Document Resources

Foundations

Foundations

Roles & permissions

All roles7 min readUpdated June 15, 2026

The complete “what each role does in CERQA” reference. Every cell in the capability matrix below reflects how CERQA actually behaves today. CERQA assigns a role at two scopes (company-level and property-level), and the two combine to determine what a person can actually do.

The two role scopes

CERQA assigns a role at two independent scopes. The company-level role is set when a member is added to your company via the Team page (Team page, then Add Member). It determines what they can do company-wide. The dropdown in that dialog is labeled “Platform role”. As a Company Admin you see six options in this dropdown.

The property-level role is set when a member is added to a specific property's team via the property's Project Team tab, then Add Member. Five role labels are available there. Company Admin is not a property-level option, because a CA's authority is already company-wide.

The two scopes combine. A member who is a Contributor at the company level but is added as a Project Admin on one specific property has Project Admin capabilities on that property and Contributor capabilities everywhere else.

The Add New Member dialog open under a Company Admin actor, showing the Platform role dropdown expanded with six options: Company Admin, Project Admin, Project Manager, Contributor, Viewer, Guest.
The Add Member dialog. The role selector is labeled Platform role. A Company Admin actor sees six options.

The six roles

All six roles, and where each one is assigned:

RoleWhere assignableNotes
Company AdminCompany-level onlyThe customer's top role. Manages members, properties, integrations, and company-wide module access.
Project AdminCompany-level or property-levelFull administration of one or more properties. Can manage that property's team and create properties at the company level.
Project ManagerCompany-level or property-levelDay-to-day operations on assigned properties. Cannot manage the property team.
ContributorCompany-level or property-levelAdds and edits content (files, pins, markup). Cannot manage the property team or sharing config.
ViewerCompany-level or property-levelRead-only access. Can open PDFs but cannot annotate; the markup toolbar is not exposed to Viewer.
GuestCompany-level or property-levelLimited access typically used for external partners. Cannot annotate.

Project Admin vs Project Manager: the key distinction

These two roles are easy to confuse. Both manage one or more properties day-to-day, and both have identical module access on properties they are assigned to. The difference is team and property authority:

CapabilityProject AdminProject Manager
Module access (Files & Models, Field, Vision, Analytics, Site, Connections, Experiences)All assignedAll assigned
Property Team, view membersYesYes (view only)
Property Team, Add Member buttonVisibleHidden
Property Team, edit member role or accessYesNo
Property Team, remove membersYesNo
Set member access expiry on a propertyYesNo
Add Property at the company levelYesNo
Analytics sidebar pageVisibleHidden

In plain English: Project Admin runs the property end-to-end (team, content, property creation, and analytics oversight). Project Manager runs day-to-day content but cannot change who is on the team, cannot create properties, and does not see the Analytics sidebar page.

The five property-level role labels

The Add Member dialog (property Property Members tab, then Add Member) shows these five labels verbatim. The label text below is what appears in the dropdown:

  • Project Admin: “Full project administration”
  • Project Manager: “Manage project operations”
  • Contributor: “Add and edit content”
  • Viewer: “Read-only access”
  • Guest: “Limited access”
The Add Member dialog on a property's Property Members tab with the role dropdown expanded, showing the five property-level role labels.
The Add Member dialog. The five role labels are the exact text shown in the dropdown.

The role hierarchy

The hierarchy rule applies to changing an existing member's role: a new role equal to or above your own level is rejected. The dropdown does not pre-filter, so the option stays visible; selecting it and saving returns an error.

Adding a new member is not restricted the same way. A Company Admin can create another Company Admin in the same company, and that save succeeds. So the rule to remember is not “you can never assign at or above your level” - it is that you cannot promote an existing member to your level or above.

Practical effect

If you see a role above your own in a dropdown, the dropdown is not lying - you can pick it. Whether the save succeeds depends on which screen you are on: adding a member goes through, changing an existing member's role does not.

The capability matrix

The complete capability reference for CERQA. Where a capability is not available in the product today, the row says so.

CapabilityWho can do it
Delete a member permanentlyCompany Admin (a Company Admin can permanently delete members below their own role, within their own company).
Deactivate a member (soft)Company Admin (same scope as delete). The gentler alternative; retains audit history.
Save a property viewAny property member (Project Admin, Project Manager, Contributor, Viewer, or Guest). No role gate.
Share a saved viewAny property member who owns the view.
Share a file via external linkContributor and above - the Share action follows the same edit permission as markup. What a given share can reach also depends on where the file sits and who the recipient is.
Add markup or annotation on a PDFContributor and above. Viewer is view-only (can open the PDF but cannot annotate); Guest has no PDF access.
Set member access expiry on a propertyProject Admin or higher (PA, CA). Two UIs by context: the Add Member dialog uses an Access Duration preset picker (new member); the Member Details modal uses a plain date input (editing an existing member).
Property-level module assignment checkboxes (Add Member dialog)Three checkboxes (Files & Models, Field, Vision) are shown only to a Company Admin. A PA sees the Add Member dialog but not the module section.
Create a 360 walkthrough or viewpointAny property member. No role gate.
Export Field pin data to PDFProject Manager and above. Contributor, Viewer, and Guest cannot export. Single Export PDF with Pins control (download icon in the Field tab's left vertical toolbar); floor plan with pins overlaid. No CSV, no ZIP.
Create a new property (Add Property button)Company Admin or Project Admin. Project Manager and below do not see the button.
Cross-company partner sharing and member groupsHandled by BIMstream on your behalf. If a workflow needs cross-company partner access or bulk member-group operations, escalate to your CERQA Account Manager (see the section below and CA-14).
Open the Integrations menu (avatar menu)Company Admin only.
Open the Team page (sidebar)Company Admin only. PM is excluded.
Open the Analytics sidebar pageCompany Admin or Project Admin.

Module gating

Features that require a module are gated independently of role. Each module has an internal code paired to its display name: DOCUMENTS (Files & Models), FIELD (Field), VISION (Vision), AERIAL (Site), CONNECTIONS (Connections), ANALYTICS (Analytics), and EXPERIENCES (Experiences). Every company works with Files & Models, Field, and Vision; Site, Connections, Analytics, and Experiences appear for companies granted those modules. Each module is granted to a company at the company level, and each appears as a Module Access checkbox in the Add Member dialog only when your company has been granted that module (checkboxes are checked by default when present).

Most modules gate a property tab. Analytics differs in what it gates: the company-wide Analytics sidebar page, not a property tab. Sustainability is not a module of its own; it is a section inside the Connections tab.

Two property tabs deserve specific callouts:

  • The Connections tab on a property is module-gated by CONNECTIONS. It is not universal.
  • The Property Members tab is the only purely role-gated property tab. The other tabs are either module-gated or open.

For the full module reference (per-module surfaces, label drift, and the company-vs-property grant model), see CA-07 - Module gating reference.

What is above your role

Two features are gated above the standard customer Company Admin role. The correct framing for both is “available, but not to your role”, not “doesn't exist.” If a workflow needs any of them, the path is escalation to your CERQA Account Manager.

Member Groups

Fully implemented. The Groups tab supports create, edit, add members, share access, and archive. The Groups tab is a BIMstream platform surface; no customer role sees it, including Company Admin. Use cases that escalate here: bulk operations on many members at once, group-level access grants across multiple properties, archiving an entire team in one action.

Cross-Company partner sharing

The Cross-Company Access tab on the Team page is a BIMstream platform surface; only your CERQA Account Manager can create a cross-company grant. Standard customer CAs do not see the tab; Project Managers have no Team page at all (see the row above: Company Admin only) and see membership only through a property's Property Members tab.

When to escalate

If a workflow needs Member Groups or Cross-Company access grants, escalate to your CERQA Account Manager. The escalation checklist in CA-14 - When to call your CERQA Account Manager covers each of these.

The cross-company partner-sharing boundary is also documented from both the Company Admin and Project Manager perspectives:

For the property-level Add Member flow (including Access Expiry on a per-property assignment), see CA-05 - Managing members. For the company-level Add Member flow that exercises this matrix, see CA-04 - Adding members.

Digital Twin Capture
BIMstream

Don't have a model? BIMSTREAM captures your building and transforms it into a digital twin hosted in CERQA.

BIMSTREAM.COM