- Workspace Admin - The most privileged role in the workspace that has access to all information and settings. As explained below, this is a read-only role.
- Senior Member - This role is identical to the Workspace Admin role except that its members will not be able to access workspace settings or administer workspace members.
- Standard Member - The Standard Member can access clients and projects where they are on the project team. On those projects, they can view time and expense for all project team members. If this member is a Project Admin on a project, they can administer and approve time and expense for those projects. This role can view resource allocations for projects where they are on the project team. If this member is a Project Admin on a project, they can administer resource allocations for that project.
- Restricted Member - The default Security Role. A restricted role whose members can only access projects they are assigned to. Additionally, these members cannot view time or expense entries of other members, nor can they view invoices, bill rates, revenue, or profit.
View Security Roles
To view the list of current security roles for your workspace, click the Settings main nav bar option and then select the Security Roles menu option (Figure 1). From here you can edit or export your security roles. In order to access the workspace settings, your assigned security role must have the Administer all workspace settings and members permission. The Workspace Admin role is the only built-in security role that has this permission.
Figure 1 - Security Roles in the Settings Area

Figure 2 - Administering Security Roles
Create a Security Role
To create a new security role, click the + button at the top-right of the security roles list. This will bring up the new security role drawer (Figure 3). Type in a name and optional description for the new role.
Figure 3 - Creating a new Security Role
Workspace Admin Permissions
When creating / editing a security role in the Security Role drawer (Figure 3), you will always see a Workspace Admin Permissions section (Figure 4). It is important to note that this section, while always visible, is unavailable to any security role in the workspace other than the built-in Workspace Admin role, which is why it appears greyed out in the image below (Figure 4). As a Workspace Admin with these permissions, a member can manage the workspace settings including the ability to administer workspace members.
Figure 4 - Workspace Admin Permissions (Only Available for Built-in Workspace Admin Security Role)
Company Permissions
If your workspace has the Pipeline feature enabled, you will have a Company Permissions section available (Figure 5). These permissions determine whether a member can create, view, edit, and delete companies in the Pipeline area of Ruddr. Company, Opportunity, and Contact permissions are each independent rulesets — granting access to one does not grant access to the others.
Figure 5 - Align Company Permissions to a Security Role
- All companies
- Companies assigned to that member’s business unit (when the Business Units feature is enabled)
- Companies assigned to that member’s practice
- Companies this member owns
- All companies this member can access
- Companies assigned to that member’s business unit (when enabled)
- Companies assigned to that member’s practice
- Companies this member owns
Opportunity Permissions
If your workspace has the Pipeline feature enabled, you will have an Opportunity Permissions section available (Figure 6), structured identically to Company Permissions above.
Figure 6 - Align Opportunity Permissions to a Security Role
- All opportunities
- Opportunities assigned to that member’s business unit (when enabled)
- Opportunities assigned to that member’s practice
- Opportunities this member owns
Contact Permissions
Contact Permissions are always available, whether or not the Pipeline feature is enabled for your workspace — contacts and the ability to manage them are independent of Pipeline. Turning Pipeline on or off never changes who can create, view, edit, or delete contacts.
Figure 7 - Align Contact Permissions to a Security Role
- All contacts
- Contacts assigned to that member’s business unit (when enabled)
- Contacts assigned to that member’s practice
- Contacts this member owns
- If a member can view a company, opportunity, or contact, they can see its activity feed.
- If a member can edit that parent record, they can create, edit, and delete activities on it.
- The activity feed shown on a contact is always read-only, even for a member who can edit the contact, since contact activities are logged through the related company or opportunity rather than the contact itself.
Member Permissions
The Member Permissions for a security role establish the access that a member has to time and expenses for another member or members. Additionally, this permission set controls access to other members’ resource allocations. There are two permissions “concepts” with regards to Time and Expenses and Resource Allocations:- Administer - This permissions concept enables View, Edit, and Delete permissions for time and expense entries and / or resource allocations. In addition, Administer grants permissions for approving time and expense entries, and submitting/un-submitting time and expense entries. Additionally, if your workspace has the Timesheets feature enabled, Administer grants permission to submit / un-submit timesheets.
- View - This permissions concept enables read-only View permissions for time and expense entries and resource allocations.

Figure 8 - Align Member Permissions to a Security Role
Time and Expense
- Administer time and expenses for:
- View time and expenses for:
Resource Allocations
- Administer resource allocations for:
- View resource allocations for:
Client Permissions
The client permissions (Figure 9) control the user’s ability to access, create, edit, and delete clients, and to manage permissions on other actions for clients as well. These settings determine if the user can access all clients and projects in the workspace or just those where the user is on a project team for the client. By default (as shown in Figure 9), each Security Role grants access to any clients to which a member is assigned to that clients’ projects.
Figure 9 - Align Client Permissions to a Security Role
- All clients
- Clients assigned to this member’s practice (Reference Custom Data for more information on practices)
- Clients where this member is assigned to a project
- All clients
- Clients assigned to that member’s business unit (when the Business Units feature is enabled)
- Clients assigned to that member’s practice
- Those clients where the member is assigned to a project
- Edit
- Delete or archive
- Administer published invoices
- Administer draft invoices
- View published invoices

Figure 10 - Assigning Client Access to Client Permissions
- Administer published invoices
- Administer draft invoices
- View published invoices
- Administer draft invoices
- View published invoices

Figure 11 - Example of Permissions Inheritance for Client Invoices
- Delete or archive clients will grant:
- Access all projects within an accessible client
- Delete or archive projects
- Administer published invoices will grant:
- Access all projects within an accessible client
- View time entries and expense items on accessible projects
- View bill rates on accessible projects
- View revenue on accessible projects
- Publish invoices for accessible projects
- Administer invoices for accessible projects
- View published invoices for accessible projects
- Administer draft invoices will grant:
- Access all projects within an accessible client
- View time entries and expense items on accessible projects
- View bill rates on accessible projects
- View revenue on accessible projects
- Create and draft invoices for accessible projects
- View published invoices for accessible projects
- View published invoices will grant:
- Access all projects within an accessible client
- View time entries and expense items on accessible projects
- View bill rates on accessible projects
- View revenue on accessible projects
- View published invoices for accessible projects
Project Permissions
The project permissions (Figure 12) control the user’s ability to access, create, edit, and delete clients, and to manage permissions regarding time and expenses for projects as well. These settings determine if the user can access all projects in the workspace or just those where the user is on a project team for the client. By default (as shown in Figure 12), each Security Role grants access to any project to which a member is on that project team. The project permissions also control whether members will have access to potentially sensitive project data such as invoices, bill rates, revenue, and profit margin.
Figure 12 - Subset of Project Permissions Available for Security Role Assignment
- Clients where this member is assigned to project
- Projects where this member is on the project team
- Projects where this member is the Project Admin
- Bill rates for projects where the member is the Project Admin
- Revenue for the projects where the member is the Project Admin

Figure 13 - The Green Badge with Checkmark Indicates the Project Admin
- All projects
- Projects assigned to that member’s business unit (when the Business Units feature is enabled)
- Projects assigned to that member’s practice
- Projects where the member is on the project team
- Edit - Edit the project details including the team, tasks, roles, rates, and budget. You can also limit which sections of a project the role can edit, as described in Edit Project Permissions.
- Delete or archive - Delete or archive the project.
- Administer published invoices
- Administer draft invoices
- View published invoices
- Administer time entries and expense items - Manage all time and expense entries on the project.
- View time entries and expense items - If a billable member does not have this permission, the member can only view his or her own time entries.
- Administer resource allocations - Manage all resource allocations for a project.
- View resource allocations
- View bill rates
- View revenue
- View profit
- Administer project health reports
- View project health

Figure 14 - Assigning Project Access to Project Permissions
- Edit will grant:
- View bill rates on projects
- View revenue on projects
- Administer published invoices
- Administer draft invoices
- View published invoices
- Administer draft invoices
- View published invoices
- Administer time entries and expense items will grant:
- View time entries and expense items
Set a Default Security Role
Ruddr provides the ability for you to specify a default security role. This default is designated in the Security Roles section (Figure 2) as a black badge with a checkmark (Figure 15).
Figure 15 - In this Example, Restricted Member is set as the Default Security Role for the Workspace

Figure 16 - Select Set to default from the Dropdown to Establish that Security Role as the Default for the Workspace
Clone a Security Role
Often times, it may be necessary to create a security role that closely mimics another security role. To assist with creating these types of closely-related roles, Ruddr allows Workspace Admins to clone existing security roles. You can generate an exact copy of an existing role and then have the ability to modify that new copy to fit the permissions needed. To do this, select Clone from the menu for a specific role (Figure 17), accessible from the Security Roles section (Figure 2). Give the role a new name (Figure 18) and click Save to create your new role.
Figure 17 - Select Clone from the Dropdown to Create an Exact Replica of a Security Role

Figure 18 - Provide a Name Your new Security Role that was Created as a Clone of an Existing Role
Deactivate a Security Role
To prevent the future assignment of a security role to member, a security role can be deactivated. This will take the security role out of the list of available security roles to be assigned to a member. Deactivating a security role does not prevent the login of any users assigned to that security role, nor will inhibit their current permissions. While deactivated, a security role can be edited, cloned, or deleted. However, per the conditions outlined in Delete a Security Role, the Delete menu item will be disabled if any members are assigned to the security role. To deactivate an active security role, select Deactivate from the menu for a specific role (Figure 19), accessible from the Security Roles section (Figure 2). When deactivated, a security role is greyed out in the Security Roles section (Figure 20).
Figure 19 - Select Deactivate from the Dropdown to Prohibit a Security Role from being Assigned to a Member

Figure 20 - The Senior Member Security Role has been Deactivated

Figure 21 - Reactivate a Deactivated Security Role
Delete a Security Role
A security role can only be deleted when there are no members assigned to the role. In this case, the Delete menu item for a security role will be disabled (Figure 16) and the number of Active Users will be shown as more than zero (Figure 16). The Members section of the workspace settings displays each project member and their assigned security role. Additionally, you can filter this list by security role to find all members assigned to a particular role. Once all members have been removed from the security role (or reassigned to another role), that security role can be deleted. To delete the security role, select Delete from the menu for a specific role (Figure 22), accessible from the Security Roles section (Figure 2). When asked for confirmation (Figure 23), click Delete to finalize the removal of the security role.
Figure 22 - Select Delete from the Dropdown to Delete a Security Role once all Members have been Removed

Figure 23 - Confirm Deletion of Security Role