Available roles
LupinusBuild currently defines six company roles. Each role is evaluated by the application before protected actions are made available.
Primary Admin
Executive-level access to company administration, team management, financials, and operational workflows.
CFO
Executive-level financial and operational access, including company, team, expense, and project-financial management.
Admin
Broad operational administration across customers, quotes, projects, tasks, files, and materials without executive financial access.
Manager
Operational management access for creating and editing customer, quote, project, task, file, and material workflows.
Field User
Field-oriented access for project viewing, task execution, file uploads, material activity, and project-status updates.
Viewer
Read-only access to supported company, customer, quote, project, and team information.
Executive access
Primary Admin and CFO are treated as executive-access roles. Executive access controls several higher-sensitivity areas of the workspace.
Operational access does not automatically provide executive financial access. This allows project execution and sensitive financial information to be controlled separately.
Permission matrix
The following matrix reflects the current application permission rules.
| Capability | Primary Admin | CFO | Admin | Manager | Field User | Viewer |
|---|---|---|---|---|---|---|
| Company management | Yes | Yes | — | — | — | — |
| Team management | Yes | Yes | — | — | — | — |
| View financials | Yes | Yes | — | — | — | — |
| Manage expenses | Yes | Yes | — | — | — | — |
| Create / edit quotes | Yes | Yes | Yes | Yes | — | — |
| Delete quotes | Yes | Yes | Yes | — | — | — |
| Create / edit customers | Yes | Yes | Yes | Yes | — | — |
| Delete customers | Yes | Yes | Yes | — | — | — |
| Create / edit projects | Yes | Yes | Yes | Yes | — | — |
| Delete projects | Yes | Yes | Yes | — | — | — |
| Manage project financials | Yes | Yes | — | — | — | — |
| Create tasks | Yes | Yes | Yes | Yes | Yes | — |
| Assign tasks | Yes | Yes | Yes | Yes | — | — |
| Complete tasks | Yes | Yes | Yes | Yes | Yes | — |
| Delete tasks | Yes | Yes | Yes | Yes | — | — |
| Upload project files | Yes | Yes | Yes | Yes | Yes | — |
| Delete project files | Yes | Yes | Yes | Yes | — | — |
| Create materials | Yes | Yes | Yes | Yes | Yes | — |
| Edit / delete materials | Yes | Yes | Yes | Yes | — | — |
| Update material status | Yes | Yes | Yes | Yes | Yes | — |
| Update project status | Yes | Yes | Yes | Yes | Yes | — |
Field User access
Field User is an operational role rather than a read-only role. Field Users can view customers, quotes, projects, and the team list while also participating in selected project workflows.
Field Users cannot assign or delete tasks, delete project files, edit or delete materials, create or edit quotes, create or edit customers, or create or edit projects under the current permission rules.
Viewer access
Viewer is the application's view-only role.
Viewers can access supported customer, quote, project, and team information, but the operational create, edit, delete, status, upload, assignment, and completion permissions documented here are not granted to Viewer accounts.
Permission model
LupinusBuild evaluates individual capabilities instead of relying only on a broad role name. This is why actions such as creating a task, assigning a task, completing a task, and deleting a task can have different permission requirements.
The same principle applies to project files, materials, customer records, quotes, projects, company administration, and financial access.
LupinusBuild is currently in pilot. Roles and individual permissions may continue to evolve as the product expands to additional company workflows.
