Set time-record permissions by task
Separate viewing, editing, approving and exporting rights.
Specify viewing, editing, approving and exporting separately. Give each role the access required for its task, then verify that access with a representative account.
List actions before naming roles
Role names are not portable between products. Write the actual actions: see one’s own entries, edit a submitted record, review a team, approve a batch and export the whole company. Decide who owns each action and which records they may access. A manager who needs a project total may not need another team’s detailed activity or personal descriptions.
Build an action-by-scope matrix
DeskTime’s documentation distinguishes own-data, managed-team and company-wide export access. Clockify’s detailed-report documentation also distinguishes editing capabilities by role. Use these as prompts to verify actual settings, not as a universal permission model.
Scroll horizontally to compare every column.
| Task | Proposed scope | Verification case |
|---|---|---|
| Contributor checks entry | Own records | Cannot open another contributor’s detail |
| Reviewer resolves exception | Assigned team or project | Cannot silently widen export population |
| Recipient reads released file | Required accepted fields only | Does not receive unrelated activity |
| Administrator manages access | Configuration as necessary | Changes recorded and reviewed |
Test both permitted and denied actions
A positive test shows the reviewer can do their job. A negative test shows they cannot see or change records outside the intended scope. Include exports, shared links and downloaded files: restricting a screen does not retract a file already sent. Use fictional records with clearly different team labels so a wrong-scope result is easy to notice.
Recheck access when responsibilities change
Before moving someone between teams or removing access, identify who will own their unresolved records and historical exports. Do not assume an archived user disappears from every report or that a role change updates previously shared files. If a product cannot express the required separation, choose a narrower handoff or a different workflow rather than sharing an administrator login.
Continue this work-record check
Use the linked guide for the next decision in this workflow. Keep your original records separate from experiments and record any unresolved requirement before changing a live process.
Sources and boundaries
Primary documentation supports the dated product facts. Proposed checks and fictional examples are our editorial method, not observed product results.
- DeskTime — roles · checked September 23, 2026
- Clockify — detail · checked September 23, 2026