Roles & Permissions Overview
YND OS shows different sidebar pages and quick actions depending on your role. This page is the master reference: a permission matrix covering every major page and action, plus the rules that govern how access actually works.
Note: This matrix describes the intended design. A handful of routes are not technically page-gated yet (see the gaps callout below) — meaning a determined person could reach them by typing the URL even if their sidebar doesn't show the link. Treat the sidebar as the source of truth for "what you're supposed to use," not as a hard security boundary.
How to read this table
- Full — role has the page/feature in their sidebar and can use every action on it.
- Read — role can view the page/data but cannot create, edit, or submit changes.
- Partial — role has limited or conditional access (explained in the footnotes), or the page is reachable by direct URL only (not linked in their sidebar) because it isn't page-gated.
- None — role has no access; visiting the URL sends them to
/access-denied(for gated pages).
Permission matrix
| Feature / Page | Door Expert | CSR | Project Manager | Dispatcher | Design Concierge | Reconciler | Manager | Executive | Installer | Admin |
|---|---|---|---|---|---|---|---|---|---|---|
Mission Control (/) | Full | Full | Full | Full | Full | Full | Full | Full | Full | Full |
Customers (/customers) | Full | Full | Full | None | Full | None | Full | Full | None | Full |
Opportunities (/opportunities) | Full | Full | Full | None | Full | None | Full | Full | None | Full |
Bookings (/bookings/new) | Partial¹ | Full | Partial¹ | Partial¹ | Partial¹ | Partial¹ | Full | Full | Partial¹ | Full |
Appointments (/appointments) | Full | Full | Full | None | None | None | Full | None² | None | Full |
Call Recordings (/recordings) | Full | Full | Full | None | None | None | Full | None² | None | Full |
Schedule (/schedule) | None | Full | None | Full | None | None | Full | None | None | Full |
My Schedule (/my-schedule) | Full | Full | Full | None | Full | None | Full | None | None | Full |
Dispatch — read (/dispatch) | None | Full³ | None | Full | None | None | Full | Full | None | Full |
| Dispatch — write | None | Read-only³ | None | Full | None | None | Full | Full | None | Full |
Routing (/routing) | None | Full | None | Full | None | None | Full | None | None | Full |
Field Portal (/field) | None | None | Full | None | None | None | Full | None | None | Full |
Estimates / Price Book (/estimate, /pricebook) | Full | Partial¹ | Partial¹ | None | Full | None | Full | Full (Price Book only) | None | Full |
Catalog (/libraries) | Full | None | None | None | Full | None | Full | None | None | Full |
Proposals / Workbench (/proposals, /workbench) | Full | Partial¹ | Partial¹ | None | Full | None | Full | Full (Proposals only) | None | Full |
Payments (/payments) | None | Full | None | None | None | None | Full | Full | None | Full |
Configurator (/configurator) | Full | None | None | None | Full | None | Full | None | None | Full |
Imagine (/imagine) | Full | None | None | None | Full | None | Full | Full | None | Full |
| Inspirations / Gallery | Full | Gallery only | Gallery only | None | Full | None | Full | Full | None | Full |
Projects (/projects) | None | None | Full | None | None | Full | Full | Full | Read | Full |
| Reconcile / Release (within Projects) | None | None | Read | None | None | Full | Full | Full | None | Full |
Approvals queue (/approvals, unlinked) | None | None | None | None | None | None | Full | Full | None | Full |
Communications (/communications) | Full | Full | Full | Full | Full | Full | Full | Full | Full | Full |
Training (/training) | Full | Full | Full | Full | Full | Full | Full | Full | Full | Full |
| Admin: Users, Permission Sets, Tags | None | None | None | None | None | None | None | None | None | Full |
| Admin: Warranty Content | None | None | None | None | None | None | Partial⁴ | None | None | Full |
| Admin: ServiceTitan Integration & Mapping | None | None | None | None | None | None | None | Partial⁴ | None | Full |
| Admin: Internal Notes Guidelines, Sales Coaching | None | None | None | None | None | None | None | None | None | Full |
| Admin: Feedback | None | None | None | None | None | None | Partial⁴ | None | None | Full |
¹ Not page-gated today — reachable by typing the URL even without a sidebar link. See the Known product gaps note below.
² Executive is not on the default allow-list for Appointments/Recordings; if an executive needs this, grant it via a permission set.
³ CSR sees the Dispatch board (read) but cannot drag/reassign jobs or edit the schedule from it unless a Permission Set also grants Dispatcher write access. See /help/troubleshooting/access-denied.
⁴ Manager and Executive each get one specific Admin sub-page, not the full Admin section.
Rules that apply everywhere
Note: Admin and Executive bypass every UI page gate. They can open any route in the app, including all /admin/* pages, without being redirected to /access-denied. The one real difference: only Admin can invite/deactivate users and edit Permission Sets on the server — Executive's extra access is view/UI only.
Note: CSR can see the Dispatch board because CSRs often need to check job status for a customer on the phone, but CSRs cannot schedule or move jobs on it — that view is read-only for them unless they've also been granted Dispatcher permissions.
Tip: If someone needs a page outside their role's defaults (e.g., a Manager who also does design work needs /configurator), don't change their role — add the specific page via Permission Sets (/admin/permission-sets). Permission sets are additive: they grant extra pages on top of the role default, they never take pages away.
Known product gaps
Some pages have no server-side or route-side gate yet, meaning any signed-in user who knows or guesses the URL can open them even if it's not in their sidebar:
/bookings/new,/estimate,/workbench,/csr-intake(legacy intake form)- Most
/admin/*pages /approvalsis real and used by Managers, but it isn't linked from the sidebar at all — you have to know the URL or follow a link from a notification.
This means the matrix's "Partial" entries for these rows reflect what's possible by URL, not what's intended. Always use the sidebar link for your role; if you land on a page that doesn't look like it belongs to you, treat it as a bug and flag it (see /help/troubleshooting/access-denied).
