Who sees what — invite your team and set roles

Serrano doesn't need my billing. He needs Tuesday. A seat in STrOp is an email plus a role, and the role decides what the app shows — not a filter someone can switch off, but the navigation and the routes themselves. A foreman's phone and the office laptop are the same shop, drawn from different sides. Here's how I brought in my foreman and my bookkeeper, and what each of them sees.

Invite by email, pick the role

  1. Settings → Roles (/settings/roles). The top of the page is everyone with a seat and the role each holds — three of us so far at Kestrel.
  2. Under Invite team member, type the email and pick the role from the dropdown: Foreman, Finance, Estimator, Project Manager, and the rest. Serrano runs crews, so he's a Foreman. Marisol runs the office, so she's Finance.
  3. Send invite. They get a magic link that's good for fourteen days. Until they open it, the invite sits in Pending invitations below — Revoke one sent to the wrong address and send it again.
  4. When they open the link they type their name, accept the click-wrap, and land in your org with the role you chose. Changing a role later is a dropdown on the member list; nobody gets re-invited.

Read the matrix

The Capability matrix at the bottom of the page is the whole rule. Roles down the side, areas across the top — CRM, Estimating, Proposal, Award, Setup, Field, Scheduling, Procurement, Changes, Billing, Closeout, Warranty, Service, Certified Payroll, Reference, Org Settings. A check means the role reaches that area; a dash means it never does.

  • Org Admin is locked to everything, so an org can't lock itself out of its own settings. The page warns you when you're the only admin — name a second one.
  • You can narrow a role, never widen it. Untick Procurement for Superintendent and your supers lose it; you can't hand a Foreman billing. If a role needs more, that's a different role.
  • Certified Payroll is the sensitive column. It decrypts worker SSNs for eCPR, so only Finance and Org Admin hold it — a PM or foreman never sees a Social Security number.

Getting started — team progress, on the same page, scores each member against their role's self-ticking checklist — so you can tell who's actually in.

Three views of one shop

Serrano, Foreman, on his phone. He lands on Tasks — today, this job, nothing else. No Pursuit, no CRM, none of the Settings libraries. Open Execution and it's Field, with the schedule and his timecards inside it. My billing never crosses his screen; his timecards never wait on me.

Marisol, Finance. She lands on Projects. Execution for her is Procurement, Changes, Billing, and Closeout — the money side of every job, plus Service and the certified-payroll run. No estimating, no pipeline lanes.

Me, Org Admin. All of it, including this page. Same org, same data, three shapes.

Common mistakes

  • Making everyone a Member to keep it simple. Member is a broad office role. A foreman on Member sees estimating and billing he doesn't need and still can't find his timecards fast.
  • Handing Finance to whoever "does the books." It carries Certified Payroll, which means SSNs. Give it to the person who files eCPR, not to everyone who sends an invoice.
  • Leaving invites to rot. Fourteen days and the link dies. The roles page nudges you when invites go stale; resend rather than assume they signed up.

See also

This is how STrOp works

The data flows you read about here are how the platform threads bid, execution, billing, and closeout. Single pipeline. No re-keying.

Request beta access →

Last updated 2026-09-07.