Skip to main content
    Claimory

    Role-based visibility

    Everyone sees exactly what they need

    Owners get full visibility across every dollar. Managers see their team. Estimators see their book. Technicians see their work. Customers see one claim through a token-scoped portal. Row-level Postgres tenant isolation is enforced at the database, not the application.

    No credit card. Works with CCC ONE and Mitchell.

    Read the security page

    Plans from $49.99 per month per location, with a 14-day free trial. No credit card required.

    Ten role-based mechanisms

    Roles tuned to body shop jobs, not generic SaaS roles

    Each role corresponds to a real seat in a body shop. The permissions match the actual work, not a generic admin / member / viewer model.

    Owner: full visibility across every claim, every dollar

    The Owner role sees every claim, every supplement, every photo, every signature, every adjuster email, every customer SMS, every parts order, and every dollar of margin. P&L exports, DRP scorecards, cycle-time math, and per-claim profit roll up live. Nothing hidden, nothing buried.

    Manager: assigned claims, team workload, performance trends

    Managers see the claims they own and their team owns, with workload distribution, supplement aging on assigned claims, and adjuster follow-up status. Cross-team financial roll-ups stay scoped to what the manager needs to schedule the shop floor without leaking other teams' data.

    Estimator: claims they wrote, full edit access

    Estimators see and edit the claims they wrote: estimate import, supplement creation, photo posts to the bay, adjuster email drafts (AI-assisted), and customer status updates. They do not see other estimators' full books or shop-wide P&L. Focus, not noise.

    Technician: task-focused mobile view of their assignments

    Techs see the claims they are assigned to, the repair stages they own, and the photo upload prompts tied to their work. They do not see supplements, customer financials, or carrier emails. Mobile-first interface so the tech can update from the bay floor in seconds.

    Front desk: runs under the Manager or Estimator role

    Front-desk work (claim intake, customer portal links, two-way SMS threads, scheduling, pickup coordination) is a job, not a separate role. Shops assign front-desk staff the Manager or Estimator role depending on how much of the back office they also run. The four roles already cover the seat.

    Customer: only their own claim, token-protected, no login

    Customers see exactly one claim: their own. Token-protected URL with a TTL prevents forwarded links from becoming permanent leaks. They see live status, photos, ETA, and a two-way SMS thread tied to their claim. No app, no password, no access to anything else in the workspace.

    Audit log: who changed what, and when

    Every change is logged with the user, the timestamp, and the action taken: status changes, notes, photos, supplements, payments, and assignments. Compliance isn't a separate effort, it is a side effect of the database schema.

    Multi-location and multi-shop scoping

    Owners with multiple locations control which users see which locations. Regional managers scope to a region. Estimators scope to their location. Shop-level data does not leak across locations even when users have parent-organization access.

    Row-level Postgres tenant isolation

    Shop-to-shop isolation is enforced at the database row level, not the application layer. A misconfigured permission check in the app cannot accidentally expose data because the database itself rejects the query. Structural protection, not policy protection.

    Role-based access, optional 2FA, and SSO on request for Enterprise

    Access is governed by four scoped workspace roles and row-level tenant isolation on every plan. Optional two-factor authentication (TOTP) is available on every plan today; single sign-on (Google Workspace, Microsoft Entra, SAML) is available on request for Enterprise (contact sales); admin-enforced 2FA is on our roadmap.

    One Tuesday, four roles and the customer portal, five different views

    Same shop, same claims, same data. Four team members plus the vehicle owner, five different scoped views. Nothing leaks across them.

    1OwnerMonday, 8:30 am

    Owner logs in, opens the dashboard, sees the live shop-wide P&L roll-up: 47 active claims, $312,000 in pending supplements, 3 supplements aging past day 7, $48,200 in deductibles collected this month, monthly margin trend tracking against last month. Drills into the aging supplements to assign follow-ups.

    2ManagerMonday, 8:42 am

    Manager opens the team workload view: 12 claims assigned to her team, 2 supplements aging, 3 customer portal messages awaiting reply, one claim flagged by Claim Audits for missing teardown photo. She does not see the other manager's team data, by design. The view is scoped to her team.

    3EstimatorTuesday, 10:15 am

    Estimator opens his claim list: 8 claims he wrote, 2 in supplement, 3 in repair, 3 awaiting customer signature. He drafts a supplement, AI flags two adjacent line items, he approves and the supplement transmits. He does not see the other estimator's claims or the shop-wide margin numbers, only his own work.

    4TechnicianTuesday, 2:30 pm

    Tech opens the mobile app, sees the 4 vehicles assigned to him today, taps the 2024 RAV4, snaps a panel-fit photo and a teardown photo, posts both to the claim. Stage updates from body to paint. He does not see customer financials or supplements; he sees the work and posts to it.

    5CustomerTuesday, 5:45 pm

    Maria scans the QR code on her work order with her iPhone camera. The portal opens, she sees the live repair stage (paint), the panel-fit photo the tech posted at 2:30, and the pickup ETA (Friday 4:30 pm). She replies to a one-line SMS from the shop number to confirm the pickup time. She cannot see anything else in the workspace.

    Role-based access in Claimory vs CCC ONE vs Mitchell vs Excel

    CCC ONE and Mitchell ship enterprise role models for their estimating workflows. Claimory ships role models for the entire collision claim lifecycle. Excel ships nothing.

    CapabilityClaimoryCCC ONEMitchellExcel
    Four workspace roles tuned to body shop jobs
    Token-protected customer access (no login required)
    Row-level Postgres tenant isolation
    Audit log of every change

    What role-based visibility saves your shop

    Conservative estimates, not measured averages.

    Onboarding time saved per new hire
    Right access on day one

    New employees get the right access on day one without a manual permission walkthrough. Default roles fit the actual job, so the office manager does not have to grant permissions one toggle at a time.

    Compliance review prep time
    Hours, not days

    Quarterly DRP and annual cyber liability reviews ask for 'who has access to claim data'. The role schema and the audit log answer that in minutes instead of days of screenshots.

    Risk of cross-shop data leak
    Checked by the database

    Row-level security on every table that holds shop data means the database itself checks each query against the signed-in user's shop, a second layer behind the app's own permission checks.

    Customer-facing leak risk
    Token TTL prevents permanent exposure

    Customer links carry a time-to-live so a forwarded link does not become a permanent access point. Lost phones, public group chats, or accidental Slack posts do not become a long-term liability.

    Short answer

    What is role-based visibility, and why does my body shop need it?

    Role-based visibility means each user (Owner, Manager, Estimator, Technician) sees exactly the slice of claim data their job needs and nothing more, plus token-scoped customer portal access for the vehicle owner. The slicing is enforced at the database row level, not the application layer.

    Generic shop tools tend to ship a flat 'admin / member / viewer' permission model that maps poorly to the real seats in a body shop. Owners need shop-wide P&L, but they should not have to grant a manager access to other teams' claims to make scheduling work. Estimators need their own book of claims, but they should not see another estimator's customer financials. Customers need their claim status, but they should never be one URL away from another customer's photos.

    Claimory ships four workspace roles tuned to the actual jobs in a collision shop (Owner, Manager, Estimator, and Technician), plus token-scoped customer portal access for the vehicle owner. Tenant isolation runs at the Postgres row level, so even a misconfigured permission cannot leak data across shops because the database itself rejects the query.

    Optional two-factor authentication (TOTP) is available on every plan today. Single sign-on (Google Workspace, Microsoft Entra, and SAML for Enterprise identity providers) is available on request for Enterprise (contact sales); admin-enforced two-factor authentication is on our roadmap. Today every paid plan includes the four-role model and Postgres row-level isolation. Plans from $49.99 per month per location, with a 14-day free trial. No credit card required.

    Default roles
    Four, body-shop tuned
    Isolation
    Postgres row-level
    Plans from
    $49.99/mo per location
    Free trial
    14 days, no card

    Frequently asked questions

    What roles does Claimory support, and can I customize them?

    Claimory ships four workspace roles tuned to the jobs a body shop actually runs: Owner, Manager, Estimator, and Technician. Each role has row-level scoped permissions tuned to the actual job that role does in a body shop, plus token-scoped customer portal access with no login for the vehicle owner. Row-level tenant isolation applies to every role.

    How does Claimory prevent one shop's data from leaking to another?

    Tenant isolation runs at the Postgres row level, not the application layer. Every query carries a shop-level scope that the database itself enforces. A misconfigured permission check in the app cannot expose another shop's data because the database rejects the cross-tenant query before it returns anything. This is structural protection, validated by external security review.

    Can a customer see anything about other claims or other customers?

    No. Customers access exactly one claim through a token-protected URL with a time-to-live. The token is scoped to a single claim, and the database enforces that scope. A forwarded customer link does not become a permanent leak because the token expires. There is no customer login, no customer dashboard, and no way for a customer to navigate to another claim.

    How do estimators see their own claims without seeing the whole shop?

    Estimators see and edit claims they wrote (or are assigned to) plus claims their manager has shared with them. They do not see other estimators' full books, shop-wide P&L, or owner-level financials. Read access scopes to assigned claims plus shared workspaces. Write access is even tighter, locked to claims they are responsible for.

    Does Claimory support SSO and two-factor authentication?

    Optional two-factor authentication (TOTP) is available on every plan today; each user enables it from Account settings. Access is governed by the four-role model and row-level tenant isolation on every paid plan. Single sign-on (Google Workspace, Microsoft Entra, and SAML) is available on request for Enterprise (contact sales); we configure your identity provider with you. Admin-enforced two-factor authentication is on our roadmap.

    Does Claimory log who changed what on a claim, and when?

    Yes. Every change is logged with the user, the timestamp, and the action: status changes, notes, photos, supplements, payments, and assignments. If a number changes, the change is visible in the audit trail with the user who made it. The log is exportable on demand for security reviews.

    Is role-based visibility included on Starter, or is it only on higher plans?

    Role-based visibility, audit logs, row-level tenant isolation, and the four-role workspace model are included on every paid plan starting at Starter ($49.99 per month per location) with a 14-day free trial. Optional two-factor authentication (TOTP) is available on every plan. Single sign-on is available on request for Enterprise (contact sales); admin-enforced two-factor authentication is on our roadmap.

    Give every team member the right access on day one.

    Four role models tuned to the body shop, plus token-scoped customer portal access. Row-level tenant isolation. Audit logging on sensitive actions. Plans from $49.99 per month per location. No credit card required.

    No credit card. Works with CCC ONE and Mitchell.

    Read the security page