Skip to content
English - United States
  • There are no suggestions because the search field is empty.

Understanding User Permissions in Mastt

Essential guide to Mastt permissions and user access for construction project managers

Mastt permissions control what users can see and do across your workspace, programs, and projects. Understanding how permissions work helps you give team members the right access level while keeping your project data secure.

Permission levels

Mastt uses three permission levels that determine what users can do.

LevelWhat users can doWhen to use it
Read (Viewer)View information but cannot make changes.Stakeholders, clients, or team members who need to monitor progress without editing project data.
Write (Standard)View and edit content within their assigned areas.The typical access level for active team members contributing to projects.
Admin (Administrator)Have full control, including the ability to manage other users and configure settings.Trusted team members only. Assign this carefully.

Organizational levels

Mastt is structured in three layers, and permissions apply at each.

LevelWhat it is
WorkspaceThe highest level, representing your company or program of work. Your subscription applies at the workspace level. Workspace Admins control everything in the workspace.
ProgramCollections of related projects grouped together. Programs help organize larger initiatives or portfolios of work. Program Admins manage the program and all projects within it.
ProjectIndividual construction jobs where day-to-day work happens. Users are typically assigned specific projects they work on.

How permission inheritance works

The core principle: permissions flow downward. Higher-level access automatically includes lower-level access.

AssignmentWhat the user gets
Workspace AdminAutomatically gets Admin access to all programs and projects in that workspace. They can access any project without being directly assigned, though only directly assigned projects appear on their home page.
Program AdminAutomatically gets Admin access to all projects within that program (in the same workspace). They inherit permissions downward but do not automatically access projects in other programs.
Direct Project AssignmentAffects only that specific project. A user with project-level access does not automatically get access to the program or workspace.

Assignment and access

These terms mean different things in Mastt.

TermWhat it means
AssignmentWhen a user is assigned to a project, program, or workspace, it appears on their home page for easy access.
AccessThe ability to open and view a resource, whether assigned or not. A user might access a project through workspace settings without it appearing on their home page (if they are not directly assigned).

For example, a Workspace Admin can access any project in the workspace but will only see directly assigned projects on their home page.

Permissions by @org@ level

Workspace permissions

PermissionWhat it allows
AdminFull control over the workspace, all programs, and all projects
MemberAccess to assigned projects and programs only

Program permissions

PermissionWhat it allows
AdminManage the program and all projects within it; can reopen cash flow months
WriteEdit program content and assigned projects
ReadView program information only

Project permissions

PermissionWhat it allows
AdminFull project control including user management; can reopen cash flow months
WriteEdit project content and data
ReadView project information only

Common permission setups by role

RoleTypical setup
Project ManagerTypically given Admin access on their specific projects, plus Read access to related programs for context and reporting.
Program DirectorGiven Admin access on their program, plus direct access to key projects they're actively involved in.
Team MemberGiven Write access on projects they contribute to plus Read access to programs for reporting and overview.
Workspace AdminFull control over everything in the workspace. Can access all projects without assignment (though only assigned projects appear on their home page).
Client or StakeholderGiven Read access on specific projects or programs they need to monitor, without ability to make changes.

Best practices

PracticeWhat to do
Workspace Admin is powerfulOnly assign Workspace Admin access to trusted team members. They can access and modify anything in the workspace.
Start minimalGive users the minimum permissions they need to do their job. You can always increase access later if they need it.
Review regularlyAudit permissions monthly, especially after team changes or when projects wrap up. Remove access promptly when users move to other projects or leave the team.
Document your approachKeep records of who has Admin access and why. This supports compliance and helps you maintain consistency as your team grows.

Troubleshooting and FAQs

Why can't a user see a project on their home page even though they have access?

They likely have access through a higher-level assignment (like Workspace Admin) but are not directly assigned to that specific project. Assign them directly to see it on their home page.

What's the difference between Program Admin and Project Admin?

Program Admin manages the entire program and all projects within it. Project Admin manages only that specific project. Program Admin is the higher level and includes more control.

If I make someone a Workspace Admin, can I limit their access to specific areas?

No. Workspace Admin has full control over the entire workspace. If you want to limit access to specific areas, use Program Admin or project-level assignments instead.

Can a user have different permission levels on different projects?

Yes. A user can be Admin on one project, Write on another, and Read on a third. Permissions are assigned individually at each level.

Related articles

Need help?

Contact Mastt Support for additional assistance.