Skip to main content
Pricing
Sign InBook a Demo

Roles and permissions

UI: Workplace Settings → Workplace Permissions / Project Permissions
Audience: workplace administrators, project managers, and access configuration owners

What are roles and permissions

A role is a set of permissions assigned to a user. In BIMWorkplace, there are two independent contexts:

ContextWhat it controlsAssignment
Workplace roleWorkplace administration and common resources: users, projects, billing, settings, credits, and cost catalog.Every active workplace member has a workplace role.
Project roleWhat the member can see or manage within a project: settings, models, Explorer, Design, CDE, Build, Management, and Insights.The same user can have a different project role in each project.

A project role does not replace or override the workplace role. Both are evaluated in their respective contexts. For example, a user can administer a project without being able to manage billing or workplace users.

Types of roles

The backend authorization contract recognizes four technical types:

TypeContextMeaning
Workplace AdminWorkplaceWorkplace administration.
Project AdminProjectProject administration; this is the type used by the Project Manager role provided by the platform.
UserBothNormal user; access depends on the values defined in the matrix.
GuestBothGuest user, with limited access. Some features apply additional restrictions to guests.

In the interface, roles can also be:

  • Default / Standard: provided by the platform. They are shown as locked and cannot be edited or deleted by the workplace.
  • Custom: created in the workplace. They can be renamed and have their matrix changed.
  • Project Manager role: a project role marked with a crown. Only one project role definition in the workplace can be marked as Project Manager at a time.

When creating a custom role, the backend initially copies the permissions of the active default role of type User. The administrator must then review the matrix before assigning the role.

A custom role can only be deleted when it is no longer assigned to any users.

Matrix levels

The Workplace Permissions and Project Permissions matrices use three editable levels:

LevelValueGeneral effect
None0Does not grant the capability. The section or action may be hidden or blocked.
Read1Allows viewing, when the functionality supports read mode. It does not, by itself, authorize creation, editing, or deletion.
Total9Allows managing the capability, including changes authorized by the API.
SeveralNot a saved level. Appears only in a group row when child permissions have different levels.

Not all permissions accept all three levels. Some offer only None/Total or None/Read, because the operation is exclusively management-oriented or exclusively view-oriented.

The backend also has more granular levels used in object permissions, such as Read + Download, Upload, Edit, and Full Administrative Control. These levels are not choices in the role matrix.

Workplace Permissions

The workplace matrix currently presents the following permissions:

PermissionWhat it controlsAvailable levels
Workplace billingBilling inquiry, prices, invoices, and plan management.None · Read · Total
Workplace profileViewing and editing general workplace information.None · Read · Total
Workplace projectsList and management of workplace projects.None · Read · Total
Users and companiesUsers, invitations, companies, and their management.None · Read · Total
Roles and permissionsAccess to matrices and management of workplace and project roles.None · Read · Total
Workplace settingsCommon settings, units, and templates.None · Read · Total
Workplace attributesWorkplace attribute library.None · Read · Total
Credits and usageBalances, history, and credit allocations.None · Read · Total
AI Pool – grantsGranting or revoking the use of the shared AI Pool.None · Total
SubscriptionViewing and managing the subscription and modules.None · Read · Total
Cost catalog – viewViewing the common workplace cost catalog.None · Read
Cost catalog – editManagement of price databases, resources, compositions, and units.None · Total

Who can manage roles

The Workplace Permissions section is controlled by the Roles and permissions permission:

  • None: the section is not available;
  • Read: allows viewing roles and levels, without alteration;
  • Total: allows creating, editing, and deleting custom roles and changing the matrix.

Project Permissions

Project roles are configured at the workplace level and then assigned to members of each project. The matrix only displays permissions with actual application in the project context; internal, legacy, or mechanism-controlled permissions are hidden.

Project administration

PermissionWhat it controls
Project profileGeneral information and project management.
Members and teamsViewing and managing members and teams.
Project unitsConfiguration of measurement units.
Project attributesProject attribute library.
Naming conventionsCreation and management of naming conventions.
CDE configurationCDE configuration, document statuses, and transitions.
Approval workflowsTemplates and steps for approval workflows.

Models and viewer

PermissionWhat it controls
Model managementManagement of project models.
Model properties and permissionsModel properties and their access rules.
Object colorsViewing color schemes and data.
Object colors – manageCreation and editing of project color schemes.
Explorer model managementModel management actions in Explorer.
Active Design modelManagement of the active model in Design.
Active Build modelManagement of the active model in Build.

Explorer

PermissionWhat it controls
Explorer viewsOpening views and, with Total, creating, editing, deleting, and sharing views.
Explorer view groupsViewing and managing Explorer information groups.

Design

PermissionWhat it controls
Design topicsNavigation and management of Design topics.
Geometry verificationClash tests, matrices, folders, and results.
Property verificationIDS library, specifications, and results.
Requirements verificationRulesets, rules, and Requirements Check results.
Design exportsExport of Design reports.
Public topicsAccess to the public scope of topics.
Private topicsAccess to the private scope of topics.
Closed topicsAccess to closed topics.

CDE

PermissionWhat it controls
CDE accessEntry into the CDE module. File and folder read/write access still depends on specific folder permissions.

Build

PermissionWhat it controls
Cost management – accessEntry into budgeting and cost control functionalities.
Cost management – editEditing budgets, BoQ, and cost structures.
Cost management – approveApproval or rejection of budget versions.
Cost management – commercialViewing sales prices and margins.
Cost management – fiscal approvalFiscal approval of progress payments after technical approval.
Site Walk – accessViewing Site Walk lists, sessions, and viewer.
Site Walk – upload and editUploading and editing sheets, videos, sessions, and mappings.
Site Walk – deleteDeletion of Site Walk data.
Build topicsNavigation and management of topics originating from Build.
Build exportsExport of Build topic reports.
Public / private / closed topicsAccess to the different scopes of Build topics.

Management – meetings

PermissionWhat it controls
Meetings – viewViewing meetings and review metadata.
Meetings – manageCreation and management of meetings.
Upload transcriptionManual upload of transcriptions.
Execute AI processingInitiation of AI processing for meetings.
Review suggestionsViewing and reviewing generated suggestions.
Apply suggestionsApplication of reviewed suggestions.
Configure policyRecording, retention, and processing policy.
View transcriptionAccess to transcription content.
View artifactsAccess to recordings, exports, and attachments.
Manage integrationsIntegrations of Meeting Intelligence providers.

Management – correspondence and tasks

PermissionWhat it controls
Correspondence – viewViewing correspondence accessible to the user.
Correspondence – manageStatuses, deadlines, and metadata of correspondence.
Correspondence – link entitiesLinks to topics, meetings, tasks, and documents.
Correspondence – exportExport of correspondence and threads.
Correspondence – configure captureAddress and rules for correspondence capture.
CDE integration mappingCDE folders used by Correspondence and Document Studio.
Tasks – viewViewing tasks visible to the user.
Tasks – manage ownCreation and management of own tasks.
Tasks – manage projectManagement and assignment of team/project tasks.

Management – Document Studio

PermissionWhat it controls
Document Studio – viewViewing authorized documents and sections.
CreateDocument creation.
Edit contentEditing authorized sections.
Suggest changesSuggestions with change tracking.
CommentComments in documents.
ApproveApproval in review workflows.
PublishPublication of approved documents, including promotion to CDE.
Manage templatesTemplates and block library.
Configure workflowsWorkflows and validation rules.
Manage permissionsSpecific access per section.

Management – Information Requirements

PermissionWhat it controls
Information Requirements – viewLibraries, revisions, and requirements matrix.
StructureLibraries, revisions, disciplines, classes, and applicability.
PropertiesDefinitions, groups, and reusable property sets.
MatrixAssignment of requirement levels.
ApproveSubmission, approval, or return of revisions.
ImportImport of IDS, XLSX, and CSV.
ExportPreview/export of IDS and BEP attachments.
Publish to DesignPublication of compiled specifications in the Design IDS library.

Insights

PermissionWhat it controls
DashboardsViewing and managing dashboards, supplemented by specific permissions for each dashboard.

Some rows depend on feature flags or active modules in the subscription. For this reason, a permission may exist in the backend and not appear in the matrix of a particular workplace.

Specific level restrictions

Most rows offer None, Read, and Total, but there are exceptions in the current interface:

  • only None/Total: Naming conventions, CDE configuration, Cost management – approve, Fiscal approval, Site Walk – upload and edit, Site Walk – delete, Object colors – manage, Correspondence – configure capture, and CDE integration mapping;
  • only None/Read: Object colors and Build closed topics.

In some action functionalities, Read may be displayed for matrix consistency but does not authorize the operation; the contextual help for the row indicates the threshold actually applied by the API.

Project Manager role

The Set Project Manager button marks a project role, not an individual user.

For a role to be marked as Project Manager:

  1. all its permissions must be set to Total;
  2. the scopes of public, private, and closed topics in Design and Build are the only exception and may have another level;
  3. when marking a new role, the mark is removed from the previously defined role.

Consequently, all project members to whom this role is assigned receive the behavior associated with the Project Manager role.

Permissions by object

The role matrix alone does not determine all access. Several areas apply additional permissions per object:

  • CDE folders;
  • topics;
  • clash tests;
  • IDS specifications;
  • views;
  • dashboards;
  • Document Studio sections.

In CDE, for example, the role controls entry into the module and the ability to manage permissions, while the folder can grant:

Folder levelCapabilities
NoneNo access.
Read OnlyView.
Read + DownloadView and download.
Read + Download + UploadView, download, and upload.
EditView, download, upload, edit, and delete.
Full Administrative ControlFull control, including allowed administration.

Folder permissions can be assigned directly to users, teams, or companies. The backend calculates the effective applicable level; a Project Admin receives full control and a Guest does not receive access to folders via this mechanism.

How to configure

  1. In Workplace Settings → Workplace Permissions, review or create workplace roles.
  2. Define the matrix for each custom role and assign it to workplace members.
  3. In Workplace Settings → Project Permissions, review or create the project roles available in the workplace.
  4. Define the project role matrix and, if applicable, mark the Project Manager role.
  5. In each project, assign the appropriate project role to each member.
  6. Also configure object-level permissions in areas that support them.

Access problem diagnosis

When a button is disabled, a section does not appear, or the API returns access denied, check in this order:

  1. the user is active in the workplace and the project;
  2. they have the correct workplace role and project role;
  3. the relevant permission is set to Read or Total, depending on the action;
  4. the module is available in the subscription and the feature flag is active;
  5. the object has its own permissions and the user, team, or company has the necessary level;
  6. the role is Guest or there is another functionality-specific rule.

Was this article helpful?

Back to Concepts