Roles and Permissions
Access to the Rochele web app is controlled by roles and permissions. A role is a job title in the system (management, estimator, tradesperson and so on) that comes with a default set of permissions. Permissions are the individual switches (view quotes, manage invoices, head office chat) that actually unlock menus, pages and buttons. This page explains both and shows which menu items each role sees.
How roles and permissions work together
Section titled “How roles and permissions work together”- Every user is given one or more roles in User Management. Selecting a role gives the user that role’s default permissions.
- Permissions can then be adjusted per user. On the user’s record each role expands to show its permissions, and extra permissions can be ticked or unticked for that person alone. This is how, for example, an operations user is given access to the Message Centre or to invoices without becoming an accounts user.
- The default permissions for each role are edited in Role Management. Changing a role there changes what every new user with that role gets.
- The management role is the super administrator. It holds every permission and is the only role that can reset passwords, log in as other users or open the Log Viewer.
The roles
Section titled “The roles”| Role name in the system | Shown in the UI as | Who it is for | Where they mostly work |
|---|---|---|---|
| management | Management | Directors and senior managers. Full access to everything. | Web app |
| operations | Operations | Office staff who run quotes, jobs, scheduling, customers and tradespersons. | Web app |
| accounts | Accounts | Finance staff. Everything operations has, plus invoices, advances and MYOB. | Web app |
| estimator | Estimator | Sales estimators who visit properties and build quotes. | iPad app, web app for quotes and leads |
| supervisor | Project Manager | Project managers who supervise jobs on site, visit, report and rate tradespersons. Called Project Manager everywhere in the UI. | iPad app |
| contractor | Tradesperson | Head tradespersons (painters, plasterers, sanders, renderers, colour consultants and other trades) who are allocated sub jobs and paid by advances. | Tradesperson app and emailed job card pages |
| contractor_team_members | Team Members | Employees or helpers of a head tradesperson, invited from the tradesperson app. They clock in and out under the head tradesperson’s jobs. | Tradesperson app |
| vendor | Vendor | Paint and material suppliers who record materials bought against jobs. | Web app, Materials only |
| key account management | Key Account Management | Business development staff. Has no default permissions; grant what is needed per user. | Web app |
| metrics | Metrics | A role reserved for reporting access. Has no default permissions; grant what is needed per user. | Web app |
There is no separate “admin” role: management is the administrator. There is also no “customer” role. Customers never log in; they reach their proposal, timeline and feedback pages through emailed links protected by a one-time email code, and can only see their own quote. Tradespersons likewise receive job card links by email and use the tradesperson app rather than the office menus.
The permissions
Section titled “The permissions”Permissions are grouped here by what they unlock. Names are shown as they appear on the Role Management and User Management screens.
Access to the web app
Section titled “Access to the web app”| Permission | What it unlocks |
|---|---|
| view backend | Lets the user log in to the web app at all. Without it a login succeeds but there is nothing to see. Project managers do not have it by default and use the iPad instead. |
| view dashboard | Shows the graphs and tables on the Dashboard. |
Viewing menus
Section titled “Viewing menus”| Permission | Menus it shows |
|---|---|
| view customers | Dashboard, Operations, Leads, Pipeline and Customers. |
| view quotes | The Quotes group: Quotes, Medium Quotes, Large Quotes, Appointments, Create Quote. |
| view jobs | The Jobs group: Jobs, Planning Board, Accepted Jobs, Jobs Board, Part Paid, Part Paid / Advanced, Job Progress, Report Gallery, QBCC Payments. |
| view contractors | The Tradespersons group: Tradespersons, Team Members, Capabilities, Improvement Requests, Agreements. |
| head office chat | Message Centre (the office side of tradesperson chat). |
| view materials | Materials. |
| view invoices | The Invoices group: Invoices, Pending Invoices, Suggested Invoices, Scheduled Invoices. |
| view advances | The Advances group: Advances, Suggested Advances, Pending Advances, Advances Sent. |
| view settings | The KPI group (KPI, KPI Settings) and the Settings group, including Access (User Management, Role Management, iPad App Download). |
| view users | User Management and Role Management in the mobile header menu. |
| view quote templates | Settings > Entities (Visit Thresholds, Items, Items Colours, Sections, Scopes, Specifications, Safety Hazards, Professions, Thresholds, Skills, Sources, Capabilities, Variables, CC Emails, PM Zones, Estimator Zones, Dynamic Pricing). |
| view sub jobs, view line items | Viewing sub job and line item detail inside jobs and quotes. |
Doing things
Section titled “Doing things”| Permission | What it allows |
|---|---|
| manage quotes | Create, edit, duplicate and send quotes. |
| manage jobs, manage sub jobs | Edit jobs, change statuses, split and allocate sub jobs, use the planning board. |
| manage invoices | Approve, send and mark customer invoices paid. Also shows MYOB Settings. |
| manage advances | Approve and send tradesperson advances. Also shows MYOB Settings. |
| manage materials | Add and edit material records. Vendors can only edit their own. |
| manage users | Create and edit users, including tradespersons. |
| manage quote templates, manage templates, manage line items | Edit the entity lists that build quotes. |
| manage agreements | Create and publish tradesperson agreements. |
| assign quote | Assign or reassign a quote to an estimator. |
| assign job | Assign a job to a project manager (project managers have this so they can pick up jobs). |
| change project manager | Override the automatic project manager assignment on a job. |
| reassign visits | Move project manager visits between project managers. |
| assign task | Assign tasks to other users rather than only to yourself. |
| full kpi report access | See KPI and dashboard results for every estimator and project manager, not just your own. Without it, estimators and project managers only see themselves. |
| RoccoAI | Shows the support chat widget on every page. |
Dashboard graphs
Section titled “Dashboard graphs”Each graph on the Dashboard has its own permission so that different roles see different charts: view all quotes graph, view sales graph, view advances graph, view site inspections graph, view safety improvement requests graph, view workmanship improvement requests graph, view variations graph, view customer review graph, view contactor review graph, view marketing types graph, view quote conversion graph, view quotes sent graph, view booked appointments graph, view digital marketing graph, view forecast repayment plan cashflow graph, the jobs graphs (vew all consolidated jobs graph, vew all jobs size graph, vew all jobs by estimator graph, view all jobs by location, view all jobs by type, view subjobs profession graph) and the leads graphs (view all consolidated leads graph, view all leads by category graph, view all leads by location graph, view all leads by estimator graph). A few names carry typos (“vew”, “contactor”); they are the real permission names and work correctly.
By default estimators see the quotes, leads, jobs-by-type and review graphs; project managers see the advances, site inspection, improvement request, variation and review graphs (the role also holds the sales graph permission, but the project manager layout never shows the Sales graph); management sees everything.
Default permissions by role
Section titled “Default permissions by role”This is what each role gets out of the box. Individual users may have more or fewer.
| Permission | Management | Operations | Accounts | Estimator | Project Manager | Tradesperson | Vendor |
|---|---|---|---|---|---|---|---|
| view backend | Yes | Yes | Yes | Yes | No | Yes | Yes |
| view dashboard | Yes | Yes | Yes | Yes | No | Yes | No |
| view customers | Yes | Yes | Yes | No | No | No | No |
| view quotes / manage quotes | Yes | Yes | Yes | Yes | No | No | No |
| assign quote | Yes | No | No | Yes | No | No | No |
| view jobs / view sub jobs | Yes | Yes | Yes | No | No | Yes | No |
| manage jobs / manage sub jobs | Yes | Yes | Yes | No | No | No | No |
| assign job | Yes | No | No | No | Yes | No | No |
| view contractors | Yes | Yes | Yes | No | No | No | No |
| view materials / manage materials | Yes | Yes | Yes | No | No | No | Yes |
| view invoices / manage invoices | Yes | No | Yes | No | No | No | No |
| view advances / manage advances | Yes | No | Yes | No | No | No | No |
| view settings / view users / manage users | Yes | Yes | Yes | No | No | No | No |
| view quote templates / manage templates | Yes | Yes | Yes | No | No | No | No |
| manage agreements | Yes | No | No | No | No | No | No |
| head office chat | Yes | No | No | No | No | No | No |
| reassign visits | Yes | No | No | No | No | No | No |
| Dashboard graphs | All | None by default | None by default | Quotes, leads, jobs, reviews | Advances, inspections, improvement requests, variations, reviews (holds the sales graph permission but never sees Sales) | None | None |
Team Members, Key Account Management and Metrics start with no permissions.
Which roles see each menu item
Section titled “Which roles see each menu item”Based on the default permissions above. “Per user” means the item appears only if that permission has been granted to the person individually.
| Menu item | Needs | Management | Operations | Accounts | Estimator | Tradesperson | Vendor |
|---|---|---|---|---|---|---|---|
| Dashboard | view customers | Yes | Yes | Yes | No | No | No |
| Operations | view customers | Yes | Yes | Yes | No | No | No |
| Leads | view customers | Yes | Yes | Yes | No | No | No |
| Pipeline | view customers | Yes | Yes | Yes | No | No | No |
| Customers | view customers | Yes | Yes | Yes | No | No | No |
| Tasks | web app access | Yes | Yes | Yes | Yes | Yes | Yes |
| Quotes, Medium Quotes, Large Quotes, Appointments, Create Quote | view quotes | Yes | Yes | Yes | Yes | No | No |
| Jobs, Planning Board, Accepted Jobs, Jobs Board, Part Paid, Part Paid/Advanced, Job Progress, Report Gallery, QBCC Payments | view jobs | Yes | Yes | Yes | No | Yes | No |
| Project Manager Visits | view jobs plus the management or operations role | Yes | Yes | No | No | No | No |
| Tradespersons, Team Members, Capabilities, Improvement Requests, Agreements | view contractors | Yes | Yes | Yes | No | No | No |
| Message centre | head office chat | Yes | Per user | Per user | Per user | No | No |
| Materials | view materials | Yes | Yes | Yes | No | No | Yes |
| Invoices, Pending, Suggested, Scheduled Invoices | view invoices | Yes | No | Yes | No | No | No |
| Advances, Suggested, Pending, Advances Sent | view advances | Yes | No | Yes | No | No | No |
| KPI, KPI Settings | view settings | Yes | Yes | Yes | No | No | No |
| Settings > Access (User Management, Role Management, iPad App Download) | view settings | Yes | Yes | Yes | No | No | No |
| Settings > MYOB Settings | manage invoices or manage advances | Yes | No | Yes | No | No | No |
| Settings > Log Viewer | management role | Yes | No | No | No | No | No |
| Settings > Entities (all entity lists) | view quote templates | Yes | Yes | Yes | No | No | No |
A few things are decided by role rather than permission, whatever else the user has been granted:
- Project Manager Visits in the Jobs menu is only shown to users with the management or operations role.
- Reset Password and Login As on a user record and the Log Viewer are management only.
- Dashboard graphs are filtered to the logged-in person for anyone with the estimator or project manager role unless they also have full kpi report access.
- Materials: a vendor can only see and edit materials they supplied; management and accounts can enter any material value.
- Estimator colour, Project Manager rank and other role-specific fields on the user form only appear once the matching role is ticked.
Roles in the companion apps
Section titled “Roles in the companion apps”- The iPad app is used by estimators and project managers. It shows a Dashboard, Quotes (My, All, Medium, Large, Recent), Jobs, Leads, Visits, Tasks, Contractors and Search. Project managers get a PM Visits menu and the Messages screen instead of the estimator’s Visits list, and their menu is reordered so Jobs and Visits sit at the top. See iPad App.
- The Tradesperson app accepts users with the tradesperson or team member role. A head tradesperson sees their jobs, advances, materials, timesheets, agreements, capabilities and team; a team member sees the jobs they are on and their own timesheet. See Tradesperson App.
- Changing a user’s permissions in the web app takes effect on the iPad and tradesperson app at their next sync.
Tips and gotchas
Section titled “Tips and gotchas”- If a new office user logs in and sees only Tasks, they have web app access but no viewing permissions. Add the right role or permissions in User Management.
- If a project manager needs to look at the web app, give them view backend plus the specific view permissions they need. Do not add the operations role, or they will lose the project manager filtering on the dashboard.
- Giving someone the estimator role makes them appear in every estimator dropdown (appointments, quotes, KPIs, zones). Only use it for people who actually quote.
- head office chat is not part of the operations default. Grant it per user to the people who handle tradesperson messages.
- A user can hold several roles, for example estimator and Project Manager for someone who both quotes and project manages. The dashboard treats such a person as having full access to both sets of graphs for themselves.


