Claimpanel guide

Management · 09

Roles and access

Who can do what: CTO, CEO, Staff and Read Only, and the permission list.

Claimpanel uses roles made of permissions. A permission is a single thing you may do (for example claims.create). Each person has one role. This chapter is for the CEO and CTO, who manage access.

The four roles

Protected

CTO

Technical administrator. Holds every permission, and is the only role that manages storage nodes, email delivery and SMS delivery. Only a CTO can manage another CTO.

Business leader

CEO

Holds every permission: operations, pricing, users, finance and reporting. The only role (with the CTO) that can reopen a closed claim, edit a note and reopen the financial ledger. Does not manage the three technical pages above.

Operations

Staff

Runs claims from intake to completion: surveys, scopes, contractor quotes and awards, work orders, scheduling, contractors, documents, insurers and policyholders. Sees no finance and no business reports, cannot override markup, manage users or change settings.

Visibility

Read Only

Looks, never changes. Sees claims, surveys, scopes, insurer quotes, work orders, the diary, the network, documents and reports, but never contractor prices or margins. Suited to an accountant or auditor.

Why only four?

The business has few people, and each runs a claim end to end. Finance and reporting stay with whoever owns the business, so a hired employee sees operations without seeing money. Roles are lists written out in full: none "inherits" from another, so adding a permission later never silently widens a role.

Permission matrix

This table is generated from the application's own role definitions. ✓ means the role holds the permission. The CTO and CEO hold all of them.

PermissionLets youCTO / CEOStaffRead Only
Claims
claims.viewOpen claims you are involved in✓✓✓
claims.view.allSee every claim in the organisation✓✓✓
claims.createAdd a claim✓✓–
claims.updateChange claim data, record steps, amend details✓✓–
claims.assignAssign a claim handler✓✓–
claims.reopenReopen a closed claim✓––
claims.closeClose a claim✓✓–
claims.notes.editRewrite a note after it is written✓––
claims.flags.manageSet and clear claim flags✓✓–
claims.triage.manageRecord the discovery-call triage✓✓–
claims.investigation.viewSee investigation indicators✓✓–
claims.investigation.manageManage investigation indicators✓✓–
Complaints
complaints.viewSee complaints✓✓✓
complaints.manageLog and resolve complaints✓✓–
Tasks
tasks.manageCreate and complete tasks✓✓–
Inspections
inspections.viewSee surveys✓✓✓
inspections.conductConduct a survey and write the report✓✓–
Scope
scopes.viewSee the scope of work✓✓✓
scopes.manageBuild and edit the scope and schedule✓✓–
Quoting
quotes.contractor.viewSee what contractors charge (commercially sensitive)✓✓–
quotes.contractor.requestSend requests for quotation✓✓–
quotes.contractor.enterEnter returned contractor prices✓✓–
quotes.contractor.awardAward a contractor✓✓–
quotes.insurer.viewSee insurer quotes (client rates)✓✓✓
quotes.insurer.buildBuild the insurer schedule✓✓–
quotes.insurer.submitIssue the schedule to the insurer✓✓–
quotes.markup.overrideOverride the standard markup✓––
quotes.margin.viewSee the gap between client and contractor rates✓✓–
Work orders
workorders.viewSee work orders✓✓✓
workorders.createCreate work phases and orders✓✓–
workorders.assignAssign contractors and raise purchase orders✓✓–
workorders.completeValidate completed work✓✓–
Scheduling
scheduling.viewSee the diary✓✓✓
scheduling.manageBook and move surveys✓✓–
Network
contractors.viewSee the network✓✓✓
contractors.manageEdit network members✓✓–
contractors.complianceReview and approve compliance records✓✓–
Finance
finance.viewSee the Finance queue and claim finances✓––
finance.invoice.issueIssue sales invoices and credit notes✓––
finance.payment.recordRecord payments, receipts and bank details✓––
finance.margin.viewSee cost and margin figures✓––
Documents
documents.viewSee claim documents✓✓✓
documents.uploadUpload documents✓✓–
documents.deleteRemove documents✓✓–
Insurers
insurers.viewSee insurers✓✓✓
insurers.manageEdit insurers and contacts✓✓–
Policyholders
customers.viewSee policyholders and properties✓✓✓
customers.manageEdit policyholders and properties✓✓–
Reports
reports.viewSee the Reports queue✓–✓
Administration
admin.users.manageInvite users and change roles✓––
admin.settings.manageChange organisation settings✓––
admin.audit.viewSee the audit log✓––
The sensitive set

Permissions that expose what we pay or what we earn are quotes.contractor.*, quotes.markup.override, quotes.margin.view and finance.margin.view. Grant them only where genuinely needed. Cost and margin figures in the Finance and Reports exports require both margin and contractor-pricing permissions.

Adding a person

  1. Administration → Users → Invite teammate

    Needs admin.users.manage (CEO, CTO). Enter their name and work email and choose a role.

  2. They receive an invitation email

    It contains a one-time link to set their own password. You never see or set their password.

  3. They verify their email and sign in

    An unverified address cannot use the panel.

  4. Encourage two-factor

    The Users list shows Protected or Not enrolled for each person. It is optional by decision, but recommended for anyone with finance access.

Changing someone's role

Users → Manage access → choose a role → Save access. The selected role replaces the current one. The role cards show what each includes.

RuleEffect
You cannot change your own role.Stops anyone granting themselves more access.
You can never remove or deactivate your own account.Stops the last administrator locking everyone out.
Only a CTO can manage a CTO account.The technical superuser is protected.
You can only manage people in your own organisation.Organisation boundary.
You can always edit your own name and email.So a typo does not need an administrator.
An administrator can change someone's email, which must be re-verified.An address nobody confirmed cannot keep working.
When someone leaves

The Users screen has no remove or deactivate button at this version (the permission rule exists for when one is added). Straight away, change their role to Read Only and ask the CTO to remove the account. Their name stays on the history of what they did: records are never rewritten.

After a release adds a permission

New permissions reach the database only when the CTO runs php artisan claimpanel:sync-permissions. The CEO and CTO pass every check regardless, so they are never locked out by a missed sync, but Staff and Read Only will not see a new feature until it has run.

Two-factor authentication

  • Optional, per person, from the account menu.
  • Uses any authenticator app. Recovery codes are shown once at set-up: store them safely.
  • If a person loses both their device and their recovery codes, tell the CTO: there is no self-service recovery beyond the codes.
  • Password rules: the framework default minimum strength, entered twice.

What each role actually sees

ScreenCTO / CEOStaffRead Only
Overview, Claims, Tasks✓✓View only
Contractor prices on a claim✓✓Hidden
Insurer quotes (client rates)✓✓View only
Finance queue, invoices, payments✓HiddenHidden
Reports queue✓HiddenView only
Administration (users, settings)✓ (CEO: not email/SMS/storage)HiddenHidden
Email, SMS, Storage settingsCTO onlyHiddenHidden
Reopen a closed claim, edit a note✓HiddenHidden