Who sees what, decided in two layers.
A route-level gate decides whether a module is reachable at all. Row-level scoping then decides which records inside it a person actually sees. Both run on every request, and the order is load-bearing.
- independent layers
- 2independent layers
- access levels
- 4access levels
- shared implementation
- 1shared implementation
Access roles
Fieldstone workspaceAssigned work only
Leads
EditProjects
ViewTasks
EditReports
ViewBilling
DisabledClick a module to switch it off for the whole company. The company ceiling is checked before role — no override inside the company reopens it.
Rows returned
Own + assigned + collaborator + team
The path a record actually takes.
- 01
The company ceiling is checked first
Modules switched off for the company are unreachable before role is even considered, so nothing inside the company can widen it back open.
- 02
Then role and override
Admins and super admins pass. Everyone else is measured against their access role, or a per-module override set just for them.
- 03
Then the rows are scoped
Past the gate, a rep still only sees records they own, are assigned, collaborate on, or share a team with. Admins see everything.
- 04
The same rules everywhere
The HTTP layer and the agent tools call the same implementation, so the two paths cannot drift apart.
What you get.
Company module gates
Turn a whole module off for the company and nobody inside can reopen it.
Access roles
Reusable permission sets, assigned per person.
Per-module overrides
Widen or narrow one module for one person without a new role.
Row-level scope
Own, assigned, collaborator, and team — the four ways a record reaches a rep.
Admin and super admin
Two tiers that see everything, for the people who need to.
One implementation
Route checks and tool calls share the same code path, by design.
Never rebuild the same project twice.
We set up your workspace and your first admin. Your team joins by invite, and the next deal you close arrives as a project that is already moving.
- We set up your workspace
- Your team joins by invite
- Bring the pipeline you have
Prefer to talk first?
- 01
Deal marked Closed/Won
One status change
- 02
Project, milestones, 5 tasks
Drafted from the conversation
- 03
#harborview-onboarding
Channel opened, kickoff posted
- 04
Owner notified
In-app and browser push
Every step above runs from one status change.