A permission mask merged over the tenant role a staff member receives inside an account. It turns off invoice viewing, contract viewing and change-order viewing, and it is applied by writing it onto the staff member's identity metadata so the client-side permission layer honours it the same way it honours any other permission.
Also called: support can't see invoices · vendor staff money mask · hide contract values from support
- 1A staff member entering an account is given a tenant role derived from their platform role — admin for owner and admin, project manager for support, sales for sales.
- 2The money mask is merged into their custom permissions at the same time.
- 3Metadata is written only when it actually differs, so the normal path costs no extra call, and it self-heals: promoting someone reconciles on their next request.
- 4Estimates are deliberately not masked.
The constant is introduced with the quote that produced it: 'Keith 08-12: the admins don't need to be able to see the money either.' The scope is drawn carefully in the same comment: 'Platform staff run the account — contacts, pipeline, estimates, projects, scheduling, comms — but the builder's billing is not theirs to read.' And the exclusion is argued rather than assumed: 'Deliberately NOT masking estimates: staff are there to help build and send quotes, and an estimate without figures is not usable. The line is drawn at money already committed or owed.'
- Helping inside an account meant seeing everything in it, including money already owed.
- A flat grant of tenant admin gave vendor staff more than their job requires.
- Masking estimates too would have made the help useless.
See it on your own jobs
Twenty minutes, your numbers, no slide deck. We’ll build one of your real buildings in front of you and send you the estimate link at the end — yours to keep either way.
or keep browsing features →