Configure roles and permissions
Last updated July 23, 2026
Roles provide a repeatable set of permissions for people who do similar work. Use them to give staff the access they need while keeping company settings, financial actions, and sensitive work limited to the right people.
Before you begin
Only authorized administrators should change roles. Review who currently uses a role before removing access because a saved change affects every staff member assigned to that role.
Open Role Permissions Management
Go to Settings → People → Roles & Permissions.
- Choose Office Permissions for office roles or Technician Permissions for field roles.
- Open Select Office Role or Select Technician Role.
- Choose the role you want to review.
- Review the selected-permission summary before making changes.
Office and technician roles have different permission groups, so review the correct tab first.
Change a role's permissions
- Select the role.
- Open each permission category that applies to the role's work.
- Turn on individual permissions the role needs.
- Turn off permissions that are no longer appropriate.
- Use a category-level selection only when the role should receive every permission in that category.
- Review the permission count and any partially selected categories.
- Click Save Changes.
Use the smallest practical access set. For example, a person who prepares invoices may need to view and edit them but may not need to manage company-wide accounting or payment settings.
Partially selected categories contain a mix of enabled and disabled permissions.
Cancel unsaved changes
- Before saving, click Cancel.
- Confirm the selected permissions return to the role's saved state.
- If needed, select another role and return to verify no unintended change remains.
Verify a staff member's access
- Go to Settings → People → Staff.
- Find the person and open the three-dot Actions menu.
- Select View permissions.
- Confirm their assigned role and access summary.
- If the role is wrong, edit the staff member rather than changing a shared role to solve one person's assignment.
Use business unit assignments and security for access that depends on team or unit membership.
What happens next
Staff assigned to the changed role receive its saved permission set. The pages and actions they can see may change the next time the interface refreshes.
Troubleshooting
A permission change appears to have no effect
Confirm you changed the role assigned to that staff member. Save the role, then ask the staff member to refresh Nexus and reopen the workspace.
An action is unavailable even though the role looks correct
The action may also require business unit assignment, feature availability, record access, or another prerequisite. Review the staff member's assignments and security.
The wrong group of permissions appears
Check whether you selected Office Permissions or Technician Permissions, then choose the role again.