Roles & Permissions

Keito uses a role-based permission system to control what team members can see and do within your workspace.

Access permissions and reporting roles are different

Keito has two separate concepts with similar names:

Setting What it controls Plan availability Where to change it
Access level and manager permissions What a person can see and do Pro and Business Team → Edit details → Permissions
Custom reporting roles Labels such as Designer or Consultant used for reporting and filtering Business Manage → Roles

Custom reporting roles do not grant access. A person labelled “Project Manager” remains a Member unless an administrator separately changes their access level to Manager or Administrator.

Permission Levels

Access level Own work Assigned projects Assigned people and reports Workspace administration
Member Track and view their own time and expenses View projects they are assigned to No, except their own data No
Manager Member access Manage assigned projects within granted permissions View and approve work for assigned people and projects Only the specific manager permissions enabled for them
Administrator All workspace time, expenses, projects, invoices, and reports All projects All people and reports Yes

Member

The default role for team members. Members can:

  • Track their own time and expenses
  • View their own reports
  • Edit their own profile
  • See projects they’re assigned to
  • Submit timesheets for approval

Manager

An elevated role for team leads and project managers. In addition to Member permissions, Managers can:

  • View time and expenses from their assigned teammates
  • Approve or reject submitted timesheets
  • See reports for their assigned team
  • Manage projects they’re assigned to as project manager

Administrator

Full access to all workspace features. Administrators can:

  • View and edit all time entries and expenses across the workspace
  • Approve any timesheet
  • Create, edit, and archive projects, clients, and tasks
  • Manage team members (invite, edit, archive)
  • Configure workspace settings
  • Manage integrations
  • Access all reports with full data
  • Manage billing and subscription

The workspace Owner has owner-level access and is not a fourth selectable access level. Owner permissions cannot be reduced. Transfer ownership before attempting to change the owner’s access.

Member Types

In addition to permission level, each person has a member type:

Type Description
Employee Internal staff member. Employees can track time and expenses on assigned projects.
Contractor External delivery worker. Contractors can track work on assigned projects but are still treated as internal workforce for delivery and reporting.
Client External client stakeholder. Clients are regular members with project-level access only.

Client accounts cannot be managers or administrators, cannot receive internal business roles, and cannot be converted back into employees or contractors. Use client accounts for people who need visibility into selected projects without internal team access.

For project-level client visibility, see Client Project Access.

Granular Manager Permissions

Administrators can customise exactly what managers can do by toggling specific permissions:

Permission Description
Create projects Create new projects for their clients
View/edit billable rates See and modify hourly rates
Draft invoices Create invoice drafts for managed projects
Send/edit invoices Send and modify invoices for managed projects
Create/edit clients and tasks Manage the client and task directory
Edit team time and expenses Modify entries belonging to assigned teammates
Withdraw approvals Undo a previous timesheet approval

These permissions are configured per-manager from the Permissions tab on their Team profile. A manager receives only the access granted by their assignments and the enabled permission switches.

Teammate Assignments

Managers can be assigned specific teammates, limiting their visibility and approval authority:

  • A manager only sees time/expenses from their assigned teammates.
  • They can only approve timesheets from their assigned teammates.
  • They only see their assigned teammates in reports.

If no teammates are assigned, the manager has no team visibility (beyond their own data).

Custom Reporting Roles (Business)

Separate from access levels, custom reporting roles are organisational labels used for reporting and filtering:

  • Examples: Designer, Developer, QA Engineer, Project Manager, Consultant
  • Users can have multiple business roles.
  • Reporting roles do not affect permissions — they are purely for categorisation.
  • Use roles in report filters to analyse time by discipline.

Create and edit custom reporting roles from Manage → Roles on the Business plan. Pro includes the Member, Manager, and Administrator access levels plus granular manager permissions, but not custom reporting-role labels.

Change a Person’s Access

An administrator can change another person’s access level:

  1. Go to Team.
  2. Open the person’s actions and select Edit details.
  3. Select the Permissions tab.
  4. Choose Member, Manager, or Administrator.
  5. For a Manager, enable only the granular permissions they need.
  6. Select Update permissions.

Use Assigned people and Assigned projects on the same profile to define the manager’s scope. An unassigned manager does not automatically gain workspace-wide team visibility.

Only an administrator or owner can change another person’s access. Members cannot elevate their own access, and the account owner’s permissions cannot be modified.