Skip to main content

Authorization and Scopes

Scope checks are enforced per endpoint.

Available Scopes

ScopeCompany keysAgency keysCovers
read:companiesYesYescompany list and competency matrix; company-scoped keys also cover company detail, regions, sectors, connected agencies, and company umbrellas
read:usersYesNouser project assignments and effective project permissions
read:tradesYesYestrades and trade detail; agency-scoped keys can access trade detail only
read:ratesYesYesstandalone rates
read:projectsYesNoprojects and project connected agencies
read:workersYesYesworkers and worker document detail
write:workersYesYesAgency keys can create and update workers; company keys can validate worker attachment and right-to-work documents
read:purchase-ordersYesNopurchase orders
read:sitesYesYessite access, including agency access where permitted
read:requisitionsYesYesrequisitions
read:assignmentsYesYesassignments
read:timesheetsYesYestimesheets and expenses
read:invoicesYesYesinvoices, AfP, and payment notices
read:credit-notesYesYescredit notes

No broad super-key behavior is granted by default.

User assignment and permission access requires read:users. Existing keys with only read:companies must be updated to grant this scope. Agency-scoped keys cannot be granted read:users.

Listing default RBAC access rule mappings requires a valid company-scoped key, with no resource scope required. Agency-scoped keys cannot access this endpoint.