Access Profiles
Access Profiles define what each role can see and do in Atlas. Use them to enforce least-privilege access across your practice.
Default Profiles
Atlas ships with standard profiles mapped to roles:
| Profile | Entities | Billing | Reports | Settings | Admin |
|---|---|---|---|---|---|
| Principal | All | Full | Full | Full | Full |
| Partner | All | View + Approve | Full | View | Limited |
| Manager | Assigned | View | Team only | — | — |
| Team Lead | Assigned | View own | — | — | — |
| Staff | Assigned | Own time only | — | — | — |
Permission Categories
Entity Access
- All — can see every entity
- Assigned — only entities assigned to them (via account manager or team assignment)
Billing
- Full — create/edit/send invoices, manage payments
- View + Approve — view invoices, approve time entries
- View — read-only access to billing data
- Own time only — can only see their own time entries
Reports
- Full — all reports, all data
- Team only — only data for their assigned entities/team
- None — no report access
Settings
- Full — can change all practice settings
- View — can see settings but not change them
- None — no settings access
Custom Profiles
Principals can create custom access profiles:
- Navigate to Settings → Access Profiles
- Click + New Profile
- Set permissions for each category
- Name and save the profile
- Assign the profile to users in Team Management