Project permissions: every tab now needs its own permission
Until now, ZEIT.IO followed a simple rule for projects: whoever was allowed to read a project saw everything in it. Whoever was allowed to edit a project could change everything in it. Invoices, credit notes, offers, expenses, timesheets, automatic invoicing – all of it depended solely on the two project permissions.
This release changes that. The tabs of a project that show invoices, credit notes, offers, expenses or timesheets now additionally check the permission for exactly these documents – the same permission that applies to the corresponding overview page of the organisation.
Why we made this change
The user permissions of an organisation let you define in fine detail who may see what. A project manager, for example, should manage their projects but not see any outgoing invoices. So they get "Read projects" and "Edit projects", but not "Read outgoing invoices". The Outgoing invoices page stays locked for them – exactly as intended.
The problem: the detail page of a project had an Outgoing invoices tab. There, the same project manager saw all invoices of the project, including all amounts. The same applied to incoming invoices, credit notes in both directions, offers, expenses, timesheets and the financial report. The project was a detour around all financial permissions.
Editing was similar. The "Edit projects" permission was enough to configure the automatic invoicing of a project. These settings determine when and to whom invoices are sent to the customer – if in doubt, they are created and sent immediately. That is a decision about outgoing invoices, not about the project. Likewise, the project tab allowed uploading and deleting timesheets or editing expenses without holding the permissions for timesheets or expenses.
A permission that can be bypassed via another page protects nothing. That is why the same rule now applies everywhere: Whoever may not see invoices sees them nowhere – not even in the project.
What changes in detail
The project permissions remain the basic requirement. For the following tabs and actions, the permission for the respective document is additionally required:
| Tab / action in the project | Additionally required permission |
|---|---|
| View timesheets | Read timesheets |
| Upload and delete timesheets | Edit timesheets |
| View expenses | Read expenses |
| Upload, edit and delete expenses | Edit expenses |
| View offers | Read offers |
| View outgoing invoices | Read outgoing invoices |
| View incoming invoices | Read incoming invoices |
| View credit notes (outgoing) | Read credit notes |
| View credit notes (incoming) | Read incoming credit notes |
| View automatic invoicing | Read outgoing invoices |
| Change automatic invoicing | Edit outgoing invoices |
Tabs for which the permission is missing no longer appear in the project menu at all. Anyone who opens such a page directly anyway – via an old bookmark, for example – gets an "Access denied" error page.
The financial report
The financial report of a project summarises times, timesheets, invoices and credit notes. Locking it completely would also have excluded people who legitimately use part of it. So it now shows only the sections for which the respective read permission is present. Someone who may see times and timesheets but no invoices, for example, sees exactly these two sections.
Suppliers
The same gap existed on the detail page of a supplier. The Incoming invoices and Credit notes tabs of a supplier now also require the matching read permission – no longer just "Read suppliers".
"Edit projects" now applies to all modifying actions
Some actions could previously be reached with "Read projects", even though they change data: creating a project, opening the related forms, recalculating the budget. When a project is created, among other things members and approvers are taken over, automatic invoicing is set up and notifications are sent. These actions now require "Edit projects". From now on, new features in the project are reachable only with the edit permission by default – a forgotten permission check thus leads to locked access instead of an open door.
Contract selection when adding members
When adding project members, the form loads the hourly rates and settings of the selected contract. This data is now only delivered for the contracts that the form actually offers to the user. Someone who may only add employees can no longer view supplier contracts this way – and vice versa.
What does this mean for you?
Organisation admins are not affected. The admin permission includes all other permissions.
For all other users: if someone in your organisation has so far accessed invoices, expenses or timesheets via the project, that access may now be gone. An example: a project manager with "Read projects" and "Edit projects" can no longer save the automatic invoicing of their project unless they also have "Edit outgoing invoices".
That is intentional – but only you know whether this person should have the access. If yes, grant the missing permission in the member's Permissions. If no, ZEIT.IO now protects your data exactly the way you had already configured it in the permissions.
More secure, because permissions now keep their promise
The change introduces no new permissions. It ensures that the existing permissions apply everywhere:
- One permission, one meaning. "Read outgoing invoices" now truly controls who sees outgoing invoices – on the overview page, in the project, in the financial report and at the supplier.
- No more detours. Financial data can no longer be viewed or changed via the project page if the matching permission is missing.
- Secure by default. New features in the project are locked without the edit permission until they are explicitly released.
- Less risk from mistakes. Whoever accidentally receives too many project permissions does not automatically gain access to invoices and amounts.
This matters especially for invoice data, hourly rates and margins: they are among the most sensitive information of any company.
Questions or comments? Write to us at support@zeit.io – we are happy to help.