Roles and permissions
UI: Workplace Settings → Workplace Permissions / Project Permissions
Audience: workplace administrators, project managers, and access configuration owners
What are roles and permissions
A role is a set of permissions assigned to a user. In BIMWorkplace, there are two independent contexts:
| Context | What it controls | Assignment |
|---|---|---|
| Workplace role | Workplace administration and common resources: users, projects, billing, settings, credits, and cost catalog. | Every active workplace member has a workplace role. |
| Project role | What the member can see or manage within a project: settings, models, Explorer, Design, CDE, Build, Management, and Insights. | The same user can have a different project role in each project. |
A project role does not replace or override the workplace role. Both are evaluated in their respective contexts. For example, a user can administer a project without being able to manage billing or workplace users.
Types of roles
The backend authorization contract recognizes four technical types:
| Type | Context | Meaning |
|---|---|---|
| Workplace Admin | Workplace | Workplace administration. |
| Project Admin | Project | Project administration; this is the type used by the Project Manager role provided by the platform. |
| User | Both | Normal user; access depends on the values defined in the matrix. |
| Guest | Both | Guest user, with limited access. Some features apply additional restrictions to guests. |
In the interface, roles can also be:
- Default / Standard: provided by the platform. They are shown as locked and cannot be edited or deleted by the workplace.
- Custom: created in the workplace. They can be renamed and have their matrix changed.
- Project Manager role: a project role marked with a crown. Only one project role definition in the workplace can be marked as Project Manager at a time.
When creating a custom role, the backend initially copies the permissions of the active default role of type User. The administrator must then review the matrix before assigning the role.
A custom role can only be deleted when it is no longer assigned to any users.
Matrix levels
The Workplace Permissions and Project Permissions matrices use three editable levels:
| Level | Value | General effect |
|---|---|---|
| None | 0 | Does not grant the capability. The section or action may be hidden or blocked. |
| Read | 1 | Allows viewing, when the functionality supports read mode. It does not, by itself, authorize creation, editing, or deletion. |
| Total | 9 | Allows managing the capability, including changes authorized by the API. |
| Several | — | Not a saved level. Appears only in a group row when child permissions have different levels. |
Not all permissions accept all three levels. Some offer only None/Total or None/Read, because the operation is exclusively management-oriented or exclusively view-oriented.
The backend also has more granular levels used in object permissions, such as Read + Download, Upload, Edit, and Full Administrative Control. These levels are not choices in the role matrix.
Workplace Permissions
The workplace matrix currently presents the following permissions:
| Permission | What it controls | Available levels |
|---|---|---|
| Workplace billing | Billing inquiry, prices, invoices, and plan management. | None · Read · Total |
| Workplace profile | Viewing and editing general workplace information. | None · Read · Total |
| Workplace projects | List and management of workplace projects. | None · Read · Total |
| Users and companies | Users, invitations, companies, and their management. | None · Read · Total |
| Roles and permissions | Access to matrices and management of workplace and project roles. | None · Read · Total |
| Workplace settings | Common settings, units, and templates. | None · Read · Total |
| Workplace attributes | Workplace attribute library. | None · Read · Total |
| Credits and usage | Balances, history, and credit allocations. | None · Read · Total |
| AI Pool – grants | Granting or revoking the use of the shared AI Pool. | None · Total |
| Subscription | Viewing and managing the subscription and modules. | None · Read · Total |
| Cost catalog – view | Viewing the common workplace cost catalog. | None · Read |
| Cost catalog – edit | Management of price databases, resources, compositions, and units. | None · Total |
Who can manage roles
The Workplace Permissions section is controlled by the Roles and permissions permission:
- None: the section is not available;
- Read: allows viewing roles and levels, without alteration;
- Total: allows creating, editing, and deleting custom roles and changing the matrix.
Project Permissions
Project roles are configured at the workplace level and then assigned to members of each project. The matrix only displays permissions with actual application in the project context; internal, legacy, or mechanism-controlled permissions are hidden.
Project administration
| Permission | What it controls |
|---|---|
| Project profile | General information and project management. |
| Members and teams | Viewing and managing members and teams. |
| Project units | Configuration of measurement units. |
| Project attributes | Project attribute library. |
| Naming conventions | Creation and management of naming conventions. |
| CDE configuration | CDE configuration, document statuses, and transitions. |
| Approval workflows | Templates and steps for approval workflows. |
Models and viewer
| Permission | What it controls |
|---|---|
| Model management | Management of project models. |
| Model properties and permissions | Model properties and their access rules. |
| Object colors | Viewing color schemes and data. |
| Object colors – manage | Creation and editing of project color schemes. |
| Explorer model management | Model management actions in Explorer. |
| Active Design model | Management of the active model in Design. |
| Active Build model | Management of the active model in Build. |
Explorer
| Permission | What it controls |
|---|---|
| Explorer views | Opening views and, with Total, creating, editing, deleting, and sharing views. |
| Explorer view groups | Viewing and managing Explorer information groups. |
Design
| Permission | What it controls |
|---|---|
| Design topics | Navigation and management of Design topics. |
| Geometry verification | Clash tests, matrices, folders, and results. |
| Property verification | IDS library, specifications, and results. |
| Requirements verification | Rulesets, rules, and Requirements Check results. |
| Design exports | Export of Design reports. |
| Public topics | Access to the public scope of topics. |
| Private topics | Access to the private scope of topics. |
| Closed topics | Access to closed topics. |
CDE
| Permission | What it controls |
|---|---|
| CDE access | Entry into the CDE module. File and folder read/write access still depends on specific folder permissions. |
Build
| Permission | What it controls |
|---|---|
| Cost management – access | Entry into budgeting and cost control functionalities. |
| Cost management – edit | Editing budgets, BoQ, and cost structures. |
| Cost management – approve | Approval or rejection of budget versions. |
| Cost management – commercial | Viewing sales prices and margins. |
| Cost management – fiscal approval | Fiscal approval of progress payments after technical approval. |
| Site Walk – access | Viewing Site Walk lists, sessions, and viewer. |
| Site Walk – upload and edit | Uploading and editing sheets, videos, sessions, and mappings. |
| Site Walk – delete | Deletion of Site Walk data. |
| Build topics | Navigation and management of topics originating from Build. |
| Build exports | Export of Build topic reports. |
| Public / private / closed topics | Access to the different scopes of Build topics. |
Management – meetings
| Permission | What it controls |
|---|---|
| Meetings – view | Viewing meetings and review metadata. |
| Meetings – manage | Creation and management of meetings. |
| Upload transcription | Manual upload of transcriptions. |
| Execute AI processing | Initiation of AI processing for meetings. |
| Review suggestions | Viewing and reviewing generated suggestions. |
| Apply suggestions | Application of reviewed suggestions. |
| Configure policy | Recording, retention, and processing policy. |
| View transcription | Access to transcription content. |
| View artifacts | Access to recordings, exports, and attachments. |
| Manage integrations | Integrations of Meeting Intelligence providers. |
Management – correspondence and tasks
| Permission | What it controls |
|---|---|
| Correspondence – view | Viewing correspondence accessible to the user. |
| Correspondence – manage | Statuses, deadlines, and metadata of correspondence. |
| Correspondence – link entities | Links to topics, meetings, tasks, and documents. |
| Correspondence – export | Export of correspondence and threads. |
| Correspondence – configure capture | Address and rules for correspondence capture. |
| CDE integration mapping | CDE folders used by Correspondence and Document Studio. |
| Tasks – view | Viewing tasks visible to the user. |
| Tasks – manage own | Creation and management of own tasks. |
| Tasks – manage project | Management and assignment of team/project tasks. |
Management – Document Studio
| Permission | What it controls |
|---|---|
| Document Studio – view | Viewing authorized documents and sections. |
| Create | Document creation. |
| Edit content | Editing authorized sections. |
| Suggest changes | Suggestions with change tracking. |
| Comment | Comments in documents. |
| Approve | Approval in review workflows. |
| Publish | Publication of approved documents, including promotion to CDE. |
| Manage templates | Templates and block library. |
| Configure workflows | Workflows and validation rules. |
| Manage permissions | Specific access per section. |
Management – Information Requirements
| Permission | What it controls |
|---|---|
| Information Requirements – view | Libraries, revisions, and requirements matrix. |
| Structure | Libraries, revisions, disciplines, classes, and applicability. |
| Properties | Definitions, groups, and reusable property sets. |
| Matrix | Assignment of requirement levels. |
| Approve | Submission, approval, or return of revisions. |
| Import | Import of IDS, XLSX, and CSV. |
| Export | Preview/export of IDS and BEP attachments. |
| Publish to Design | Publication of compiled specifications in the Design IDS library. |
Insights
| Permission | What it controls |
|---|---|
| Dashboards | Viewing and managing dashboards, supplemented by specific permissions for each dashboard. |
Some rows depend on feature flags or active modules in the subscription. For this reason, a permission may exist in the backend and not appear in the matrix of a particular workplace.
Specific level restrictions
Most rows offer None, Read, and Total, but there are exceptions in the current interface:
- only None/Total: Naming conventions, CDE configuration, Cost management – approve, Fiscal approval, Site Walk – upload and edit, Site Walk – delete, Object colors – manage, Correspondence – configure capture, and CDE integration mapping;
- only None/Read: Object colors and Build closed topics.
In some action functionalities, Read may be displayed for matrix consistency but does not authorize the operation; the contextual help for the row indicates the threshold actually applied by the API.
Project Manager role
The Set Project Manager button marks a project role, not an individual user.
For a role to be marked as Project Manager:
- all its permissions must be set to Total;
- the scopes of public, private, and closed topics in Design and Build are the only exception and may have another level;
- when marking a new role, the mark is removed from the previously defined role.
Consequently, all project members to whom this role is assigned receive the behavior associated with the Project Manager role.
Permissions by object
The role matrix alone does not determine all access. Several areas apply additional permissions per object:
- CDE folders;
- topics;
- clash tests;
- IDS specifications;
- views;
- dashboards;
- Document Studio sections.
In CDE, for example, the role controls entry into the module and the ability to manage permissions, while the folder can grant:
| Folder level | Capabilities |
|---|---|
| None | No access. |
| Read Only | View. |
| Read + Download | View and download. |
| Read + Download + Upload | View, download, and upload. |
| Edit | View, download, upload, edit, and delete. |
| Full Administrative Control | Full control, including allowed administration. |
Folder permissions can be assigned directly to users, teams, or companies. The backend calculates the effective applicable level; a Project Admin receives full control and a Guest does not receive access to folders via this mechanism.
How to configure
- In Workplace Settings → Workplace Permissions, review or create workplace roles.
- Define the matrix for each custom role and assign it to workplace members.
- In Workplace Settings → Project Permissions, review or create the project roles available in the workplace.
- Define the project role matrix and, if applicable, mark the Project Manager role.
- In each project, assign the appropriate project role to each member.
- Also configure object-level permissions in areas that support them.
Access problem diagnosis
When a button is disabled, a section does not appear, or the API returns access denied, check in this order:
- the user is active in the workplace and the project;
- they have the correct workplace role and project role;
- the relevant permission is set to Read or Total, depending on the action;
- the module is available in the subscription and the feature flag is active;
- the object has its own permissions and the user, team, or company has the necessary level;
- the role is Guest or there is another functionality-specific rule.
Links
Was this article helpful?