What an assistant is allowed to change
Reading, writing and administration are separate permissions. Work that touches a priced or client-facing document waits in an approval queue.
Permissions are granted separately when you authorise the assistant. Reading is one permission; writing is another. An assistant granted reading cannot write, whatever it is asked to do.
Commercially sensitive reading — invoices and the final account — is a further permission again, and only owners and administrators can grant it.
Your own role still applies on top. An assistant cannot do anything you could not do yourself.
Your role is checked on every single call, against your live membership. If your role is changed or you are removed from the workspace, every assistant you connected reflects that on its next call. There is no window where an old permission still works.
Write operations are graded by consequence. Low-consequence work — creating a project, adding a CRM contact, adding a task — is applied straight away and recorded in the audit log like any other change.
Anything touching priced or client-facing work is queued instead. It appears in the agent inbox in the application, where you can see exactly what is proposed and approve or discard it.
The most consequential operations cannot be performed by an assistant at all. Issuing a document and certifying a valuation stay with a person.
Every call an assistant makes is recorded in the audit log against you, so the trail shows both that it was an assistant and who authorised it.
Fields
- Read
- View projects, estimates, takeoffs, programmes, CRM and reports.
- Example: Any role can grant this.
- Commercial read
- Additionally view invoices and the final account.
- Example: Owners and administrators only.
- Write
- Create and change records. Priced and client-facing work queues for approval.
- Example: Owners, administrators and members.
- Administration
- Read workspace settings and raise proposals.
- Example: Owners and administrators only.
Examples
Drafting bill lines
Ask an assistant to draft lines for a section and they arrive as a proposal in the agent inbox. Nothing enters the bill until you accept it there.
A colleague leaves
Remove them from the workspace and any assistant they connected stops working immediately. You do not need to hunt for their tokens.