# Engineer roles and permissions

Source: https://help.mucka.ai/engineers/engineer-roles-and-permissions
Category: Engineers
Last updated: 2026-09-04

> Owner, Manager, Engineer and Subcontractor, plus custom roles. Who can see and do what, and how to change it.

Mucka has four built-in roles plus the option to build your own. Roles control what each person on your team can see, do and approve. Get this right early and the rest of the business runs cleanly.

## The four built-in roles

| Role | Best for | Sees / does |
|---|---|---|
| **Owner** | You (or business co-owners) | Everything: jobs, clients, quotes, invoices, billing, team, settings, AI approvals |
| **Manager** | Office manager, operations lead | Everything except billing and team admin |
| **Engineer** | On-the-tools team members | Their own jobs, their own schedule, their own client info from those jobs. Cannot see the wider business |
| **Subcontractor** | Subbies and agency lads | Only the jobs you put them on, and their own schedule. No clients, no prices, no invoices. **Free — doesn't use a seat** |

Engineers can't see other engineers' jobs, the full client list, invoices, or financial data. That's deliberate. Day-to-day they focus on what they're booked on.

Subcontractors see less again, because they work for other firms too. There's a [full guide to adding one](/help/engineers/add-a-subcontractor).

## The Subcontractor role is fixed

Owner, Manager and Engineer are yours to adjust. **Subcontractor isn't** — its permissions are set by Mucka and can't be widened, by you or by anyone.

A subbie sees the jobs you put them on, their own diary, and their own hours if you've turned on self-logged timesheets. That's it. They never see your client list, your prices, your quotes, your invoices or your takings, they can't take a card payment in your name, and they can't raise a gas certificate against your business.

It's fixed rather than a default because a subbie works for other firms — including, sometimes, the one down the road. Everyone who gives a subbie a login should get the same guarantee about what that login can reach, without having to check a settings page to find out.

Open the role in **Settings → Team → People → Roles** and you'll see exactly what it holds, marked *Fixed*, with no Edit button. **If someone needs more than that, they need an Engineer seat** — which is billable, and that's the honest trade.

## What each role can actually do

Permissions sit in categories:

- **View:** jobs (all vs own), clients, schedule, team, quotes, invoices, actions
- **Create / edit / delete:** jobs, clients, quotes, invoices, projects
- **Approvals:** approve AI actions, send emails, send review requests
- **Admin:** manage team, manage roles, manage billing, manage workspace, manage skills

Each role gets a set of permissions ticked or unticked. Defaults are sensible. You don't have to touch them unless you want to.

## Custom roles

Sometimes the three built-ins don't quite fit. Common reasons:

- An engineer you trust with quotes but not invoices
- A part-time admin who handles the diary but not money
- A senior tradesperson who books their own jobs but not anyone else's

Head to [**Settings → Team → People → Roles**](/settings/team/roles) (Roles is a sub-tab under Settings) and tap **Add role**. Name it ("Senior Engineer", "Office Junior"), pick the permissions you want, save. The role appears in the dropdown when you next invite a teammate or change someone's role.

A custom role is a first-class role, not a second-class one. Whatever you tick is what that person gets — the same pages, the same buttons, the same alerts and the same answers from Mucka as a built-in role holding the same permissions. Tick "See contacts" and Contacts opens for them. Tick "Approve actions" and they get the WhatsApp about a quote a customer just signed, the same as you.

## Change someone's role

Head to [**Settings → Team → People**](/settings/team/team), find the teammate, tap their row, change role, save. The change takes effect on their next page load. Mucka tells them their access changed.

## Who can change roles

Only owners with the **manage roles** permission. Admins can normally invite but not promote, this keeps role escalation under owner control.

## Common gotchas

- **Promoting an engineer to owner.** A workspace can have multiple owners. Promoting carefully gives the new owner full billing and team access, including the ability to remove the original owner. Use sparingly.
- **Custom role with no useful permissions.** A teammate with a role that has nothing ticked sees a mostly-empty Mucka. Make sure custom roles include at least view permissions for jobs and clients.
- **"Why can't this engineer see X?"** Open Settings → Team → People, check their role, then Settings → Team → People → Roles, check what that role can do. Adjust either the role or the person.
- **Default roles are locked from delete.** You can edit the permissions on Owner / Manager / Engineer, but not Subcontractor (see above), and you can't delete any of the four. Custom roles you create are deletable as long as no one's assigned to them.
- **A custom role named "Subcontractor" is not the same thing.** Only the built-in role is fixed. If you build your own and call it Subcontractor, its permissions are yours to set — and it's a billable seat.
- **Moving someone off Subcontractor costs a seat.** Subbies are free. Promote one to Engineer or above and they become billable, so Mucka will ask you to upgrade at that point. Going the other way frees the seat back up.
