muqawil · مقاول
FeaturesHow it worksPricingBlogPartners
العربيةSign inGet started
  1. Home
  2. /
  3. Blog
  4. /
  5. Eight Roles: Who Does the Work, Who Approves It

Roles & permissions

Who acts and who signs off: how permissions are built in a construction system

Published: 8 August 202611 min read

Ask any finance manager for the single most dangerous permission-design mistake and they will name the same pattern: one employee who can both raise an expense and approve it themselves, or approve a change order they created. It takes no bad intent to become a problem — a plain mistake sails through with no second set of eyes to catch it. A good permission system does not hand everyone everything, and it does not lock everyone out of everything either; it draws a precise line between who does the work and who signs off on it, so that every number stays auditable rather than merely trusted.

Key takeaways

  • Eight built-in roles split into two kinds of scope: tied to a specific site, or operating across the whole company.
  • At least four processes — daily reports, material requests, expenses, payroll — explicitly separate who raises the item from who approves it.
  • The separation reaches down to the individual record: you cannot approve a document you uploaded, review a submittal you submitted, or approve a change order you created.
  • A single-owner company never gets stuck: if no other eligible approver exists, the sole eligible approver can approve their own work rather than the process locking up entirely.
  • Every sensitive action lands in a permanent audit log with an IP address and a precise timestamp — who signed off on what, and when, becomes a one-click answer instead of an inbox search.

In this article

  1. 01Whoever does the work should not be who signs off on it
  2. 02Eight roles, two kinds of scope
  3. 03Four places the split is explicitly enforced
  4. 04You cannot approve your own work
  5. 05Site-scoped access versus company-wide access
  6. 06Every action leaves a name and a time
  7. 07How this works in muqawil

Whoever does the work should not be who signs off on it

Permissions at most small companies are built on personal trust: "this person is reliable, they can do anything." That works until the company grows a little, or until an ordinary mistake happens that has nothing to do with trust at all — an expense entered with the wrong figure, with no second set of eyes reviewing it before it gets paid. Separating who raises a piece of work from who approves it is not an accusation aimed at anyone; it is a design that makes an ordinary mistake visible before it turns into money that has already moved.

This matters in construction specifically for one reason: money moves through fast, field-level decisions — an urgent expense, a change order a site manager waves through verbally, a rush material request — and those are exactly the moments everyone is tempted to skip review "because there's no time." A system that separates roles ahead of time does not leave that call to the mood of the moment.

Eight roles, two kinds of scope

Alongside the owner — who always holds every permission — there are seven other roles, splitting into two fundamentally different ways of operating.

The eight roles and their scope
RoleScope
OwnerEvery permission, on every project, always
Site ManagerTied to whichever site(s) they are explicitly assigned to
ForemanTied to whichever site(s) they are explicitly assigned to
Client (view only)Tied to one project, with no access to financial figures
Procurement / PurchasingCompany-wide — not tied to a single site
Finance / AccountantCompany-wide — not tied to a single site
HR / AdminCompany-wide — not tied to a single site
Warehouse / StorekeeperCompany-wide — not tied to a single site

The difference between the two kinds is practical, not theoretical: a site manager assigned to two of five projects sees nothing about the remaining three. The accountant, by contrast, sees financial figures across the whole company by virtue of the role itself — because that role is functional, not site-based.

Four places the split is explicitly enforced

At least four processes build the separation between raising and approving straight into the workflow itself — not as an optional step that can be skipped.

Who raises and who approves, across four core processes
ProcessWho raises itWho approves it
Daily reportOwner, Site Manager, or ForemanSite Manager or above
Material requestField staff or the StorekeeperOwner, Site Manager, or Procurement
ExpenseAccountant or whoever is authorised to book itSite Manager or above
Payroll runAccountant or HR (prepare the run)Finance (approves, marks paid)

The daily report is a clear example of why this split matters: it used to be manager-only, which locked out the foreman — the person who actually witnesses the work every day — and turned approval into the manager signing off on their own report. Opening authorship to the foreman while keeping approval at manager-or-above put the separation back where it belonged.

Payroll splits along a slightly different line: HR owns the employee records, contracts and leave that a payslip is built from, while Finance is who actually releases the money. Whoever prepares the run is not necessarily who signs off on paying it.

You cannot approve your own work

The separation does not stop at the role level; it reaches down to the individual record. Whoever uploaded a document cannot approve it. Whoever submitted a submittal cannot review it. Whoever created a change order cannot approve it — even if they hold the approving permission by role.

  • Document and submittal review: the reviewer must be someone other than whoever uploaded or submitted it.
  • Change order approval: whoever created the order is excluded from approving it, even as a manager.

Note: Expenses are a lighter split — role-level, not record-level

Expenses are worth calling out separately: the separation there is role-level only. Whoever lacks the approving permission can never use it, no matter what — but whoever holds it can approve an expense they raised themselves, unlike documents, submittals and change orders, where the record's own creator is excluded from approving it even as a manager.

Note: A single-owner company doesn't get stuck

If a company has only one eligible approver at all — a young company with a single owner — that sole approver is allowed to approve their own work rather than the path locking up with no way through. The rule exists to stop someone bypassing another eligible person, not to disable a company that never had one to begin with.

Site-scoped access versus company-wide access

A contractor running five projects at once, each with its own site manager. The site manager on project one sees nothing about the other four unless explicitly assigned to them — that is site-scoped access. An accountant, by contrast, sees financial figures across all five projects from day one, because their role is functional across the company, not tied to one project.

The practical result: growing the site team (site managers, foremen) means assigning each person to their specific project, while hiring into a functional department (procurement, finance, HR, warehouse) grants access across the whole company by virtue of the role itself — no project-by-project assignment required.

Every action leaves a name and a time

Approving an expense, responding to an RFI, signing off on a change order — every sensitive action is recorded in an audit log that cannot be deleted or edited afterwards, with the IP address and the exact time of whoever did it.

The value of that log shows up most clearly in a dispute: "who approved this change order, and when?" becomes a question with an instant answer from the log, instead of a search through email threads or a reliance on someone's memory.

How this works in muqawil

A team is built by email invitation, choosing one of the eight roles; site scope for roles that need it — Site Manager, Foreman, or Client (view only) — is assigned afterwards from the site page. Daily reports, material requests, expenses and payroll are all built on an explicit role-level split between who raises and who approves, and for documents, submittals and change orders that separation reaches down to the individual record — with a safe path for a single-owner company. Every sensitive action shows up in a permanent audit log.

  • Email invitation with a role choice; site scope for roles that need it is assigned afterwards.
  • Eight built-in roles, split between site-tied and company-wide.
  • Separation between raising and approving across reports, expenses, material requests and payroll.
  • A permanent audit log with an IP address and timestamp for every sensitive action.

Frequently asked questions

What if I'm the sole owner and there's nobody else to approve after me?+

The sole eligible approver is allowed to approve their own work when no alternative exists — the rule stops bypassing another eligible person, not disabling a company that never had one.

Can I give someone access to just one project and not the others?+

Yes. Site Manager, Foreman and Client (view only) are all site-scoped roles — tied to whichever project you explicitly assign them to, with no automatic access to any other.

Does the Accountant see everything the Owner sees?+

No. Accountant is a company-wide financial role that grants visibility into financial figures, but actions like deleting a project or managing users stay with the Owner alone.

Does the "Client (view only)" role see financial figures?+

No, that role is deliberately excluded from detailed financial visibility. For an external client who does not need a full account, the client portal — a read-only link with no login at all — is usually the better fit.

Is there a record of who approved what, and when?+

Yes, every sensitive action — approving an expense, responding to an RFI, signing off on a change order — is recorded in a permanent audit log with an IP address and an exact timestamp.

Can someone's role be changed later?+

Yes, any team member's role can be changed at any time from the team page, with no need to revoke and re-send their invitation.

Build your team with the right roles from day one

Invite your team into muqawil and assign each person their role and scope — and watch the split between raising and approving work from the first report or expense.

Start a free trialExplore the features

Related reading

Field operations24 July 2026·10 min read

Daily Site Reports That Hold Up in a Claim

Most daily reports are written to be filed, not read. The gap between a worthless archive and a record that survives scrutiny is five fields, filled in on the day itself.

Read the article
Procurement1 August 2026·11 min read

Three-Way Match for Construction Procurement

A purchase order is an instruction, not a fact. The delivery record and the supplier invoice are two independent claims about what actually happened — and the gap between them is where money leaks, unnoticed.

Read the article
Payroll4 August 2026·13 min read

Construction Payroll: Attendance to Payslip

An office salary is a fixed number that repeats. A day-rate wage is a multiplication — real days worked by a rate that may have changed mid-month — and it is never more accurate than the attendance record underneath it.

Read the article
Client portal6 August 2026·10 min read

Client Portal: Transparency Without a Login

A monthly PDF means the client lives thirty days in the past. A read-only portal replaces it with one link that reflects the latest update — without ever creating them an account.

Read the article
All articles
muqawil · مقاول

Construction management for the Arab world, in Arabic and English.

Product

  • All features
  • How it works
  • Pricing
  • Blog

Company

  • Create account
  • Sign in
  • Contact
  • Referral program

Legal

  • Terms of service
  • Privacy policy
© 2026 muqawil. All rights reserved.العربية