Roles & Permissions
Keito uses a role-based permission system to control what team members can see and do within your workspace.
Access permissions and reporting roles are different
Keito has two separate concepts with similar names:
| Setting | What it controls | Plan availability | Where to change it |
|---|---|---|---|
| Access level and manager permissions | What a person can see and do | Pro and Business | Team → Edit details → Permissions |
| Custom reporting roles | Labels such as Designer or Consultant used for reporting and filtering | Business | Manage → Roles |
Custom reporting roles do not grant access. A person labelled “Project Manager” remains a Member unless an administrator separately changes their access level to Manager or Administrator.
Permission Levels
| Access level | Own work | Assigned projects | Assigned people and reports | Workspace administration |
|---|---|---|---|---|
| Member | Track and view their own time and expenses | View projects they are assigned to | No, except their own data | No |
| Manager | Member access | Manage assigned projects within granted permissions | View and approve work for assigned people and projects | Only the specific manager permissions enabled for them |
| Administrator | All workspace time, expenses, projects, invoices, and reports | All projects | All people and reports | Yes |
Member
The default role for team members. Members can:
- Track their own time and expenses
- View their own reports
- Edit their own profile
- See projects they’re assigned to
- Submit timesheets for approval
Manager
An elevated role for team leads and project managers. In addition to Member permissions, Managers can:
- View time and expenses from their assigned teammates
- Approve or reject submitted timesheets
- See reports for their assigned team
- Manage projects they’re assigned to as project manager
Administrator
Full access to all workspace features. Administrators can:
- View and edit all time entries and expenses across the workspace
- Approve any timesheet
- Create, edit, and archive projects, clients, and tasks
- Manage team members (invite, edit, archive)
- Configure workspace settings
- Manage integrations
- Access all reports with full data
- Manage billing and subscription
The workspace Owner has owner-level access and is not a fourth selectable access level. Owner permissions cannot be reduced. Transfer ownership before attempting to change the owner’s access.
Member Types
In addition to permission level, each person has a member type:
| Type | Description |
|---|---|
| Employee | Internal staff member. Employees can track time and expenses on assigned projects. |
| Contractor | External delivery worker. Contractors can track work on assigned projects but are still treated as internal workforce for delivery and reporting. |
| Client | External client stakeholder. Clients are regular members with project-level access only. |
Client accounts cannot be managers or administrators, cannot receive internal business roles, and cannot be converted back into employees or contractors. Use client accounts for people who need visibility into selected projects without internal team access.
For project-level client visibility, see Client Project Access.
Granular Manager Permissions
Administrators can customise exactly what managers can do by toggling specific permissions:
| Permission | Description |
|---|---|
| Create projects | Create new projects for their clients |
| View/edit billable rates | See and modify hourly rates |
| Draft invoices | Create invoice drafts for managed projects |
| Send/edit invoices | Send and modify invoices for managed projects |
| Create/edit clients and tasks | Manage the client and task directory |
| Edit team time and expenses | Modify entries belonging to assigned teammates |
| Withdraw approvals | Undo a previous timesheet approval |
These permissions are configured per-manager from the Permissions tab on their Team profile. A manager receives only the access granted by their assignments and the enabled permission switches.
Teammate Assignments
Managers can be assigned specific teammates, limiting their visibility and approval authority:
- A manager only sees time/expenses from their assigned teammates.
- They can only approve timesheets from their assigned teammates.
- They only see their assigned teammates in reports.
If no teammates are assigned, the manager has no team visibility (beyond their own data).
Custom Reporting Roles (Business)
Separate from access levels, custom reporting roles are organisational labels used for reporting and filtering:
- Examples: Designer, Developer, QA Engineer, Project Manager, Consultant
- Users can have multiple business roles.
- Reporting roles do not affect permissions — they are purely for categorisation.
- Use roles in report filters to analyse time by discipline.
Create and edit custom reporting roles from Manage → Roles on the Business plan. Pro includes the Member, Manager, and Administrator access levels plus granular manager permissions, but not custom reporting-role labels.
Change a Person’s Access
An administrator can change another person’s access level:
- Go to Team.
- Open the person’s actions and select Edit details.
- Select the Permissions tab.
- Choose Member, Manager, or Administrator.
- For a Manager, enable only the granular permissions they need.
- Select Update permissions.
Use Assigned people and Assigned projects on the same profile to define the manager’s scope. An unassigned manager does not automatically gain workspace-wide team visibility.
Only an administrator or owner can change another person’s access. Members cannot elevate their own access, and the account owner’s permissions cannot be modified.