Roles & visibility

Who sees what, decided in two layers.

A route-level gate decides whether a module is reachable at all. Row-level scoping then decides which records inside it a person actually sees. Both run on every request, and the order is load-bearing.

independent layers
2independent layers
access levels
4access levels
shared implementation
1shared implementation

Access roles

Fieldstone workspace

Assigned work only

Leads

Edit

Projects

View

Tasks

Edit

Reports

View

Billing

Disabled

Click a module to switch it off for the whole company. The company ceiling is checked before role — no override inside the company reopens it.

Rows returned

Own + assigned + collaborator + team

How it works

The path a record actually takes.

  1. 01

    The company ceiling is checked first

    Modules switched off for the company are unreachable before role is even considered, so nothing inside the company can widen it back open.

  2. 02

    Then role and override

    Admins and super admins pass. Everyone else is measured against their access role, or a per-module override set just for them.

  3. 03

    Then the rows are scoped

    Past the gate, a rep still only sees records they own, are assigned, collaborate on, or share a team with. Admins see everything.

  4. 04

    The same rules everywhere

    The HTTP layer and the agent tools call the same implementation, so the two paths cannot drift apart.

What you get.

Company module gates

Turn a whole module off for the company and nobody inside can reopen it.

Access roles

Reusable permission sets, assigned per person.

Per-module overrides

Widen or narrow one module for one person without a new role.

Row-level scope

Own, assigned, collaborator, and team — the four ways a record reaches a rep.

Admin and super admin

Two tiers that see everything, for the people who need to.

One implementation

Route checks and tool calls share the same code path, by design.

Start hereYour next won deal

Never rebuild the same project twice.

We set up your workspace and your first admin. Your team joins by invite, and the next deal you close arrives as a project that is already moving.

  • We set up your workspace
  • Your team joins by invite
  • Bring the pipeline you have

Prefer to talk first?

  1. Deal marked Closed/Won

    One status change

    01
  2. Project, milestones, 5 tasks

    Drafted from the conversation

    02
  3. #harborview-onboarding

    Channel opened, kickoff posted

    03
  4. Owner notified

    In-app and browser push

    04

Every step above runs from one status change.