CupixWorks 5.0 — this article is still being finished. Screenshots marked to be replaced show the right screens and will be retaken before launch. Taken in a support session, so the top of the screen shows a bar you will not see. Taken on an internal test system, so the address and team name are not the ones you will see.
The product draws this matrix for you
You do not have to hold the permission model in your head. Team Settings › Members is the matrix. It lists everyone in a scope down the left and the grades available in that scope across the top, and marks which grade each person holds.
This article explains how to read it. The four role articles beside it explain what each grade can actually do.
The roles, and what each one is
CupixWorks has eight roles across three scopes. A role is granted at one scope and reaches everything below it, so the same person can be a Team Admin here and hold nothing at all in another team.
| Scope | Role | What it is |
|---|---|---|
| Team | Super Admin | The team's owner-level grade. It is displayed but never offered when inviting someone or changing a permission — it changes hands only by transfer. |
| Team | Team Admin | Administers the whole team: every workspace and every project in it, plus team-wide settings, standards and templates. |
| Team | Team Member | Belongs to the team without administering it. |
| Workspace | Workspace Admin | Administers one workspace and every project inside it. The product's own words: “Full access to workspace settings, members, and all projects.” |
| Workspace | Workspace Member | The product's own words: “Can view and contribute to assigned projects within the workspace.” Membership is usually a consequence of being added to a project inside the workspace rather than something granted directly. |
| Project | Project Admin | The product's own words: “Manages the Project Admin Center — members, project assets such as BIM and levels, SiteView setup, SiteInsights and Deviation analysis.” |
| Project | Project Member | The product's own words: “Accesses every SiteView in the project, views SiteInsights and Deviation Analysis reports, and can add captures.” |
| Project | Guest | Limited access to one project, granted per app. For each app on the project's roster a guest is set to Read Only or Read & Write; an app the project does not use cannot be granted. |
Where a description is quoted above, those are the words CupixWorks itself prints on the Permission Levels card — on the workspace's Workspace Members tab and the project's Members tab. If a description here and the one on your screen ever disagree, the screen is right and this page is out of date.
If you used CupixWorks 4.0: SiteView Member and SiteView Observer are no longer roles. SiteView Member is now a Guest with Read & Write and Observer is a Guest with Read Only. A Guest with Read & Write can do everything a SiteView Member could.
How to read the tables below
Super Admin, Team Admin, Workspace Admin and Project Admin share one row in the tables below. Within their own scope they have the same access to features; they differ in how far that scope reaches — one project, one workspace, or the whole team.
Guest appears as two rows, because a guest's level is set for each app separately. A guest can be Read & Write in SiteView and Read Only in another app on the same project.
| Cell | Means |
|---|---|
| Yes | the role can do this |
| No | the role cannot do this |
| All | every SiteView in the project |
| Shared only | only the SiteViews a Project Admin has shared with them |
| View only | can see what others made, cannot create or change it |
| Create & View | can create their own and see everyone's |
| ? | not yet confirmed — this cell is being verified and is deliberately not guessed |
What each role can do: capture and SiteView
This table applies to every project, whatever else the project has switched on.
| Role | Capture | Access SiteViews | Create SpatialNotes | Save Measurements | Generate Timeline Reports | Bookmarks |
|---|---|---|---|---|---|---|
| Super Admin | Yes | All | Yes | Yes | Yes | Create & View |
| Team Admin | Yes | All | Yes | Yes | Yes | Create & View |
| Team Member | ? | ? | ? | ? | ? | ? |
| Workspace Admin | Yes | All | Yes | Yes | Yes | Create & View |
| Workspace Member | ? | ? | ? | ? | ? | ? |
| Project Admin | Yes | All | Yes | Yes | Yes | Create & View |
| Project Member | Yes | All | Yes | Yes | Yes | Create & View |
| Guest — Read & Write | No | Shared only | Yes | Yes | Yes | Create & View |
| Guest — Read Only | No | Shared only | View only | Create, cannot save | No | View only |
What the columns mean. A Yes is only useful if you know what it is a yes to.
| Capability | Definition |
|---|---|
| Capture | Record 360° site captures in the CupixCapture app, or upload captures through CupixConnect. |
| Access SiteViews | Which SiteViews in the project the role can open. |
| Create SpatialNotes | Add markers, forms and notes to document site conditions. |
| Save Measurements | Create and save measurements for distances, areas and volumes. A Read Only guest can take a temporary measurement but cannot save it. |
| Generate Timeline Reports | Export a PDF report showing site progress across several capture dates. |
| Bookmarks | Saved viewpoints in SiteView. |
Add-on: CupixConnect
CupixConnect. Available with the relevant license or activation — Reality Capture and drone uploads need the higher license tier.
| Role | Upload CupixCapture | Upload Reality Capture | Upload drone photos | Download SiteView content |
|---|---|---|---|---|
| Super Admin | Yes | Yes | Yes | Yes |
| Team Admin | Yes | Yes | Yes | Yes |
| Team Member | ? | ? | ? | ? |
| Workspace Admin | Yes | Yes | Yes | Yes |
| Workspace Member | ? | ? | ? | ? |
| Project Admin | Yes | Yes | Yes | Yes |
| Project Member | Yes | Yes | Yes | No |
| Guest — Read & Write | No | No | No | No |
| Guest — Read Only | No | No | No | No |
What the columns mean. These capabilities exist only when CupixConnect is available on the project.
| Capability | Definition |
|---|---|
| Upload CupixCapture | Send captures recorded in the mobile app up to the project. |
| Upload Reality Capture | Upload laser-scan or other reality-capture data. |
| Upload drone photos | Upload drone imagery for processing. |
| Download SiteView content | Pull SiteView content back down to a desktop. Downloads must be enabled for your team, and are unavailable for archived projects or expired licenses. |
Add-on: Drone Capture
Drone Capture. Available with the relevant license or activation — Higher license tier only.
| Role | Upload via CupixConnect | Edit & publish in the editor | Visualize in SiteView |
|---|---|---|---|
| Super Admin | Yes | Yes | Yes |
| Team Admin | Yes | Yes | Yes |
| Team Member | ? | ? | ? |
| Workspace Admin | Yes | Yes | Yes |
| Workspace Member | ? | ? | ? |
| Project Admin | Yes | Yes | Yes |
| Project Member | Yes | No | Yes |
| Guest — Read & Write | No | No | Follows SiteView access |
| Guest — Read Only | No | No | Follows SiteView access |
What the columns mean. These capabilities exist only when Drone Capture is available on the project.
| Capability | Definition |
|---|---|
| Upload via CupixConnect | Upload drone images for cloud processing into aerial maps. |
| Edit & publish in the editor | Review the processed result, adjust the vertical (Z) offset, and publish the data types you want — Ortho, DSM, Point Cloud, Mesh — to SiteView. |
| Visualize in SiteView | View published aerial maps in Compare View with the usual SiteView tools. |
Add-on: AssetAtlas
AssetAtlas. Available with the relevant license or activation — A 5.0 app; the cells come from its own 4.0-brand draft, not from the PO.
| Role | View registry & status history | Browse, filter, switch layouts | Add, edit, import, delete | Reposition in the viewer |
|---|---|---|---|---|
| Super Admin | Yes | Yes | Yes | Yes |
| Team Admin | Yes | Yes | Yes | Yes |
| Team Member | ? | ? | ? | ? |
| Workspace Admin | Yes | Yes | Yes | Yes |
| Workspace Member | ? | ? | ? | ? |
| Project Admin | Yes | Yes | Yes | Yes |
| Project Member | Yes | Yes | Yes | Yes |
| Guest — Read & Write | Yes | Yes | No | No |
| Guest — Read Only | Yes | Yes | No | No |
What the columns mean. These capabilities exist only when AssetAtlas is available on the project.
| Capability | Definition |
|---|---|
| View registry & status history | Read an asset's detail and every status change recorded against it, with timestamp and user. |
| Browse, filter, switch layouts | Move around the registry — by category, by text filter, and between the table and the 3D and floor-plan layouts. |
| Add, edit, import, delete | Change what is in the registry, including CSV import. |
| Reposition in the viewer | Give an asset a coordinate by pointing at it in the embedded viewer. |
Add-on: SiteInsights
SiteInsights. Available with the relevant license or activation — Needs SiteInsights activation.
| Role | View dashboard | Create reports | Initiate analysis |
|---|---|---|---|
| Super Admin | Yes | Yes | Yes |
| Team Admin | Yes | Yes | Yes |
| Team Member | ? | ? | ? |
| Workspace Admin | Yes | Yes | Yes |
| Workspace Member | ? | ? | ? |
| Project Admin | Yes | Yes | Yes |
| Project Member | Yes | Yes | No |
| Guest — Read & Write | No | No | No |
| Guest — Read Only | No | No | No |
What the columns mean. These capabilities exist only when SiteInsights is available on the project.
| Capability | Definition |
|---|---|
| View dashboard | Open the app's dashboard and read its results. |
| Create reports | Export the results as a PDF, with your own grouping and date range. |
| Initiate analysis | Request a new analysis run to update the results. |
Add-on: DeltaBIM
DeltaBIM. Available with the relevant license or activation — Higher license tier only.
| Role | View dashboard | Initiate analysis |
|---|---|---|
| Super Admin | Yes | Yes |
| Team Admin | Yes | Yes |
| Team Member | ? | ? |
| Workspace Admin | Yes | Yes |
| Workspace Member | ? | ? |
| Project Admin | Yes | Yes |
| Project Member | Yes | No |
| Guest — Read & Write | No | No |
| Guest — Read Only | No | No |
What the columns mean. These capabilities exist only when DeltaBIM is available on the project.
| Capability | Definition |
|---|---|
| View dashboard | Open the app's dashboard and read its results. |
| Initiate analysis | Request a new analysis run to update the results. |
Not in these tables yet
Five things in CupixWorks 5.0 have no role table here yet, because no specification states one: Compass, Analytics, SmartFilter, Custom Object Locator, BIM AI. They are being confirmed and will be added as separate tables in the same shape as the ones above.
Two roles — Team Member and Workspace Member — show ? in every table. Both are new in 5.0, so there is no earlier documentation to carry. What each one is is settled and appears in the roster above; what is still being confirmed is the detail of what each may do, capability by capability. Those cells are being checked rather than guessed.
Pick the scope first, because the scope decides the columns
The panel on the left is Permission Scope — All Members at the top, then every workspace, and the projects inside each one. Each node carries its own member count.
Choosing a node changes the table. Not just the rows — the columns too, because different scopes have different grades:
| Scope | The grade columns you get |
|---|---|
| Team (All Members) | Super Admin · Admin · Member · Guest |
| Workspace | Workspace Admin · Workspace Member |
| Project | Project Admin · Project Member · SiteView Member · Guest |
It also renames the button in the top right: Add Member at team, Add Workspace Member on a workspace, Add Project Member on a project. If you are wondering which scope you are about to add someone to, read that button.
Reading a row
Three things sit on every row. Who — name and email, or a group. Status — Active or Invited. And the grade columns, where the cell marks the level that person holds here.
A cell can name a scope instead of a grade. That means the permission is inherited from a level above rather than granted here. It is not a blank and it is not an error: it is the matrix telling you where to go to change it.
Invited is not Active. An invited person occupies a row and a grade before they have ever signed in, which is what makes the matrix a record of intent as well as of access.
The tabs and the filter
Above the table: All, Users and Groups. Groups appear in the same table as people because a group holds a grade the same way a person does.
Beside them, a filter by name or email. On a team with a few hundred members that is the fastest route to one person's row, and the row menu then offers Filter by this user to pin the view to them across scopes.
Changing one person's permission
The row menu offers Change Permissions, Filter by this user and Remove.
Change Permissions opens a dialog naming the person and the scope, with one radio per grade and a one-line description of each. The grade they hold already carries a Current badge.
Which scope you are editing was decided when you opened the dialog, not inside it. That matters because a workspace and a project can carry the same name, so the header alone will not always tell you. If in doubt, close it and check what is selected in the scope tree.
What the matrix is not
It is not a list of who can see this scope. Workspace Admins, Team Admins and Super Admins reach everything below them without appearing on the list. A project's member list of four can be visible to a dozen people.
It is not a list of who can act today. A deactivated member keeps their row and their grade, because the matrix answers how permission is distributed, not who is currently able to sign in.