YND OS Help Center

Guides, workflows and role playbooks for the whole team.

Everyone

Roles & Permissions Overview

YND OS shows different sidebar pages and quick actions depending on your role. This page is the master reference: a permission matrix covering every major page and action, plus the rules that govern how access actually works.

Note: This matrix describes the intended design. A handful of routes are not technically page-gated yet (see the gaps callout below) — meaning a determined person could reach them by typing the URL even if their sidebar doesn't show the link. Treat the sidebar as the source of truth for "what you're supposed to use," not as a hard security boundary.

How to read this table

  • Full — role has the page/feature in their sidebar and can use every action on it.
  • Read — role can view the page/data but cannot create, edit, or submit changes.
  • Partial — role has limited or conditional access (explained in the footnotes), or the page is reachable by direct URL only (not linked in their sidebar) because it isn't page-gated.
  • None — role has no access; visiting the URL sends them to /access-denied (for gated pages).

Permission matrix

Feature / PageDoor ExpertCSRProject ManagerDispatcherDesign ConciergeReconcilerManagerExecutiveInstallerAdmin
Mission Control (/)FullFullFullFullFullFullFullFullFullFull
Customers (/customers)FullFullFullNoneFullNoneFullFullNoneFull
Opportunities (/opportunities)FullFullFullNoneFullNoneFullFullNoneFull
Bookings (/bookings/new)Partial¹FullPartial¹Partial¹Partial¹Partial¹FullFullPartial¹Full
Appointments (/appointments)FullFullFullNoneNoneNoneFullNone²NoneFull
Call Recordings (/recordings)FullFullFullNoneNoneNoneFullNone²NoneFull
Schedule (/schedule)NoneFullNoneFullNoneNoneFullNoneNoneFull
My Schedule (/my-schedule)FullFullFullNoneFullNoneFullNoneNoneFull
Dispatch — read (/dispatch)NoneFull³NoneFullNoneNoneFullFullNoneFull
Dispatch — writeNoneRead-only³NoneFullNoneNoneFullFullNoneFull
Routing (/routing)NoneFullNoneFullNoneNoneFullNoneNoneFull
Field Portal (/field)NoneNoneFullNoneNoneNoneFullNoneNoneFull
Estimates / Price Book (/estimate, /pricebook)FullPartial¹Partial¹NoneFullNoneFullFull (Price Book only)NoneFull
Catalog (/libraries)FullNoneNoneNoneFullNoneFullNoneNoneFull
Proposals / Workbench (/proposals, /workbench)FullPartial¹Partial¹NoneFullNoneFullFull (Proposals only)NoneFull
Payments (/payments)NoneFullNoneNoneNoneNoneFullFullNoneFull
Configurator (/configurator)FullNoneNoneNoneFullNoneFullNoneNoneFull
Imagine (/imagine)FullNoneNoneNoneFullNoneFullFullNoneFull
Inspirations / GalleryFullGallery onlyGallery onlyNoneFullNoneFullFullNoneFull
Projects (/projects)NoneNoneFullNoneNoneFullFullFullReadFull
Reconcile / Release (within Projects)NoneNoneReadNoneNoneFullFullFullNoneFull
Approvals queue (/approvals, unlinked)NoneNoneNoneNoneNoneNoneFullFullNoneFull
Communications (/communications)FullFullFullFullFullFullFullFullFullFull
Training (/training)FullFullFullFullFullFullFullFullFullFull
Admin: Users, Permission Sets, TagsNoneNoneNoneNoneNoneNoneNoneNoneNoneFull
Admin: Warranty ContentNoneNoneNoneNoneNoneNonePartial⁴NoneNoneFull
Admin: ServiceTitan Integration & MappingNoneNoneNoneNoneNoneNoneNonePartial⁴NoneFull
Admin: Internal Notes Guidelines, Sales CoachingNoneNoneNoneNoneNoneNoneNoneNoneNoneFull
Admin: FeedbackNoneNoneNoneNoneNoneNonePartial⁴NoneNoneFull

¹ Not page-gated today — reachable by typing the URL even without a sidebar link. See the Known product gaps note below. ² Executive is not on the default allow-list for Appointments/Recordings; if an executive needs this, grant it via a permission set. ³ CSR sees the Dispatch board (read) but cannot drag/reassign jobs or edit the schedule from it unless a Permission Set also grants Dispatcher write access. See /help/troubleshooting/access-denied. ⁴ Manager and Executive each get one specific Admin sub-page, not the full Admin section.

Rules that apply everywhere

Note: Admin and Executive bypass every UI page gate. They can open any route in the app, including all /admin/* pages, without being redirected to /access-denied. The one real difference: only Admin can invite/deactivate users and edit Permission Sets on the server — Executive's extra access is view/UI only.

Note: CSR can see the Dispatch board because CSRs often need to check job status for a customer on the phone, but CSRs cannot schedule or move jobs on it — that view is read-only for them unless they've also been granted Dispatcher permissions.

Tip: If someone needs a page outside their role's defaults (e.g., a Manager who also does design work needs /configurator), don't change their role — add the specific page via Permission Sets (/admin/permission-sets). Permission sets are additive: they grant extra pages on top of the role default, they never take pages away.

Known product gaps

Some pages have no server-side or route-side gate yet, meaning any signed-in user who knows or guesses the URL can open them even if it's not in their sidebar:

  • /bookings/new, /estimate, /workbench, /csr-intake (legacy intake form)
  • Most /admin/* pages
  • /approvals is real and used by Managers, but it isn't linked from the sidebar at all — you have to know the URL or follow a link from a notification.

This means the matrix's "Partial" entries for these rows reflect what's possible by URL, not what's intended. Always use the sidebar link for your role; if you land on a page that doesn't look like it belongs to you, treat it as a bug and flag it (see /help/troubleshooting/access-denied).

Role pages

Ask the Assistant

Answers from YND OS help docs only

Try asking

Mission Control