

Everything above describes rights on an individual user. But workgroups — including the top-level enterprise (company) row at the very top of the Users tree — have their own Rights popup too, opened the exact same way. This is one of the most powerful, and most easily overlooked, controls in the whole program: a right that is unchecked at a workgroup automatically overrides that same right for every user and every nested workgroup beneath it, no matter how each individual account is configured.

Standard Time®'s HasRight() check walks up the tree from the user to their workgroup, to that workgroup's parent, and so on up to the enterprise row. If any ancestor has the right turned off, the check returns "no" — a user's own checkbox can never override a "no" set higher up the tree. The reverse is not true: an individual user can still be denied a right their workgroup allows, simply by unchecking it on their own account.

Diagram showing a right unchecked at the Company (enterprise) level flowing down through Production workgroup and Machining sub-workgroup to a user, overriding that user's own checkbox which is still checked — the user ends up without the right
A right turned off at any level of the tree — including the top-level Company row — silently overrides that same right for every workgroup and user beneath it, even if their own checkbox is still checked.
Practical power move: Need to disable a right for your entire organization in one click — say, Access to Invoicing, or Can view salary rates and costs — without touching a single individual user account? Open the Rights popup on the top-level enterprise (company) row and uncheck it there. It instantly applies to every workgroup and every user underneath, company-wide.
Caution — this is also the most common cause of "why can't this one admin see X" tickets. If an individual user's Rights popup shows a box checked, but they still can't access that feature, check the Rights on their workgroup — and that workgroup's parent, all the way up to the enterprise row. One of them almost certainly has the right unchecked. Un-checking at a parent silently wins over a child's own setting.

Administrator-Only Rights

The 40 rights in the popup break down into seven categories. The next several sections work through each one, starting with the seven that only appear for administrators and workgroups.

Category map showing the 40 User Rights grouped into 7 categories: Administrator-Only (7 rights, red, admins and workgroups only), Access (9), Entry Shortcuts (6), Task and Log Editing (6), Rates and Billing (4), Entry Dates and Notes (3), and Account and Session (5)
The seven categories covered on this page, and how many rights fall into each one.

These first seven rights only appear in the Rights popup when the account being edited is an administrator or a workgroup. They govern the highest-impact capabilities in the program — managing other users, managing projects and clients, and bypassing normal safeguards.

RightAdmin OnlyWhat It Controls
Superuser accessAdminAdmin rights, and access to all items, even if not assigned. A Superuser sees every project in the system, not just the ones they are individually assigned to.
Administer usersAdminView a list of employees who can access the program or scan barcodes. Hidden from an admin's own Rights popup — only visible when editing another admin's account.
Administer projects, clients, etc.AdminCreate new projects, clients, and other items that control how employees use the program. Also hidden from an admin's own Rights popup.
Administer reportsAdminModify and create new custom reports.
Can view timesheet approvalsAdminApprove timesheets containing time and materials for other employees.
Can bypass locksAdminAllow the user to dismiss warnings about locked records such as time and expenses.
Can import and exportAdminBring in new records from external systems, and export data to other systems.

Access Rights

These rights simply turn entire pages or features on or off for an employee. Uncheck a right and the corresponding page disappears from that employee's view — this is the fastest way to strip a shop floor login down to just the icons a worker actually needs.

RightAdmin OnlyWhat It Controls
Access to Project TasksView a list of project tasks for the purpose of editing.
Access to TimesheetView the timesheet for entering hours.
Access to Time LogsView the time log for entering hours.
Access to ExpensesView the list of expenses for entering new items.
Access to InvoicingView and create client invoices.
Access to Time OffDisplay the Time Off view, and allow the user to enter Time Off requests.
Access to InventoryView inventory for managing materials.
Access to stock reportsRun the built-in reports that are installed with the program.
Access to AIAllow AI chat and AI updates to projects and tasks.
Related reference: Home Screen Icons — Every Icon Explained shows exactly which Home screen icon each Access right unlocks, plus which icons require Admin status on top of a right.

Time & Expense Entry Shortcuts

By default, Standard Time® expects a time log or expense to reference a project, subproject, task, client, and category. These six rights loosen that requirement field by field, so an employee can log time or expenses faster without picking every classification — useful for miscellaneous or overhead time that doesn't map cleanly to a specific job.

RightAdmin OnlyWhat It Controls
Can log time with no projectCan enter hours or scan jobs without a project.
Can log time with no subprojectCan enter hours or scan jobs without a subproject.
Can log time with no project taskCan enter hours or scan jobs without a project task.
Can log time with no clientCan enter hours or scan jobs that do not have a client associated with it.
Can log time with no categoryCan enter hours or scan jobs without a category.
Can add expenses with no accountsCan enter expense records without an account associated with it.

Task & Time Log Editing Rights

These rights control who can create or modify the underlying records — project tasks and time logs — once access to those pages is already granted by an Access right above.

RightAdmin OnlyWhat It Controls
Can create new project tasksAbility to create new project tasks that can be scanned or displayed in the timesheet.
Can edit project tasksAbility to edit existing project tasks.
Can delete project tasksAbility to delete existing project tasks.
Can mark tasks as completeMark or scan barcode completions for project tasks.
Can edit time logsAbility to edit time logs.
Can edit time logs datesAbility to edit time log dates.

Rates & Billing Rights

These rights control visibility into pay-sensitive numbers and the billable/billed flags used when invoicing clients.

RightAdmin OnlyWhat It Controls
Can view salary rates and costsDisplay salary rates in the program.
Can view client rates and costsDisplay client rates in the program.
Enable Billable option for time and expensesAllow the employee to check and uncheck billable options.
Enable Billed option for time and expensesAllow the employee to check and uncheck billed options.
Tip: Most shops leave Can view salary rates and costs unchecked for everyone except payroll and management — salary figures are the single most sensitive number in the system.

Entry Dates & Notes Rights

These rights govern when an employee is allowed to log time relative to today's date, and whether a note is required to justify a change.

RightAdmin OnlyWhat It Controls
Can enter time and expenses into today or past datesAllow the user to enter new records into the past.
Can enter time and expenses into today or future datesAllow the user to enter new records into the future.
Modify time without requiring special notesDo not require special notes for each change to time and expense records.

Account & Session Rights

These rights control login behavior and convenience settings for the employee's own account.

RightAdmin OnlyWhat It Controls
Can change passwordAllow the employee to change their own password.
Can change pay typeAllow the user to change the pay type for time log records.
Automatically log in each time program starts upOpen the program without asking for login information (remembers the last login).
Keep pages opened between loginsRemember which pages were opened from the last login.
Stay logged in, no session timeoutRemain logged in indefinitely without the session timing out.
Shared scan stations: Consider unchecking Can change password for any shared login used at a shop floor scan station — see Shop Floor Logins in the User Setup Guide for the full pattern.

Opening the Rights Popup

Every right on this page lives in the same place, regardless of which employee you're editing.

Five-step flow: Open Users, click the employee row, Properties panel opens, scroll to User Experience, click Rights to open the checkbox popup
The full click path from the Users page to the Rights checkbox popup for any employee.
Steps to open a user's Rights:
  1. Open Home > Users.
  2. Click the employee row to open the Properties panel on the right.
  3. Scroll down to the User Experience section.
  4. Click the Rights property. A popup checkbox list opens.
  5. Check or uncheck individual rights to control exactly what this employee can access.
  6. Close the popup — changes are applied immediately, no save button required.
User Rights popup showing a checkbox list of individual feature permissions an employee can be granted or denied

Remember: which checkboxes appear depends on whether the employee you're editing is an administrator or a workgroup — see Admin Status vs. User Rights above. This same click path also opens Rights on a workgroup row, including the top-level enterprise (company) row — see Workgroup Rights Cascade to Every User Below for why that's worth knowing.


Practical Rights Combinations

Most shops don't configure all 40 rights individually for every employee — they settle on a handful of role-based patterns and reuse them. A few common starting points:

RoleAdmin CheckboxTypical Rights
Shop floor workerOffOnly the Access rights needed to scan and see their own hours (typically just Access to Time Logs, if any). All other Access rights unchecked so the Home page shows only Scan Barcodes.
Team leadOffAccess to Time Logs and Access to Project Tasks for their workgroup, plus Can edit time logs to make corrections. Can view timesheet approvals is Administrator-Only — leads who approve timesheets need Admin checked instead.
Project managerAdminFull Access rights, Can create/edit/delete project tasks, Can view client rates and costs, and Can view timesheet approvals. Usually without Superuser access unless they must see unassigned projects.
Plant manager / ownerAdminAll rights checked, including Superuser access, Administer users, and Administer projects, clients, etc.
Tip: Grant the seven Administrator-Only rights sparingly, even to admins. Administer users and Administer projects, clients, etc. in particular let a person reshape how everyone else uses the program — reserve those for a small group of trusted managers.

Setting up rights per employee works well for a handful of exceptions. For a rule that should apply to a whole department or the whole company, set it once on the workgroup instead — see Workgroup Rights Cascade to Every User Below.

Related articles and FAQ:

Back to Learning Center

Ready to Fine-Tune Employee Access?

Start a free 30-day trial and set up exactly the right permissions for every role on your shop floor.

View Pricing Contact Us