# Roles and permissions

Every role and every permission, filterable.

ToolboxFM decides what you can do from your **role**, never from a check on the screen you are looking
at. This page is the complete list.

## The roles

| Role | Scope | Priority |
| --- | --- | --- |
| **Head Office** | Organisation-wide | 1 (highest) |
| **Project Supervisor** | One project | 2 |
| **Subcontractor Supervisor** | One project | 3 |
| **User** | One project | 4 |

Priority matters when somebody holds more than one role: ToolboxFM resolves them to the
highest-privilege role they hold.

## Who can grant what

| You are | You can give |
| --- | --- |
| Head Office | Any role, including Head Office |
| Project Supervisor | Project Supervisor, Subcontractor Supervisor, User |

## Permission matrix

Filter by permission name, or untick a role to take it out of the table.

:::note
The scope column is the part people get wrong. A permission scoped to **one project** is checked against
your role on the project in question, so being a Project Supervisor at one job gives you nothing at another.
:::

:::note
`work_activity:update` lets a Subcontractor Supervisor file a close-out for their own subcontractor's
activity, but they cannot change it after submission. Only a Project Supervisor or Head Office can edit a
submitted close-out.
:::

## Related

- [Users and roles](/tenant-setup/users-and-roles/)