Roles & Permissions
Clockwise has five built-in roles plus an "account manager" extension you can layer on top of any non-admin user.
The roles are cumulative — each one can do everything the one below it can, plus more:
User → Operations Support → Finance → Admin → Owner
User
The default role for most employees. Users can:
Fill out and submit their own timesheets.Request time off.View the Team Calendar.See their profile, charge code assignments, and leave balances.Two extra capabilities are unlocked automatically based on assignments — no role change required:
Approvers — Users named as a group approver (see Groups & Approvers) get an Approvals queue and can approve or reject submissions from that group's members.Managers — Users with direct reports get a My Team view that aggregates their reports' timesheets, leave, and reporting.Account Managers — Users named as a manager on an Account get a My Accounts sidebar entry with read-only access to that account's detail page (see Account Managers).Operations Support
The day-to-day operational role — roster and charge-code housekeeping, with no access to financial data or company configuration. Operations Support can:
Fully manage Charge Codes — create, edit, deactivate, bulk-remap, and assign them to users.Add and remove group members (creating or deleting groups, and naming approvers, stays Admin/Owner).Open the Users list and drill into any user — read-only, except for that user's charge-code assignments and their Sick policy tab.Manage Announcements.View All Timesheets, review unlock requests, and unlock a submitted or approved timesheet directly. They cannot edit or submit a timesheet on someone else's behalf — that is Finance and above.View Holidays and the Sick Leave settings page read-only.Operations Support sees no Accounts, Invoices, Salaries, Contractors, or Reports.
Finance
Everything Operations Support can do, plus the accounting surfaces — and read-only access to most remaining admin sections so accounting can pull what they need without changing configuration.
Sees all admin nav items except Company, Identity, Notifications, Timekeeping Policy, Billing, Activity Log, and Integrations.Can browse Users, Groups, Charge Codes, Accounts, Sick Leave, Leave Balances, Contractors, Reports, and Invoices.Can read Salaries — the full compensation roster and history. Adding, editing, and removing salary rows stays Admin/Owner: finance reconciles pay against payroll, it doesn't set it.Can add, edit, and delete Holidays — the holiday calendar is finance-writable, not read-only.Can fully manage Contractors — add, edit, import, and match users to subcontractor companies — not just view them.Can add and edit users from Settings > Users — employment type, manager, department, dates, and active status. Two limits on roles: Finance can only assign User or Operations Support (and only to someone who already holds one of those) — anything involving Finance, Admin, or Owner is Admin/Owner-only, and only the Owner can grant or remove the Owner role. Bulk CSV/JSON roster import also stays Admin/Owner only.Has access to the full company-wide Timeliness report alongside admin and owner.Can correct, create, and submit a timesheet on another employee's behalf — the administrative-correction flow, which requires a written reason and is recorded in the audit trail.Can manage Announcements alongside Operations Support and Admins.Server-side guards reject write attempts on the read-only sections even if a UI control is visible.Admin
Full operational access:
Manage Users, Groups, Contractors, Charge Codes, Accounts, Sick Leave, Leave Balances, Salaries, Reports, and Invoices.Configure company-level settings (Company info, Identity/SSO/SCIM, Holidays, Announcements, Notifications, Timekeeping Policy, Billing, Imports).Manage charge-code assignments and leave balances per user.Read the company Activity Log.Approving timesheets is the one thing the Admin role does not grant by itself — approval always comes from being named an approver on a group. See Groups & Approvers.
Owner
Normally one per company. The Owner has every Admin permission, plus:
Grant or remove the Owner role — Admins cannot do either, in either direction.Transfer ownership of the company.Final say on billing and subscription changes.Promote a user to Admin from Settings → Users. Transfer ownership from Settings → Company.
Comparison
● full access · ○ read-only · — no access
Approving timesheets, My Team, and My Accounts are left out of the table because they don't come from your role at all — every role gets them by being named a group approver, having direct reports, or being named a manager on an Account.
| Capability | User | Ops Support | Finance | Admin | Owner |
|---|
| Everyday |
| Own timesheet, time off, profile, Team Calendar | ● | ● | ● | ● | ● |
| Timesheet oversight |
| View everyone's timesheets | — | ● | ● | ● | ● |
| Review unlock requests; unlock directly | — | ● | ● | ● | ● |
| Edit / submit on someone's behalf | — | — | ● | ● | ● |
| Roster |
| Users list and user pages | — | ○ | ● | ● | ● |
| Create / edit users | — | — | ● | ● | ● |
| Assign the Finance / Admin roles | — | — | — | ● | ● |
| Bulk roster import | — | — | — | ● | ● |
| Groups — create, delete, approvers | — | ○ | ○ | ● | ● |
| Groups — add / remove members | — | ● | ● | ● | ● |
| Charge codes |
| Charge codes, assignments, bulk remap | — | ● | ● | ● | ● |
| Leave |
| Holidays | — | ○ | ● | ● | ● |
| Sick policies — create / edit / delete | — | ○ | ○ | ● | ● |
| Sick policy assignment per user | — | ● | ● | ● | ● |
| Leave balances | — | — | ○ | ● | ● |
| Announcements |
| Announcements | — | ● | ● | ● | ● |
| Accounting |
| Contractors | — | — | ● | ● | ● |
| Accounts — create / edit | — | — | ○ | ● | ● |
| POP, CLIN, LCAT, invoice periods | — | — | ● | ● | ● |
| Invoices and Burndown | — | — | ● | ● | ● |
| Salaries — view | — | — | ○ | ● | ● |
| Salaries — add / edit / remove | — | — | — | ● | ● |
| Company-wide Reports | — | — | ● | ● | ● |
| Configuration |
| Company info, Identity, Integrations | — | — | — | ● | ● |
| Notifications, Timekeeping Policy | — | — | — | ● | ● |
| Billing | — | — | — | ● | ● |
| Activity Log | — | — | — | ● | ● |
| Transfer ownership; grant or remove the Owner role | — | — | — | — | ● |