Panzo
Getting started

Invite your team and set roles

Add users, assign role-based access and set the reporting hierarchy so people see only what is relevant to them.

Add the people who run your studio, give each of them exactly the access their job needs, and set up the reporting lines so everyone sees what is relevant and nothing more. This guide is for the owner or admin doing the first setup.

Add your team

You add and manage people from Control Panel → Users. When you create a user, Panzo also provisions their sign-in automatically, so they can log in straight away rather than existing in the app but being unable to get in. If any older accounts were added before this and still have no login, the Users page shows an amber banner with a Create Logins button that fixes them all in one click, and each affected person carries a No Login chip until you do.

  1. Open Control Panel and go to Users

    You need the Manage Users permission to see this. The list shows everyone in your organisation and their status.
  2. Add the person

    Enter their name, email and contact details, then pick their Role and Profile. The Profile is what actually controls access, so choose it with care.
  3. They sign in

    The account is ready immediately. People reach the sign-in screen from the Sign In link on the marketing site, then enter their email and password.

Note

Enterprise identity

Single sign-on, SAML and two-factor authentication are on the roadmap and are not available yet. For now, sign-in is by email and password.

Roles and profiles: who can do what

Access in Panzo is governed by a Profile permission matrix. A Profile spells out which actions a person holds in each module, for example editing in Finance or approving a BOQ in Procurement. The same decision is enforced identically on the web, in the mobile app and in the interface, so a person never sees a button they are not allowed to use.

Most modules are open by default, so a new hire whose Profile you have not fully configured is not locked out of everyday work. The modules that move money are the exception: they deny by default. A brand-new account can never record or approve a payment until you grant it explicitly, which keeps your cash safe from day one.

AreaDefault accessWhy
Everyday modules (Leads, Projects, tasks, and the like)Allowed until you restrict themSo an unconfigured account can still do its job
FinanceDenied until grantedInvoices, collections and payment milestones move money
ProcurementDenied until grantedVendor payments, purchase orders and BOQ approval move money
Money-moving After Care actionsDenied until grantedApproving claims and warranty decisions carry real cost

Reporting hierarchy and record visibility

Beyond which actions a person can take, Panzo controls which records they can even see. Every module can be scoped so a person works with their Own records, their Team's records, or All records in the organisation. This is how you map your reporting lines onto the app: a sales rep sees their own leads, a team lead sees the whole team's, and an owner sees everything. The scope applies to editing and deleting too, so someone on Own cannot change a teammate's record even if they know its reference number.

Tip

Start tight on money, generous on visibility

A common setup is to keep Finance and Procurement granted only to the few who need them, while giving delivery staff Team visibility on Projects so a manager and their site engineers share one live picture.

Keep a record of access changes

Privileged admin actions are written to an access audit log: when a user is created, when someone's access changes (recorded as a clear from and to), and when an admin uses the View As tool to see the app through another person's permissions. The View As activity is always recorded against the real admin, so impersonation is traceable rather than a blind spot. If you ever remove someone, deleted records go to the 30-day recycle bin rather than vanishing.

Key takeaways

  • Creating a user in Control Panel provisions their sign-in automatically, with a one-click backfill for older accounts.
  • A Profile permission matrix decides who can do what, enforced the same way on web and mobile.
  • Finance, Procurement and money-moving After Care actions deny by default, so new accounts cannot touch money until you allow it.
  • Own, Team and All record scopes map your reporting hierarchy onto what each person can see and edit.
  • SSO, SAML and 2FA are not available yet; access changes and View As are captured in an audit log.

Cannot find what you need? Ask the Panzo team.

Bring structure to your interior business.

Start managing your leads, quotations, projects, procurement, billing, and handovers with Panzo.