Let them do the work
without showing them the margin.
The reason a lot of studios stay small is that the owner is the only person allowed to see everything, so the owner ends up doing everything. Workroom splits that apart: 218 individual permissions across 24 modules, built into sets you name yourself — so a junior can source, order and receive without ever seeing what the firm makes on it.
One module of twenty-four. Every action is its own switch, tagged by what it actually does.
Trusted by the studios doing the work
You cannot delegate sourcing if sourcing shows the margin
Every studio hits the same wall. There is more work than the principal can do, and the obvious answer is to hand product research to someone junior. Then you realize the product record carries the vendor discount, the markup and the profit — and handing over the work means handing over the P&L.
So the principal keeps sourcing. At two in the morning. For another year.
Product Catalog and Project FF&E are separate modules with separate permissions, and the financial fields are their own switches inside them. Someone can add products, attach specifications, chase lead times and receive deliveries against a set that never turns on a single cost field.
- Source and specify without cost, discount or margin
- Receive and track without touching the money
- Budget, Invoices and Bills off entirely — and invisible
- The set is named for the job, not for the person
A set is a job, not a person. Hire a second sourcing assistant and they start with the same 46 on their first morning.
A greyed-out button is still an answer
Most software disables what you are not allowed to do and leaves it on screen. That tells a junior exactly how much they are not trusted with, and it tells anyone looking over their shoulder that the firm has a Bills module and an owner who does not want them in it.
- Hide the module entirely — turn it off and it leaves the sidebar. Not dimmed, not locked. Absent.
- Independent of the actions — you can enable actions inside a module and still hide it, for people who reach it through a project rather than the menu.
- Nothing to explain — a new hire never sees a surface they will have to be told is none of their business.
“Who is allowed to sign this off” has one answer
Most systems scatter approval rules across the documents they apply to, so the answer to who can release a payment lives somewhere different from who can approve a timesheet. Then somebody leaves, and nobody is sure which of those they had.
In Workroom every approval right is a permission on the set. Turn on Require approval before paying and a bill cannot be paid until a member holding Approve / reject bills signs it — plus the account owner, always. Timelog approval, estimate approval, purchase-order approval and change-order approval all work the same way.
- Bills cannot be paid without an approver
- Timelogs can require sign-off before they bill
- Estimates and POs can require approval before sending
- The account owner is always an approver
Bill approval is controlled from Permission Sets. Turn on “Require approval before paying” on any active permission set to gate paying a bill until an approver signs off. Approvers are members granted the “Approve / reject bills” permission (plus the account owner).
Open permission sets →A rate, a role, and one switch that beats everything
Each team member carries a role, a permission set and an hourly rate. The rate is not just for billing — it is what the audit uses to work out gross profit on a project, which is why a firm that never enters rates never finds out which work actually paid.
Above all of it sits Has full admin rights, which overrides the permission set entirely. It exists so that the person running the studio never gets locked out of their own business by a set somebody built on a Tuesday.
Used to calculate gross profit margin on projects.
“I could finally hand sourcing to someone new without handing over the margin. That one change is why we hired.”
Permissions, specifically answered
Can someone source products without seeing cost or margin?
Yes. Product Catalog and Project FF&E are separate modules with their own permissions, and the financial fields are individual switches inside them. A set can allow adding products, attaching specifications, chasing lead times and receiving deliveries while every cost, discount and margin field stays off.
What is the difference between a role and a permission set?
The role is a label — Jr. Designer, Office Manager — and it does not control access. The permission set does, and it is where all 218 switches live. Two people can share a role and hold different sets, or share a set and hold different roles.
Does turning a module off just gray it out?
No. “Hide this module from the menu” removes it from that member’s sidebar entirely, so they never see a surface they cannot use. It is independent of the individual actions, so you can hide a module from the menu while still allowing actions inside it for people who reach it through a project.
How do approvals work?
Approval rights are permissions. Turn on “Require approval before paying” and a bill cannot be paid until a member granted “Approve / reject bills” signs it off — the account owner always counts as an approver. Timelogs, estimates, purchase orders and change orders each have their own equivalent.
Do I have to build a set from scratch?
No. Presets give you a starting point and you adjust from there, module by module. Each module shows how many of its actions are enabled, so a half-configured set is obvious rather than something you discover when somebody cannot do their job.
Can I lock myself out?
No. “Has full admin rights” on a team member overrides the permission set entirely, and the account owner is always an approver on anything requiring sign-off.
Tell us the job you cannot hand over.
We will build the permission set for it live on the call — and you can see exactly what that person would and would not be able to open on their first morning.