What is an object role?
An object role gives an employee extra permissions that apply only within the selected object(s), for example a specific construction site or service location.
Important: An object role adds permissions for the selected objects, but it never limits the employee's main permissions. If the employee's main permissions already let them view or edit data across the whole company, they keep that right after an object role is assigned. An object role can never take away or narrow anyone's existing permissions.
Requirements
Your company must be using the Objects module.
Only employees with the Administrator permission level can create or change object roles, meaning decide what a role allows. No other permission level can do this, however many other permissions it has.
More people can assign an existing object role to someone. This includes an employee who has edit rights on that object and already has at least the same level of access. For example, they already have that role, or their own permissions cover everything the role would give. An Administrator can always assign anything.
Step 1: Create an object role
Go to Configure → Permissions → Object roles:
Give the role a name (e.g. "Site manager").
For each data set (e.g. working time, documents), choose whether the role gives No rights, Can view or Can edit. This is one ranked choice, not two separate checkboxes. If you choose Can edit, you automatically get view rights too.
If needed, allow the role to use the timer when adding working times (see below).
Step 2: Assign the object role to an employee and an object
You can link a role from either side:
On the employee's profile page (the Object roles panel): choose the object role and one or more objects or object groups it applies to.
On the object's page: the other way round. Assign the role to several employees on the same object at once.
You can also set a validity period:
If you leave the start date empty, the role is valid straight away.
If you leave the end date empty, the role has no end date.
If you set an end date, the role is valid up to and including that date. Access ends automatically from the next day, so you don't need to delete anything by hand.
Step 3: Check the permissions
After assigning the role, it's a good idea to check the employee's profile to see which objects and roles apply to them.
Permission to add working times with the timer
This permission only lets the employee start and stop the working time timer (the start and end time of their work) on the selected object. It doesn't let them view or edit working time entries. That needs its own separate permission.
Example
Need | Solution |
A site manager needs extra permissions to manage their own object's data | An object role linked to that specific object |
An employee should be able to clock in and out with the timer on one object only | An object role that only allows adding working time with the timer |
Good to know
An object role only adds permissions. It never takes anything away.
Changes (assigning or removing a role) take effect straight away. The user doesn't need to log out and back in.
When you deactivate an employee, you can choose whether to also remove all object roles linked to that employee.
You can't give anyone an object role that would give them more permissions than you have yourself.



