Launch
Roles and permissions: every screen, API call and AI assistant follows the person's role
Planes now enforces one set of role permissions everywhere — web, API, API keys and AI assistants — and admins can tune what Sales, Service, Production, Sub and Readonly roles may do from Settings → Roles, with a history of every change.
Highlights
- One set of permissions, enforced everywhere. What a role may do is now the same rule on the web, the API, API keys and AI assistants (Claude, ChatGPT, Planes' own assistant). There is no longer an "admin only" shortcut that a screen or a tool could get wrong.
- Changes take effect immediately. A promotion, demotion or deactivation applies on the person's very next request — no logout, no waiting for a session to expire.
- Admins can tune roles. Settings → Roles shows every role's permissions as a grouped matrix in your company's own vocabulary; change what Sales, Service, Production, Sub and Readonly can do, review the diff, save. Some permissions are locked on purpose.
- Refusals explain themselves. "Your role (Sales) can't delete Customers. Ask an admin to change the Sales role." — and admins see a "Change this" link straight to the right cell.
- Tasks are personal by default. You see tasks assigned to you or your team; admins and roles given "See all tasks" see everything.
What changed
Permissions and roles
- A demotion, promotion or deactivation now applies on your very next request on the web, the API, API keys and connected assistants.
- When something is refused, the message says which role you have and which permission was needed, in plain words.
- Settings → Account has a new What my role can do section: your role, a one-sentence summary and the full list of what it allows.
Screens follow permissions, not an "admin only" rule
- Non-admin roles can now reach the screens their permissions already allowed: Invoices (sales, service), Inventory items and locations (production), Lists (production), Tags (all roles), Production, Today, Subcontractors, Paysheets, Expenses and Accounting reports per role, Customers for service.
- Purchase Orders, Stock and Marketplace no longer appear for roles that never had the permission.
- Settings for non-admins shows only Account, Assistant & Tools and My Schedule.
Tasks
- You now see only tasks assigned to you or to a team you are on — on the Tasks page, on a record's Tasks card and in your assistant. Admins, and any role given See all tasks, still see every task. A task you create and assign to someone else leaves your view.
AI assistants
- When connecting Claude, ChatGPT or another assistant, every role can now choose Allow changes. The assistant can only do what your role allows, and it only sees the tools you can use.