← Help

Product help

Assign the right work to each teammate

Product team · Reviewed

Assign the right work to each teammate

Workspaces → People & access → Scoped client and financial permissions gives limited staff and contractors a working desk for selected business records. Invite the person and have them accept their workspace membership first. Then select them in the scoped access editor.

Owners, administrators and staff with full workspace access retain their existing authority. A scoped policy cannot restrict a full operator. Change that membership to limited staff or contractor first if you want the person to use only their assigned work. Granting scoped access never enrolls an invited collaborator in a paid seat.

Choose records and automatic rules

A client assignment covers that client record, its current and future projects, and inquiries or project contacts linked to those projects. A project assignment includes the project’s client record and linked contacts, but does not open the client’s other projects. An inquiry assignment opens that inquiry without granting its linked project.

You can assign the same record independently to several teammates. Each person has their own sections, expiration and revocation controls. The records remain in your private business workspace; another business on the shared wedding does not receive this access.

For automatic assignment, add an exact tag and its record type. For example, a project rule for coordination-team assigns current and future projects with that exact tag. A client tag includes that client’s projects; an inquiry tag grants the inquiry only. Matching is evaluated against current records when the person reads or changes work. Removing the last matching tag or explicit assignment removes access on the next authorized request. Scoped teammates cannot change tags from this desk.

The preview shows current matching counts, explicit selected records and section permissions. Review the rule’s future effect as well as today’s matches. Automatic tags require a separate approval. An optional UTC expiration ends the policy without deleting the member or original records.

Grant sections independently

The basic overview shows the assigned record’s name, date, status and location. Contact details need a separate grant. Other choices include:

  • Team notes: read existing text, with a separate permission to append reviewed notes.
  • Tasks: read task details, with a separate permission to create or edit ordinary project tasks and completion.
  • Schedule: read draft and published times, locations and preparation checklists. Publishing remains an operator action.
  • Guests: read names, RSVP, meals, allergies and seating, with a separate edit permission. Household email, phone and mailing addresses require another grant.
  • Documents: only individually selected current project documents from private storage.
  • Financial sections: independent read grants for budgets, published proposals, agreements, invoices and project expenses.

Each financial grant applies only within the assigned record scope. An invoice grant does not expose expenses or the business-wide finance desk. Contract access includes its text and financial terms; signatures, payment links, saved methods, charges and refunds cannot be changed from the scoped desk. Invoice balances use recorded principal ledger entries and never backfill history merely because a teammate opens the page. Historical paid flags without receipt evidence require operator reconciliation.

Notes, task descriptions, timeline labels and uploaded documents can contain information your team entered, including financial details or contact information. Section permissions do not automatically redact that text. Review the contents before granting access. Personal notes, personal assistant conversations, face-search portraits/results, gallery originals, exports and isolated system artifacts are outside these grants.

Preview and approve access

Choose Preview this access policy, read the matched counts and selected records, and approve the exact policy. If the member, matched set or saved policy changed in the meantime, preview again. The audit history records the policy, reviewer and current matching counts. Recover an uncertain save with the original request instead of making another one.

After saving, Preview this person’s saved work desk opens the same projected record and section data they can read. Administrator preview cannot edit as the recipient or download a file on their behalf.

Work from web or mobile

The teammate opens Assigned work on web or the Assigned tab in the iOS/Android app. Section tabs appear only for currently granted capabilities. Task edits and guest edits use the existing domain services with the original reviewed revision or hash. A new teammate edit creates a conflict rather than overwriting it. Appended notes retain all existing text.

If a guest’s main-event invitation controls RSVP or meal answers, that authority stays intact. The scoped guest editor can review permitted basic details but cannot replace invitation-managed responses. Ask the coordinator to update the household invitation.

This native delegation desk requires a current connection and does not save its record views into offline runbooks. It clears displayed source data when the app backgrounds and reloads on return. A reviewed request with an uncertain response can be retried in the same screen with its original identity. The existing day-of offline runbook is a separate granted workflow. Physical-device and app-store activation remain part of the coordinated launch rehearsal.

Document downloads require a selected document, its current revision, an assigned project and a ready private asset. Public legacy Blob URLs are never shared through this desk. The operator must migrate those documents first. Newly issued storage download links expire after 60 seconds; already downloaded files cannot be recalled.

End or change an assignment

Disable the scoped policy and approve the change, remove an explicit assignment or tag rule, let the expiration pass, or remove the workspace membership in People & access. Existing business records, signed documents and money history remain intact.

Membership role, capabilities, revocation or rejoining changes invalidate the previous scoped approval. An administrator must review a fresh policy to resume scoped access. Replaying an old successful task request after revocation does not reveal its old result or restore access. Existing full-workspace pages and general API credentials keep their original full-access checks.

Policies support up to 500 explicit IDs in each assignment list, 50 tag rules and 5,000 matching active records per class. Lists and section records are paginated. Narrow assignments if a limit is reached; the service rejects an oversized scope rather than silently broadening or truncating it.