# Role-Based Access Control | EternalEngine Security

Right access for the right people. Granular permissions, custom roles, and feature-level access control — built for the principle of least privilege.

Security & Compliance

# Right access for the right people.

Stop giving everyone admin. EternalEngine's RBAC system lets you define exactly what each role can see and do — from full Admin access down to read-only Viewer — with feature-level granularity.

[Start free](https://app.eternalengineos.io/signup?plan=free&interval=annual)[View all security →](https://eternalengineos.io/features/security-compliance/)

Permission Matrix

| Feature | Admin | Manager | Member | Viewer |
| --- | --- | --- | --- | --- |
| View Contacts | ✓ | ✓ | ✓ | ✓ |
| Edit Contacts | ✓ | ✓ | ✓ | ✗ |
| View Reports | ✓ | ✓ | ✗ | ✗ |
| Delete Records | ✓ | Own only | ✗ | ✗ |
| Manage Users | ✓ | ✗ | ✗ | ✗ |
| Billing & Plans | ✓ | ✗ | ✗ | ✗ |
| Export Data | ✓ | ✓ | ✗ | ✗ |

+ Custom roles can be created for any combination of permissions

## Roles and permissions

Admin, sales manager and custom role cards from the team settings.

Click to enlargeGive each person exactly the access they need.

## Access control that scales with your team

From solo founders to enterprise teams — define the exact permissions structure you need.

### Granular Permissions

Control access at the feature level — not just read/write/admin. Decide who can view reports, delete records, export data, manage users, and access billing independently.

### Custom Roles

The built-in Admin / Manager / Member / Viewer roles cover most teams. Need something specific? Create a custom role with exactly the permissions your org requires.

### Feature-Level Access

Permissions aren't just read/write flags — they're scoped to individual features. A rep can log calls but not delete contacts. A manager can view reports but not manage billing.

### Invite Management

Invite new team members with a role pre-assigned. They get exactly the access they need on day one — no over-provisioning, no onboarding security gaps.

## The principle of least privilege, made easy

Users get what they need. Nothing more.

### Principle of Least Privilege

Grant the minimum access required for each role. Reduces your attack surface, limits blast radius of compromised accounts, and keeps sensitive data appropriately restricted.

### Onboarding Simplicity

Assign a role at invite time — the new team member arrives with correct access pre-configured. No IT ticket. No manual permission review. Just the right access, from day one.

### Compliance Alignment

Access control is a core requirement of SOC 2, ISO 27001, and HIPAA. EternalEngine's RBAC gives you the granularity to demonstrate controls to auditors without custom tooling.

Questions

## Common questions, straight answers.

### Keep exploring

- [All security features](https://eternalengineos.io/features/security-compliance/)
- [Audit trails](https://eternalengineos.io/features/security-compliance/audit-trails/)
- [Team coordination](https://eternalengineos.io/features/project-management/team-coordination/)
- [Plans and pricingFree to start; every paid plan has a 30-day free trial.](https://eternalengineos.io/pricing/)

Which roles come built in?

Admin, manager and member roles, plus custom roles you define with the exact permissions each person needs.

Can I hide financials from field staff?

Yes. Permissions are per area, so a crew role can see jobs and check-ins without invoices or revenue.

Which plans include custom roles?

Every multi-seat plan: Team, Pro and Business.

## Run your business from one place.

Five plans, seventeen launch apps, one dashboard. Set up in under 5 minutes — change tiers any time.

[Start free$0 forever &bull; No card &bull; Upgrade any time](https://app.eternalengineos.io/signup?plan=free&interval=annual)[Talk to Sales](https://eternalengineos.io/contact/)

From $0 · Basic $9.95/mo · Save 20% on annual billing · Upgrade or downgrade any time
