Roles & Permissions

Pranaalika Nirman has five built-in roles, hierarchical and scoped to your organization. This page describes what each role can do and includes the full permission matrix.

Where roles are assigned
Admins invite users from the Team page (/users) and pick the role at the time of invitation. Roles can be changed later by any admin from the same page.

The five roles

Admin

admin

Organization owner. Full read and write across all projects, plus the ability to invite, remove, and change roles of other users.

Typical: Founders, MDs, directors, or whoever signs the cheque.

Manager

manager

Project lead. Can approve indents, GRNs, transfers, and DPRs. Manages budgets and payroll inputs. Cannot manage users or billing.

Typical: Project managers, operations heads.

Engineer

engineer

Site-level operator. Creates and updates sites, materials, attendance, GRNs, DPRs, and issues. Cannot approve or delete.

Typical: Site engineers, supervisors.

Member

member

Generic team member. Can create DPRs, indents, petty cash entries, issues, and AI queries. Limited edit permissions.

Typical: Junior engineers, foremen, support staff.

Viewer

viewer

Read-only. Can view every record across the projects they are added to. Cannot create, edit, or delete anything.

Typical: External stakeholders, owners or clients you want to keep informed without giving them write access.

The hierarchy

Roles are strictly ranked: Admin > Manager > Engineer > Member > Viewer. A higher role can do everything a lower role can — the permission matrix below shows the minimum role required for each operation.

Full permission matrix

Each cell shows the minimum role required to perform that action on that resource. A dash (—) means the action is not exposed for that resource (default deny).

ResourceCreateReadUpdateDeleteApproveManage
ProjectsManagerViewerEngineerAdmin
SitesEngineerViewerEngineerManager
TasksMemberViewerMemberManager
MaterialsEngineerViewerEngineerManager
WorkersManagerViewerEngineerManager
AttendanceEngineerViewerEngineerManager
PayrollManagerViewerManagerAdmin
BudgetManagerViewerManagerAdmin
IssuesMemberViewerMemberManager
GRNEngineerViewerEngineerAdminManager
IndentsMemberViewerEngineerAdminManager
Petty CashMemberViewerManagerAdminManager
Material TransfersEngineerViewerEngineerAdminManager
Daily Progress Reports (DPR)MemberViewerEngineerAdminManager
ReportsViewerViewerManager
AI Assistant & ReportsMemberViewer
Vendor AttendanceEngineerViewerEngineerManager
Users (team management)MemberAdmin
Organization SettingsManagerAdmin
Report SchedulingManagerEngineerManagerAdmin

Notes on the matrix

  • Approve is the financial control lever. It exists only on resources that move money or material (GRN, Indents, Petty Cash, Material Transfers, DPR) and is restricted to managers and above. An engineer can submit an indent, but only a manager can approve it.
  • Read is permissive by design. Most resources allow viewer-level read so external stakeholders can see relevant context without write access.
  • Delete is generally manager-or-admin. Hard delete is treated as a senior operation.
  • AI features inherit your role. A viewer asking the AI Assistant cannot see data their role does not grant access to. The AI is not a back door.
  • Cross-organization access is never possible. A user can only see data from organizations they are an explicit member of.

Seat limits per plan

Each plan caps the number of active users in your organization:

  • Starter — 10 users
  • Team — 50 users
  • Enterprise — Unlimited

Pending invitations count against the cap. So if you have 8 active members on Starter and 2 pending invitations, you are at your limit; no new invitation can be sent until somebody accepts or a pending invitation is cancelled. See pricing for the details.

At the user limit?
New invitations are blocked. Free a seat by cancelling a pending invitation or deactivating an existing user, or upgrade to a higher plan.

Frequently asked questions

Can I create custom roles for my organization?

Not yet. Pranaalika Nirman ships with the five built-in roles above. Custom roles are on the roadmap and currently a discussion item for Enterprise customers.

Can a user have different roles in different projects?

Not in the current release. A user's role is organization-wide. Project-level role overrides are tracked as a future enhancement.

Do deactivated users count against my seat limit?

No. Only active users count. Deactivate a user from the Team page to free a seat without losing their historical records.

How does the AI know what data to show me?

The AI Assistant and AI Reports run against your project data with your role applied. If your role cannot see a project, the AI will not surface anything from it.

Can deleted users still appear in audit logs?

Yes — by design. Audit log entries retain the user reference until the user is fully deleted, after which the entries persist with the user reference removed. This preserves history without exposing personally identifying information. See our Account Deletion page for details.

For administrators — managing your team

  • Invite a user: Team page → Invite User. Pick role at invitation time.
  • Change a user's role: Team page → click the user → Change role.
  • Deactivate a user: Team page → click the user → Deactivate. Reactivate any time.
  • Remove a user: Team page → click the user → Remove. Audit history is preserved.