---
title: "Roles & permissions"
slug: "roles-permissions"
tags: ["restrict", "view only"]
updated: 2026-06-29T15:49:54Z
published: 2026-06-29T15:49:54Z
canonical: "help.wrapbook.com/roles-permissions"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://help.wrapbook.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles & permissions

The *Roles & permissions* section of *Company settings* is where you can manage access to company and project data, and Wrapbook features.

## Access Roles & permissions

> [!NOTE]
> Permissions and Access Control are permission based
> 
> To update a company’s *Permissions and Access Control* settings, your account must have one of the following [roles](/v1/docs/roles-permissions) enabled:
> 
> - Role: *Company Admin*
> - Custom role with: *Company settings/Permissions and access control - Full access*

To access *Roles & permissions*:

1. In the left-side navigation, click the dropdown menu
2. In the dropdown menu, select **All projects**
3. In the left-side navigation, click **Company settings**
4. Scroll down the page until you see the *Permissions and Access Control* section and then click the **Manage** button next to *Roles & permissions*

## View a role’s permissions

- On the *Roles & permissions* page, click the **View permissions** button next to the role that you want to see
- This will open a page listing the Wrapbook features that the role can access

### Preconfigured roles

Wrapbook provides the following preconfigured roles that you can assign to people in your company:

| **Role** | **Description** |
| --- | --- |
| ***Company Admin*** | - Offers the highest level of visibility and access to all the features of Wrapbook |
| ***Department Head*** | - Can manage [departments](/v1/docs/about-organizations) that they’ve been assigned to within a project |
| ***Company Manager*** | - Can manage projects, reports, and people across the organization - Can view worker sensitive information |
| ***Project Assistant*** | - Can assist with key tasks on projects they’ve been assigned to |
| ***Project Coordinator*** | - Can manage projects that they’ve been assigned to |
| ***Accountant*** | - Offers full visibility and access to [cost tracking](/v1/docs/about-cost-tracking) and [production accounting](/v1/docs/about-production-accounting) features - Can view worker sensitive information |

### Custom roles

On the *Roles & permissions* page, you also have the option to create custom roles.

#### Access levels

When you create a custom role in Wrapbook, you’ll be able to see the full list of company/project data and Wrapbook features, and the access levels that you can assign to each of them.

****Click the arrow** to see the complete list of categories, settings, access level options, and permissions**

| **Category** | **Setting** | Access level options | Permissions |
| --- | --- | --- | --- |
| **Company settings** | **General settings** | Full access | - Can manage company information and project preferences within Wrapbook |
|  |  | None | - No access |
|  | **Funding methods** | Full access | - Can manage bank account and drawdown information within Wrapbook |
|  |  | View only | - Can view bank account and drawdown information within Wrapbook |
|  |  | None | - No access |
|  | **Permission and access control** | Full access | - Can manage company roles and user within Wrapbook |
|  |  | None | - No access |
|  | **Accounting settings** | Full access | - Can manage company roles and users within Wrapbook |
|  |  | None | - No access |
|  | **Organizational structure** | Full access | - Can manage a company’s organizational structure within Wrapbook |
|  |  | None | - No access |
|  | **Production entities** | Full access | - Can manage a company roles and users within Wrapbook |
|  |  | Manage | - Can update production entities but cannot create them |
|  |  | None | - No access |
| **Reports** | **Production & payroll reports** | View all | - Can access all company and project reports |
|  |  | View basic | - Can access project reports only |
|  |  | None | - No access |
|  | **Accounting reports** | Full access | - Can access accounting reports for all projects |
|  |  | None | - No access |
| **Projects, People & Approvals** | **Project management** | Full access | - Can create and edit projects and documents - Can assign funding methods to a project |
|  |  | Manage | - Can update projects, bur can’t create them - Can create and edit documents - Can assign funding methods to projects |
|  |  | View only | - Can view projects, but can’t create or update them - Has no access to documents |
|  |  | None | - No access |
|  | **Location management** | Full access | - Can manage project locations |
|  |  | None | - No access |
|  | **Worker hiring and startwork** | Full access | - Can hire workers and manage startwork for all projects across the company |
|  |  | Project access only | - Can only hire workers and manage startwork for their assigned projects |
|  |  | None | - No access |
|  | **Worker sensitive information** | Full access | - Can see workers' tax identification numbers (SSN, EIN - USA; ITN, CBN - Canada) |
|  |  | None | - No access, members will see masked tax identification information on payroll reports |
|  | **Approval requests** | Full access | - Can skip, approve, deny, and see approval requests across the whole company |
|  |  | View all | - Can see approval requests across the whole company, but can’t approve or deny unless assigned |
|  |  | Assigned only | - Can only approve, deny, and see approval requests if assigned as an approver |
| **Payroll & Financials** | **Worker rate and pay information** | Full access | - Can see worker rates and gross total amounts across the whole company |
|  |  | Project access only | - Can see worker rates and gross total amounts on assigned projects |
|  |  | None | - No access to worker rate or pay information |
|  | **Timecards** | Full access | - Can create and approve timecards |
|  |  | Create and manage | - Can create timecards but can’t approve them |
|  |  | Approve only | - Can approve timecards, but can’t create them |
|  |  | None | - No access |
|  | **Allowances** | Full access | - Can create and approve allowances |
|  |  | Create and manage | - Can create allowances but can’t approve them |
|  |  | Approve only | - Can approve allowances but can’t create them |
|  |  | View only | - Can see allowances but can’t create, update, or approve them |
|  |  | None | - No access |
|  | **Payroll information** | View all | - Can see all sensitive and non-sensitive information on payrolls |
|  |  | View basic | - Can see non-sensitive information on payrolls |
|  |  | None | - No access |
|  | **Payroll preparation** | Full access | - Can create, recalculate, update, see, and cancel payroll batches |
|  |  | Create & update payrolls | - Can create, see, and update payroll batches |
|  |  | Create | - Can create payroll batches |
|  |  | None | - No access |
|  | **Payroll processing** | Full access | - Can authorize, decline, and fund payroll |
|  |  | Allow decline | - Can authorize and decline payroll, but can’t fund them |
|  |  | All | - Can authorize payroll funds, but can’t decline or fund them |
|  |  | None | - No access |
| **Accounting & Cost Tracking** | **Vendors** | Full access | - Can view, create, edit, and delete all vendor fields, including banking and tax identity - Can approve/reject vendor submissions - Can merge vendors - Full audit trail access. |
|  |  | Create and manage | - Can create and edit vendors (contact info, address, DBA, tax classification) - Sees obfuscated banking info (•••1234) and SSN - Can submit banking change requests (routed through approval when Vendor Approvals is configured) - Cannot approve own submissions |
|  |  | Project access only | - Can create new vendor records and attach them to transactions; new vendors enter Pending Review status until approved - No vendor list access - Cannot view or modify banking info or SSN |
|  |  | View only | - Can view existing vendors in the context of POs and/or AP Invoices only - Cannot create or edit vendors - No visibility into banking info or SSN - Team members with no access to POs or AP Invoices have no access to vendors |
|  |  | None | - No access |
|  | **Vendor payments** | Full access | - Can create and cancel vendor payments |
|  |  | None | - No access |
|  | **Distribution changes** | Full access | - Can make distribution changes on all transaction types |
|  |  | None | - No access |
|  | **Budgets (Cost Tracking)** | Full access | - Can see, create, import, and lock budgets |
|  |  | View & Import | - Can see, import, and update, but not lock budgets |
|  |  | View only | - Can view budgets |
|  |  | None | - No access |
|  | **Budgets (Production Accounting)** | Full access |  |
|  |  | None |  |
|  | **Bank reconciliation** | Full access | - Can see, update, and delete bank reconciliations - Can export a bank reconciliation PDF statement |
|  |  | View only | - Can only see bank reconciliations - Can export a bank reconciliation PDF statement |
|  |  | None | - No access |
|  | **Purchase orders** | Full access | - Can create, manage, and approve project vendors and purchase orders |
|  |  | Manage | - Can update purchase orders and view project vendors |
|  |  | View only | - Can view purchase orders and project vendors |
|  |  | None | - No access |
|  | **Petty cash** | Full access | - Can create and manage petty cash funding and distributions |
|  |  | Manage | - Can manage petty cash distributions, but can’t fund petty cash |
|  |  | None | - No access |
|  | **Journal entries** | Full access | - Can view, create, update, and delete journal entries - Can post journal entry transactions to the general ledger - Can export the summary view and detailed view CSV reports |
|  |  | Manage and post | - Can view and update journal entries - Can post journal entry transactions to the general ledger - Can export the summary view and detailed view CSV reports |
|  |  | View | - Can only see journal entries |
|  |  | None | - No access |
|  | **AP invoices** | Full access | - Can view, create, update, and delete AP invoices - Can post AP transactions to the general ledger |
|  |  | Create and manage | - Can see, create, and update AP invoices, but can’t delete them or post to the general ledger |
|  |  | View only | - Can only view AP invoices |
|  |  | None | - No access |
|  | **Payroll invoices** | Full access | - Can view and edit payroll invoices - Can post PR transactions to the general ledger - Can export the summary view and detailed view CSV reports with the read sensitive permission |
|  |  | Manage and post | - Can view and edit payroll invoices - Can post PR transactions to the general ledger - Can export the summary view and detailed view CSV reports |
|  |  | View only | - Can only view payroll invoices - Can export the summary view and detailed view CSV reports |
|  |  | None | - No access |
|  | **Project settings: Accounting bank accounts** | Full access | - Can setup and manage accounting bank accounts |
|  |  | None | - No access |
|  | **Project settings: Payroll transactions** | Full access | - Can setup and manage the default bank and clearing account used for payroll transactions |
|  |  | None | - No access |
|  | **Project settings: Tag management** | Full access | - Can setup and manage tags |
|  |  | None | - No access |
|  | **Project settings: Period management** | Full access | - Can setup and manage accounting periods |
|  |  | None | - No access |
|  | **Project settings: Accounting e-signatures** | Full access | - Can create and manage their own e-signature on a project |
|  |  | View only | - Can only see e-signatures |
|  |  | None | - No access |

#### Create a custom role

1. On the *Roles & permissions* page, scroll down until you see the *Add your first custom role* section and click the **+ Add custom role** button
2. In the *Add custom role* popup choose either: *Start from scratch* or *Copy existing role*
3. Click the **Continue** button

#### Start from scratch

1. On the *Add custom role* page, enter a *Role name*, and *Description*
2. Click the dropdown menu next to each item in the list to select the permission levels the role will have
3. When you’re finished selecting permission levels, click the **Save** button

#### Copy existing role

1. In the *Add custom role* popup, under Role, click the search icon
2. Select the role name and then click the **Continue** button
3. On the *Add custom role* page, enter a *Role name*, and *Description*
4. Review the pre-selected permission levels and click the dropdown menus to make adjustments as needed
5. When you’re finished selecting permission levels, click the **Save** button

#### Update custom roles

1. On the *Roles & permissions* page, click the three dots next to the custom role that you want to update
2. Select from the following: *Edit role, View members, Duplicate role, Delete role*

## Project-level roles

*Project-level roles* allow your production company’s [team members](https://help.wrapbook.com/docs/members) to have different roles and permission levels across multiple projects within the same company.

With project-level roles you can:

- Assign different roles for each project a team member works on
- Maintain appropriate access permissions as team members take on different responsibilities across different projects
- Better reflect real-world production workflows where team members often have different roles across projects
- Reduce security risks by providing only the permissions needed for each specific project

### Company-level role

Every team member has a *company-level role* that determines what they can see on company-wide dashboards in Wrapbook like:

- All projects dashboard
- Company startwork dashboard
- Company reports dashboard

### Project-specific roles

In addition to their *company-level role*, team members can be assigned different roles for each project they're part of, meaning:

- A team member can have unique permissions tailored to their responsibilities on each project
- Permission levels can differ between projects based on job requirements
- The fallback will always be a company-level role if the project-level role cannot be determined or used

**Note:** *Company Admin* and *Company Manager* roles cannot be assigned at the project level. These roles are designed to grant comprehensive access across the entire company.

### Project-level role options

Project-level roles are assigned when [inviting team members](https://help.wrapbook.com/docs/members#invite-members) to your company.

![Form to invite a new member with role and project access options.](https://cdn.us.document360.io/67f3ef76-1568-46b4-8047-4792fc3a99ce/Images/Documentation/Untitled - 2025-08-12T130725.559(1).png)

The option to assign project-level roles appears when inviting a team member to your company

#### All company projects

- The team member will have access to all projects across the company
- Choosing this options requires the invitee to be assigned a *Role*

#### A specific organization’s projects

- The team member will have access to all projects within a specific [organization](https://help.wrapbook.com/docs/about-organizations)
- Choosing this option requires the invitee to be assigned a *Role*, and an *Organization*
- The permissions associated with the team member’s assigned role will apply to all of the organization’s projects

#### Specific projects

- The team member will have access to specific projects only
- Choosing this option requires the invitee to be assigned a *Role*, and at least one *Project*
- To assign the team member additional roles and projects, click **+ Add another project**
- When a team member is assigned additional roles and projects, the first role selection listed is considered their [company-level role](/v1/docs/roles-permissions#companylevel-role)

#### Specific project departments

- The team member will have access to specific projects or departments only
- Choosing this options requires the invitee to be assigned a *Role*, *Project,* and [*Department*](https://help.wrapbook.com/docs/additional-settings#departments)
- To assign the team member additional roles and projects, click **+ Add another project**
- When a team member is assigned additional roles and projects, the first role selection listed is considered their [company-level role](/v1/docs/roles-permissions#companylevel-role)

Documents filled out by workers at the beginning of the work, which contains specific, vital information needed to process payroll.

Employer Identification Number: Federal tax identifier used to identify a business

A company or individual providing a product or service.

Professional review of the ledger and transactions of a project to ensure compliance with laws & procedures. May be conducted by Federal or State agencies, labor union representatives, Studio or Financier representatives, or to review compliance with tax incentive guidelines.

(Accounts Payable) Cash disbursements through the payment of vendor invoices and other payables
