Skip to content
Browse all articles

Roles and permissions

The four roles Temponia has, what each one can reach, and why a manager's rights depend on the project.

Last updated 25 July 2026

Temponia has four roles: Owner, Admin, Manager and Employee. Three of them are picked from the Role field when you create or edit a user. Owner is not in that list, because a workspace has exactly one owner and it is set on the Company info tab of Company settings, where only the current owner can change it.

Owner and Admin are treated the same almost everywhere. The two differences are that only the owner can hand ownership to someone else, and that the owner account cannot be archived.

The interesting role is Manager, because its rights are not global. A manager gets rights on a project only when they are ticked as PM in that project's Users assigned table. A manager who runs no projects sees roughly what an employee sees, including no Manage section in the sidebar at all.

What each role can do

Capability Employee Manager Admin and owner
Track their own time Yes Yes Yes
Enter time for someone else No People on their projects Yes
See the Projects list No Projects they manage All projects
Create or archive a project No No Yes
Edit a project, its rates and budget No Projects they manage Yes
Assign people and tasks to a project No Projects they manage Yes
Manage clients, tasks and expense types No No Yes
Invite, edit and archive users No No Yes
Company settings, modules and security No No Yes
Invoicing No No Yes
Edit or delete expenses Own only Any Any
Timesheet report and pivot table Own time Their projects Everything
Project report No Their projects Everything
Cost and profit columns in reports No No Yes

Rows that mention invoicing, expenses or approvals also depend on the matching module being switched on.

What everyone can do

Whatever their role, each person can track time on the projects they are assigned to, import their own entries from a file with Import timesheets, start and stop timers when the timers module is on, connect their own calendar, and edit their own details and password through View Profile in the menu under their avatar.

Absences are entered by an owner or an admin. Everyone else can see them but not add them.

Reports

Reporting is where the roles are most visible, because the same report returns different data depending on who runs it.

  • Employees only ever see their own entries. The User, Price, Invoiced and Hour rate columns are not offered to them.
  • Managers are limited to the projects they are assigned to. Cost, cost per hour and profit are never available. If the selection also covers a project they are assigned to but do not manage, the price and rate columns drop out as well, because those would let a cost be worked out indirectly.
  • Owners and admins see everything, including cost and profit.

The same reasoning applies to the Labor rate on a user: it is stated on the form itself that only administrators are able to view it.

Approvals

When the approvals module is on, approval rights follow the reviewer, not the role.

  • Everyone submits and recalls their own period.
  • The Approvals inbox opens for anyone who is not an Employee, and for any employee who is named as a reviewer on at least one submission.
  • Approving, rejecting or reopening a submission requires two things: it is not your own, and you are either the named reviewer for it, an admin, or the owner. Running a project is not enough on its own.
  • Opening and closing approval periods is limited to admins and the owner.

See reviewing and approving timesheets.

Choosing a role

Most people are Employees. Give someone Manager when they need to see how a particular project is doing, adjust its rates or budget, decide who works on it, and correct their team's time, without also handing them clients, invoices, subscription and everyone else's costs.

Reserve Admin for the people who genuinely run the workspace. An admin can change company settings, see every rate and cost, invoice, and archive other users. See inviting your team for how to set a role, and how to remove access when someone leaves.

Still stuck?

Open a support ticket and tell us your workspace name and what you were trying to do. A real person answers, usually within one working day.