Management · 09
Roles and access
Who can do what: CTO, CEO, Staff and Read Only, and the permission list.
Claimpanel uses roles made of permissions. A permission is a single thing you may do (for example claims.create). Each person has one role. This chapter is for the CEO and CTO, who manage access.
The four roles
CTO
Technical administrator. Holds every permission, and is the only role that manages storage nodes, email delivery and SMS delivery. Only a CTO can manage another CTO.
CEO
Holds every permission: operations, pricing, users, finance and reporting. The only role (with the CTO) that can reopen a closed claim, edit a note and reopen the financial ledger. Does not manage the three technical pages above.
Staff
Runs claims from intake to completion: surveys, scopes, contractor quotes and awards, work orders, scheduling, contractors, documents, insurers and policyholders. Sees no finance and no business reports, cannot override markup, manage users or change settings.
Read Only
Looks, never changes. Sees claims, surveys, scopes, insurer quotes, work orders, the diary, the network, documents and reports, but never contractor prices or margins. Suited to an accountant or auditor.
The business has few people, and each runs a claim end to end. Finance and reporting stay with whoever owns the business, so a hired employee sees operations without seeing money. Roles are lists written out in full: none "inherits" from another, so adding a permission later never silently widens a role.
Permission matrix
This table is generated from the application's own role definitions. ✓ means the role holds the permission. The CTO and CEO hold all of them.
| Permission | Lets you | CTO / CEO | Staff | Read Only |
|---|---|---|---|---|
| Claims | ||||
claims.view | Open claims you are involved in | ✓ | ✓ | ✓ |
claims.view.all | See every claim in the organisation | ✓ | ✓ | ✓ |
claims.create | Add a claim | ✓ | ✓ | – |
claims.update | Change claim data, record steps, amend details | ✓ | ✓ | – |
claims.assign | Assign a claim handler | ✓ | ✓ | – |
claims.reopen | Reopen a closed claim | ✓ | – | – |
claims.close | Close a claim | ✓ | ✓ | – |
claims.notes.edit | Rewrite a note after it is written | ✓ | – | – |
claims.flags.manage | Set and clear claim flags | ✓ | ✓ | – |
claims.triage.manage | Record the discovery-call triage | ✓ | ✓ | – |
claims.investigation.view | See investigation indicators | ✓ | ✓ | – |
claims.investigation.manage | Manage investigation indicators | ✓ | ✓ | – |
| Complaints | ||||
complaints.view | See complaints | ✓ | ✓ | ✓ |
complaints.manage | Log and resolve complaints | ✓ | ✓ | – |
| Tasks | ||||
tasks.manage | Create and complete tasks | ✓ | ✓ | – |
| Inspections | ||||
inspections.view | See surveys | ✓ | ✓ | ✓ |
inspections.conduct | Conduct a survey and write the report | ✓ | ✓ | – |
| Scope | ||||
scopes.view | See the scope of work | ✓ | ✓ | ✓ |
scopes.manage | Build and edit the scope and schedule | ✓ | ✓ | – |
| Quoting | ||||
quotes.contractor.view | See what contractors charge (commercially sensitive) | ✓ | ✓ | – |
quotes.contractor.request | Send requests for quotation | ✓ | ✓ | – |
quotes.contractor.enter | Enter returned contractor prices | ✓ | ✓ | – |
quotes.contractor.award | Award a contractor | ✓ | ✓ | – |
quotes.insurer.view | See insurer quotes (client rates) | ✓ | ✓ | ✓ |
quotes.insurer.build | Build the insurer schedule | ✓ | ✓ | – |
quotes.insurer.submit | Issue the schedule to the insurer | ✓ | ✓ | – |
quotes.markup.override | Override the standard markup | ✓ | – | – |
quotes.margin.view | See the gap between client and contractor rates | ✓ | ✓ | – |
| Work orders | ||||
workorders.view | See work orders | ✓ | ✓ | ✓ |
workorders.create | Create work phases and orders | ✓ | ✓ | – |
workorders.assign | Assign contractors and raise purchase orders | ✓ | ✓ | – |
workorders.complete | Validate completed work | ✓ | ✓ | – |
| Scheduling | ||||
scheduling.view | See the diary | ✓ | ✓ | ✓ |
scheduling.manage | Book and move surveys | ✓ | ✓ | – |
| Network | ||||
contractors.view | See the network | ✓ | ✓ | ✓ |
contractors.manage | Edit network members | ✓ | ✓ | – |
contractors.compliance | Review and approve compliance records | ✓ | ✓ | – |
| Finance | ||||
finance.view | See the Finance queue and claim finances | ✓ | – | – |
finance.invoice.issue | Issue sales invoices and credit notes | ✓ | – | – |
finance.payment.record | Record payments, receipts and bank details | ✓ | – | – |
finance.margin.view | See cost and margin figures | ✓ | – | – |
| Documents | ||||
documents.view | See claim documents | ✓ | ✓ | ✓ |
documents.upload | Upload documents | ✓ | ✓ | – |
documents.delete | Remove documents | ✓ | ✓ | – |
| Insurers | ||||
insurers.view | See insurers | ✓ | ✓ | ✓ |
insurers.manage | Edit insurers and contacts | ✓ | ✓ | – |
| Policyholders | ||||
customers.view | See policyholders and properties | ✓ | ✓ | ✓ |
customers.manage | Edit policyholders and properties | ✓ | ✓ | – |
| Reports | ||||
reports.view | See the Reports queue | ✓ | – | ✓ |
| Administration | ||||
admin.users.manage | Invite users and change roles | ✓ | – | – |
admin.settings.manage | Change organisation settings | ✓ | – | – |
admin.audit.view | See the audit log | ✓ | – | – |
Permissions that expose what we pay or what we earn are quotes.contractor.*, quotes.markup.override, quotes.margin.view and finance.margin.view. Grant them only where genuinely needed. Cost and margin figures in the Finance and Reports exports require both margin and contractor-pricing permissions.
Adding a person
- Administration → Users → Invite teammate
Needs
admin.users.manage(CEO, CTO). Enter their name and work email and choose a role. - They receive an invitation email
It contains a one-time link to set their own password. You never see or set their password.
- They verify their email and sign in
An unverified address cannot use the panel.
- Encourage two-factor
The Users list shows Protected or Not enrolled for each person. It is optional by decision, but recommended for anyone with finance access.
Changing someone's role
Users → Manage access → choose a role → Save access. The selected role replaces the current one. The role cards show what each includes.
| Rule | Effect |
|---|---|
| You cannot change your own role. | Stops anyone granting themselves more access. |
| You can never remove or deactivate your own account. | Stops the last administrator locking everyone out. |
| Only a CTO can manage a CTO account. | The technical superuser is protected. |
| You can only manage people in your own organisation. | Organisation boundary. |
| You can always edit your own name and email. | So a typo does not need an administrator. |
| An administrator can change someone's email, which must be re-verified. | An address nobody confirmed cannot keep working. |
The Users screen has no remove or deactivate button at this version (the permission rule exists for when one is added). Straight away, change their role to Read Only and ask the CTO to remove the account. Their name stays on the history of what they did: records are never rewritten.
After a release adds a permission
New permissions reach the database only when the CTO runs php artisan claimpanel:sync-permissions. The CEO and CTO pass every check regardless, so they are never locked out by a missed sync, but Staff and Read Only will not see a new feature until it has run.
Two-factor authentication
- Optional, per person, from the account menu.
- Uses any authenticator app. Recovery codes are shown once at set-up: store them safely.
- If a person loses both their device and their recovery codes, tell the CTO: there is no self-service recovery beyond the codes.
- Password rules: the framework default minimum strength, entered twice.
What each role actually sees
| Screen | CTO / CEO | Staff | Read Only |
|---|---|---|---|
| Overview, Claims, Tasks | ✓ | ✓ | View only |
| Contractor prices on a claim | ✓ | ✓ | Hidden |
| Insurer quotes (client rates) | ✓ | ✓ | View only |
| Finance queue, invoices, payments | ✓ | Hidden | Hidden |
| Reports queue | ✓ | Hidden | View only |
| Administration (users, settings) | ✓ (CEO: not email/SMS/storage) | Hidden | Hidden |
| Email, SMS, Storage settings | CTO only | Hidden | Hidden |
| Reopen a closed claim, edit a note | ✓ | Hidden | Hidden |