Mason Permissions: Team Member and Field Users
Learn how to give team members and field users access to Mason, automations, and tools.
- Role-based permissions: turn Mason access on or off for team members and field users.
- Automation-level permissions: choose which specific automations each role can run.
- Tool-level permissions (inherited): built-in guardrails that control what data and actions Mason can touch on a user's behalf, regardless of role or automation access.
Table of Contents
- Role-based permissions
- Managing role-based access to Mason
- Automation-level permissions
- Tool-level permissions
1. Role-Based Permissions
For team members and field users, admins can control access to two separate capabilities:- Automations: the ability to run Ressio's prebuilt automations (with custom, user-built automations coming soon).
- Messaging: the ability to have a free-form, natural language conversation with Mason — similar to chatting with any other LLM — rather than being limited to running predefined automations.
💡Admin users always have full access to both Messaging and Automations. This access can not be disabled.
‼️Messaging and automations are not fully independent toggles. Since automations are part of the messaging process, any role with messaging access automatically has access to automations. Admins users can turn off messaging while still allowing a role to use automations — so a role can be restricted to automations only, but not the reverse.
2. Managing role-based access
- Go to the Automations page

- Click the Manage Access (cog) icon to open the AI Tool Permissions page

- Toggle Messaging and Automations on or off for Team Members and/or Field Users

💡Admin users can also reach this same screen directly from the Admin > AI Tool Permissions page.
3. Automation-Level Permissions
Giving a role access to automations doesn't mean they get access to every automation. Admins can control this at the individual automation level:
- Go to the Automations Library

- Click the name of any Automation and choose whether that specific automation is available to Team Members and/or Field Users

💡This is useful when an automation doesn't apply to a particular role, or when you simply don't want certain roles running it, even if they have general automation access.
4. Tool-Level Permissions (Inherited, Non-Negotiable)
Behind every Mason interaction, Mason relies on a set of underlying tools (for example, creating a bill, creating a change order, or updating an estimate). These tools have their own inherited permission settings based on the user's role, independent of the Mason-specific permissions above.
This means:
- Field users and team members will not gain access to tools or data their role doesn't already permit, even if they're allowed to use an automation that calls those tools.
- These underlying tool permissions are stricter than, and independent of, the Mason messaging/automation toggles, and act as a safety net.
💡If a team member or field user repeatedly runs into a tool restriction and legitimately needs that access for their job, this is a good opportunity to review their role and permission level rather than trying to work around it through Mason.
Allowing team members and field users utilize Mason lets your whole organization - not just office staff - get value from AI assistance, while keeping sensitive actions and data locked down appropriately. Common use cases for team members and field users include:
- Automatically creating daily logs
- Posting or creating to-do lists
- Translating messages or notes between English and Spanish (and other supported languages)