> ## Documentation Index
> Fetch the complete documentation index at: https://docs.reclaimtime.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles and permissions

> The four roles, what each one can see and change, and how scoping decides which people appear.

Every account has exactly one role. It decides both what appears in the navigation and which people's data is in scope.

| Role                 | Dashboard                                                   | Scope                              |
| -------------------- | ----------------------------------------------------------- | ---------------------------------- |
| **Standard**         | No access                                                   | Not applicable                     |
| **Supervisor**       | Statistics, Activity, Versions, Workforce, Hierarchy        | The groups assigned to the account |
| **Enterprise Admin** | Everything above plus Plans, Targets, Settings, Data Export | The whole organisation             |
| **Super Admin**      | Everything, plus the log viewer                             | Every organisation                 |

Signing in requires the Supervisor role or higher. A standard user who tries is refused, which is the reason for [Supervisors who need two accounts](/admin/supervisors-with-two-accounts).

## What each role sees

**Standard** is a tracked employee. The account exists so the desktop client can sign in and activity can be attributed to a person. It is not a login.

**Supervisor** is read only. They can see the numbers for their groups and export them. They cannot create or edit users, change groups, edit the corporate list or change any organisation setting.

<Info>A supervisor's scope is the groups on their account, and it includes everything underneath them. Assign a supervisor to **Athens** and they see every team inside Athens. Assign them to **Athens > Team Aurora** and they see only that team.</Info>

<Warning>Assign a supervisor to **one** group. If more than one group is set on the account, the filter requires a person to be in **all** of them at once, so the supervisor typically sees nobody. If somebody needs two unrelated teams, assign them the nearest common parent group instead.</Warning>

**Enterprise Admin** is the day to day administrator: users, groups, versions, the corporate list, plans, exports and organisation settings, for their organisation only.

**Super Admin** is us. The difference that matters to you is that a super admin is not tied to one organisation, so on screens where an admin sees their organisation automatically, a super admin has to choose it from a dropdown.

<Warning>Create administrators as **Enterprise Admin**, not Super Admin. A super admin creating a user must pick the organisation by hand, and if they forget, the account is saved without one. Such an account is invisible to every organisation-scoped admin and its client cannot sign in, because the client refuses an account with no organisation. This has happened, and it produces users who exist, cannot be found, and block the email address from being reused.</Warning>

## Changing a role

Edit the user in **Workforce** and change **Role**. Two rules apply:

* You cannot set a role higher than your own.
* Changing a role changes which fields apply. The tracking, single sign-on, lock and working schedule fields only mean anything for a standard user, so they are hidden for supervisors and admins.

Moving somebody from Standard to Supervisor is usually the wrong move on its own. If they should still be tracked, they need two accounts. See [Supervisors who need two accounts](/admin/supervisors-with-two-accounts).

## Related tasks

* [Troubleshooting](/guides/troubleshooting)

***

*Checked against ReclaimTime client 8.0.0.9 and dashboard V3 on 5 September 2026.*
