The short answer: roles are not bureaucracy. They are one decision, made once: who needs to see what in order to do their job well, and what stays behind the counter. The field kit is the schedule, the scope, the site history and the day's tools, while money, client details beyond what the work needs, and the destructive levers stay owner-side, and whole sections get hidden rather than grayed out, because a button that refuses reads as distrust instead of as job design.
Your helper is showing the client photos of the tile going in. Nice moment. Then his thumb keeps scrolling, and now the two of them are looking at the job's numbers: the quote total, the deposit, and, if your setup is careless enough, something close to your margin.
Nobody did anything wrong. The client asked to see the photos. The helper opened the job on his phone, because everything about the job lives in one place, which is exactly what makes the app useful. The problem is that "everything in one place" quietly became "everything in front of everyone," and a kid three weeks into the job just walked a client through your pricing.
Small crews resist thinking about roles and permissions because the words sound corporate, and the whole point of a five-person shop is not being corporate. Fair. But roles are not bureaucracy. Bureaucracy is approval chains and job titles. Roles are just the answer, decided once, to a practical question: who needs to see what to do their job well, and what should stay behind the counter?
You already run roles on your physical crew. Not everyone drives the truck. Not everyone talks to the client about money. Not everyone holds a company card. The software version is the same instinct, applied to information.
What a tech actually needs
Start from the work, not from the fear. A field tech or helper on a job needs, roughly:
- Today and this week: where to be, when, and what the job is.
- The scope: what was sold, in enough detail to build the right thing. The approved quote's line items, the drawings, the site notes.
- The history: photos, day logs, previous visits, what the last guy found.
- The tools of the day: clock in and out, add photos and notes, tick the checklist, record materials used.
- Enough client contact to function: a name, the site address, a phone number for "I'm outside" and "we're on our way."
That is a complete kit for doing excellent field work, and notice what is absent from it. Nothing in a tech's day requires job profitability, your labor rates, what the client paid, the client's full contact history, or your revenue chart. Those are not secrets because you distrust your people; they are absent because they have no function in the field. Every screen a person can open is something they now have to interpret, gossip about, or accidentally show a client. Information that has no job to do on a phone is just risk riding around in a pocket.
What stays owner-side, and why
Three categories earn their place behind the counter.
Money. Rates, margins, quotes-in-progress, invoices, payments, the dashboard. Partly for the obvious external reason: phones get handed to clients, propped on lumber, left on seats, and a margin column in the wrong sightline reprices a negotiation instantly. But mostly for internal reasons that nobody likes saying out loud. Your crew does not know each other's wages; job numbers that reveal what the labor line must be put you one bored lunch-break conversation away from that changing. And margin without context reads wrong in both directions: a tech who sees a $4,000 gap on one job concludes you are rich (the gap is your overhead, your slow February, your warranty risk). A tech who sees a job lose money concludes the ship is sinking. You carry the whole picture; a single number without it is misinformation.
Client PII. A tech needs the site address and a working phone number. They do not need the client's email, their other properties, their payment history, their spouse's number, or notes from the sales process ("mentioned budget is tight, husband skeptical"). Privacy law in every jurisdiction you operate in expects personal information to be accessed on a need-to-know basis, and your clients assume it. The crew member who leaves in a huff next spring should walk out holding memories, not a mental export of your client list.
The levers. Deleting things, editing signed documents, changing prices, adding and removing people. Not because anyone would, but because "nobody can" is a much better answer than "nobody would" when something goes missing and everyone is looking at everyone.
Hide it, don't gray it out
Here is the part most people get backwards. Once you have decided a tech should not open the invoices screen, there are two ways software can behave: show the button and refuse when tapped, or not show the button at all. They feel similar. They are not.
The tap-and-refuse version is poison, in a specific way. A button that answers "you don't have permission" reads as one of two things, both bad: the app is broken, or, worse, you personally are distrusted. It converts a neutral fact about job design into a small daily insult, delivered by their own phone, in front of whoever is standing there. People do not experience "access denied" as policy; they experience it as a door slammed while reaching for a handle someone left visible.
The hidden version has no sting because there is nothing to sting. The tech's app simply is their app: schedule, jobs, photos, timesheet, complete and coherent, with nothing on it that does not work. A well-cut role should feel like a tool built for the job, not like the owner's app with padlocks bolted on. Your bookkeeper does not feel deprived that her screen lacks a clock-in button; your helper should not feel deprived that his lacks a revenue chart. Deprivation requires visibility.
There is one exception worth knowing. Hide whole surfaces, but for a control inside a shared surface (say, the edit action on a job you can view), grayed-out is honest, because the surface has room to make sense of it. The rule of thumb: hide sections, disable buttons.

Delegation is a permissions decision
Roles sound like restriction, but on a growing crew they are what makes letting go possible. The reason so many owners are still doing every quote, every invoice and every client call at 9 p.m. is not that nobody else could; it is that the only alternative on offer was handing over everything. With no middle setting between "field tech" and "sees what I see," delegation feels like exposure, so it never happens, so the owner stays the bottleneck forever.
Real roles create the middle settings. The classic ladder on a small outfit looks like:
- Helper: their schedule, their jobs, photos, notes, clock in and out. No client list, no money.
- Tech: the above plus job scope and site history, materials, checklists, "on the way" messages.
- Lead hand or office: the above plus scheduling other people, creating and sending quotes and invoices you have priced or templated, the client list. Still no margins, rates or reports.
- Admin: most things, for the spouse or office manager actually running the books, minus perhaps the final levers.
- Owner: everything, including the numbers that are nobody else's job.
Each rung is a real handoff you can make without handing over the shop. Your lead can now run Tuesday while you are at the other site. The office can send invoices without being able to see, or accidentally change, what the business clears. And the promotion conversation gets a new, surprisingly motivating dimension: moving up on this crew visibly means being trusted with more of the machine.
Two disciplines keep it honest. Decide by role, not by person, so it never reads as targeted at an individual ("techs don't see money" lands fine; "Jake doesn't see money" is a fight). And revisit when reality changes: the tech who now closes small jobs on-site needs quote access, and the day someone leaves, their access leaves with them, in one tap, same hour, no drama. That offboarding speed alone justifies the whole setup.
How Zeus draws these lines
If you run your crew on Zeus, this article is mostly a settings decision you make once. Everyone joins from an invite link, lands in the team roster, and gets a role. Owner, admin and office see the business. Techs and helpers get the field kit: their schedule, their jobs, photos, day logs, time tracking, checklists. The money surfaces (quotes, invoices, payments, the money reports, the dashboard, job profitability) stay on the owner's side of the line. What a role cannot use, it does not see: a helper's app is simply a helper's app, with no locked doors to rattle. The server enforces the same lines, so the boundary is real rather than cosmetic. Choosing someone's role takes about as long as reading this sentence, which is roughly the right amount of bureaucracy for a five-person crew.
The underlying principle costs nothing and applies whatever tool you use, including paper: information should live where it has a job to do. Everything on a person's screen either helps them do today's work or it is a liability you handed them for free. Draw the line once, kindly and by role, and then never think about it again, which is, after all, the point.
Where Zeus fits
Deciding who sees the numbers is a settings decision you make once, and it only helps if you make it before the next time a client asks to see the photos. You add each person from your own phone and pick their level while you are adding them, which is the moment you are already thinking about what they will be doing. What a level does not reach is not on their screen at all: no greyed rows, no locked doors to rattle, nothing to ask you about. Changing somebody later is the same two taps, so promoting a helper into running jobs is a setting rather than a project. The schedule stays visible to all of them, because a schedule nobody can read is exactly what makes you the bottleneck for every question. Clock in and out sits with the job. The crew and supply pages show how the team, the stock and the suppliers sit together, and everything the app does is listed there. It costs nothing to start, there is no card, and it does not expire; the pricing page has what the paid sizes add. Put it on the crew's phones and set the levels once.
The helper scrolling past the tile photos into the deposit and the quote total was not doing anything wrong. He opened the job, and the job had everything in it. Ten seconds of deciding, once, is the whole distance between everything in one place and everything in front of everyone.
Frequently asked questions
Isn't hiding the numbers a trust problem? I want an open culture.
Openness about how the business works ("here's roughly what a job costs to run, here's why we charge what we charge") builds trust, and you should do it, out loud, in conversation, with context attached. Raw live margins on every phone are not openness. They are unlabeled data that reads wrong without the overhead picture, and they expose client and wage information that was never yours to share crew-wide. Be generous with explanation and stingy with dashboards.
My crew is me and one guy. Do roles matter yet?
Barely, and that is fine. But set his role deliberately anyway, because the habit is free now and expensive to retrofit. The day you are five people, "everyone sees everything" is not a policy you chose. It is an accident you have to unwind person by person, and every removal reads as a demotion. Start with the field kit as the default; add access when a job needs it.
What do I say when someone asks why they can't see the money screens?
Tell the truth, briefly and by role: "Money stuff lives with me and the office; field roles get the job stuff. Same for everyone on the tools; it's about client privacy and keeping wage info private, not about you." Delivered matter-of-factly on day one it is a non-event. Delivered defensively after someone noticed, it becomes a thing, which is one more reason to set roles before the first hire, not after the first incident.
Should my lead hand see job profitability if he's pricing changes on site?
He needs prices, not profits: the rates and line items to quote a change correctly, which is exactly the kind of middle-rung access roles exist for. Whether he eventually sees job-level margins is a judgment call about his path; if he is your successor-in-training, probably yes, with the overhead conversation attached. Grant it as a deliberate step-up conversation, not as a side effect of needing one number.




