Jobber contains more than a daily schedule. Depending on permissions, an account can expose client addresses, property notes, quote pricing, invoices, payments, reports, team activity, and settings that shape every customer interaction. A shared crew login or an overpowered dispatcher account therefore creates both a security risk and an operating problem: nobody can reliably tell who changed the scope, moved the visit, viewed pricing, or connected an outside application.
Jobber provides preset roles such as Limited Worker, Worker, Dispatcher, and Manager, plus higher administrative access and configurable permissions. Those options are starting points rather than a substitute for a responsibility map. A field technician who needs assigned visits and work instructions may not need financial reporting; an estimator may need quote pricing without team administration; a dispatcher may need wide schedule access without control over payment-bank details or connected-app authorization.
The strongest lifecycle joins identity, permission, device, schedule, and integration steps. Before a new employee starts, create an individual account and test the role. When duties change, approve and revalidate access rather than stacking exceptions. Before offboarding, reassign incomplete work, determine whether automations depend on that user, recover company devices and keys, deactivate at a coordinated time, and retain evidence. This guide applies that sequence to Jobber's current controls.
Key decisions at a glance
- Use named individual Jobber accounts and map responsibilities before choosing presets or custom permissions; shared logins weaken both security and accountability.
- Test Limited Worker, Worker, Dispatcher, Manager, Admin, and any custom configuration against realistic tasks on desktop and mobile devices.
- Protect the account owner, payment settings, two-step verification codes, recovery information, and support-access process as separate high-impact controls.
- Reassign incomplete calendar work and identify integration ownership before deactivating the user who created connected applications.
- Prefer deactivation when history must remain available; deletion can remove user history and should be a deliberate, documented decision.
Map Jobber Roles to Named People and Business Duties
Start with a matrix of Jobber duties, not job titles. List who may view the complete schedule, assign visits, access all clients, change request or quote records, see pricing, create invoices, collect or record payments, open reports, manage team members, change settings, and authorize integrations. Include temporary staff, subcontractor coordinators, bookkeepers, and owners who use the system infrequently. For each duty, name the business reason and approving manager.
Compare that matrix with Jobber's presets. Limited Worker and Worker configurations are designed around field activity, Dispatcher broadens operating access, and Manager supports wider oversight; Admin has substantially greater control. The exact capability set can vary with account configuration and plan, so inspect the current permission screen rather than relying on an old screenshot or a role name. Avoid using Admin merely to make an error disappear, because it obscures the missing permission and expands every future consequence of that account.
Issue one account per person with a unique email address under a company-managed identity wherever possible. Do not let a crew share one username or forward verification codes. Named accounts improve investigation, offboarding, and training, and they let the company remove one person's access without disrupting the rest of a truck or department. Record the approved role, manager, start date, device assignment, and review date beside the account.
- Separate owner, Admin, office operations, estimating, dispatch, field work, billing, bookkeeping, and reporting responsibilities.
- Require a documented reason and expiration date for temporary elevated access.
- Use company-controlled email and mobile contact details where practical so recovery does not depend on a former employee.
- Maintain a small named Admin group and a verified path for reaching the account owner.
Build and Test Least Privilege on Real Jobber Scenarios
Jobber exposes configurable permissions across areas that include schedules, time, notes and files, pricing, job costing, text messaging, clients, requests, quotes, jobs, invoices, payments, and reports. Some permissions depend on others. Change one control at a time, save the configuration, and test it as the affected user. An administrator's own screen is poor proof because elevated access can hide restrictions that the technician will encounter in the field.
Create a non-production scenario set for each role. A Limited Worker might open an assigned visit, read approved instructions, add an internal note or required photo, track time if used, and complete the visit without browsing unrelated clients. A dispatcher may need to see teams, move visits, and contact customers but should be tested for financial and administrative boundaries. An estimator should be able to prepare and revise quotes without inheriting the ability to manage every user or integration.
Test confidentiality as well as task completion. Confirm whether users can see prices, job costing, internal notes, attachments, invoice status, payment details, or broad client history. Check both desktop and the Jobber app, and include notifications and exported or downloaded information. If a custom role becomes difficult to explain, return to the duty matrix and simplify; a permission set nobody can audit is not a sustainable control.
- Capture expected allow and deny results for each tested action and retain the date, user role, device, and tester.
- Verify that customer-visible notes and messages are separated from private office and technician context.
- Retest permissions after plan changes, major feature releases, role redesigns, or changes to connected applications.
- Review Admin and custom-role membership at least quarterly and after every personnel or ownership change.
Protect Verification, Ownership, Payments, and Support Access
Enable and maintain two-step verification using contact information controlled by the intended person. Jobber requires it for account owners using Jobber Payments and can prompt when an unrecognized device signs in or sensitive payment settings are changed. A verification code is an authentication secret: Jobber says its team will never ask for that code, and staff should not relay one to a caller, coworker, or supposed support agent. Lost-phone and number-change procedures should be written before an urgent payout change is needed.
Treat account ownership as a specific governance role. Jobber documents that other users cannot edit the owner's information and that ownership can be transferred to another Admin. Confirm the current owner, business-controlled email and phone, succession contact, and transfer procedure during access reviews. If an owner departs, completes a sale, or becomes unavailable, waiting until a bank or subscription change is urgent can turn a planned transition into a service interruption.
Separate routine administration from high-impact payment and support actions. Jobber's payment-settings guidance reserves bank-detail changes for the owner, while administrators may handle other operational settings. Use Jobber's explicit support-access feature when assistance requires account visibility, record who granted it and why, and remove or let that access expire as appropriate. Never solve a support case by sharing a password or verification code.
- Verify the owner's recovery phone and email with a controlled test, then store the procedure rather than the authentication secret.
- Train users to reject unsolicited verification-code requests even when the caller claims urgency or account suspension.
- Record ownership transfers, payment-setting changes, support-access grants, and Admin changes as high-impact events.
- Review active sessions and company devices after suspected credential exposure or an unexpected verification prompt.
Coordinate Onboarding, Role Changes, and Offboarding
For onboarding, add the team member with the approved email and permissions, verify sign-in and two-step verification, issue the company phone or tablet, test assigned work, and provide a short acceptable-use and customer-data briefing. Do not wait for the first solo appointment to learn that the worker cannot see instructions or can see financial information the role never required. Obtain manager signoff after the test, not merely after the invitation is sent.
For offboarding, inventory active visits, incomplete calendar items, recurring responsibilities, approvals, devices, keys, radios, cards, and customer conversations before changing the account. Jobber's team-management guidance warns that deactivation can unassign incomplete calendar items, so reassign them first. The same dependency principle applies to connected applications: Jobber notes that apps established by a user can disconnect when that user is deactivated, and its Zapier guidance calls out the connector-user dependency directly.
Choose deactivation or deletion knowingly. Deactivation removes access and frees a seat while retaining the team member as an inactive record; reactivation does not restore assignments that were removed. Deletion is more destructive and can remove historical associations, so use it only when policy and record requirements support that outcome. After the coordinated cutoff, verify login failure, schedule ownership, integration health, returned equipment, email and phone access, and the absence of unresolved customer work.
- Use one checklist that links HR timing, Jobber status, schedule reassignment, integration ownership, and physical asset return.
- Move integrations to a durable company-managed Admin before deactivating the person who originally authorized them.
- Confirm that incomplete visits, requests, quotes, jobs, invoices, and customer follow-ups have a new named owner.
- Retain the approval, execution time, validation results, and exceptions for every departure or high-risk role change.
Vendor documentation and ALLMSP resources
- Jobber Help Center: Manage Team Members
- Jobber Help Center: User Permissions
- Jobber Help Center: Two-Step Verification
- Jobber Help Center: Account Ownership
- Jobber Help Center: Granting Jobber Support Access
- Jobber Help Center: Manage Jobber Payments Settings
- Jobber Help Center: App Marketplace
- Jobber Help Center: Jobber and Zapier Integration
- ALLMSP Software Support
- ALLMSP Cybersecurity Services
- ALLMSP Managed IT Services
- ALLMSP Construction and Contracting Resources
- ALLMSP Jobber Support Category
- Contact ALLMSP
Frequently Asked Questions
Should Jobber users share a login on the same service truck?
No. Give each person a named account so permissions, activity, recovery, and offboarding can be handled individually. A shared login makes it difficult to identify who changed a record and forces the company to disrupt several people when one worker leaves or a credential is exposed.
Which Jobber permission preset should a field technician use?
Start by comparing Limited Worker and Worker with the technician's actual duties, then test the selected configuration on the real mobile device. The right answer depends on schedule scope, notes, time tracking, pricing visibility, client access, and which records the worker must change; the role name alone is not sufficient evidence.
Who can change Jobber user permissions?
Jobber documents permission management as an Admin responsibility. Keep the Admin population small, require manager approval for changes, test the result as the affected user, and retain an access record so temporary elevation does not become permanent by accident.
Does Jobber support custom permissions?
Yes. Jobber exposes configurable controls across schedule, clients, workflow records, financial areas, reports, notes, files, and related capabilities, with some dependencies between settings. Build from a duty matrix and validate both allowed and denied actions because a custom role can otherwise contain surprising combinations.
When does Jobber use two-step verification?
Jobber requires it for account owners using Jobber Payments and may request a code for an unrecognized device or sensitive payment-setting activity. Maintain current personal contact details, never share a code, and write a lost-phone or changed-number process before a recovery is urgent.
Will Jobber support ever ask for a two-step verification code?
Jobber's guidance says its team will never ask for the verification code. A user who receives such a request should stop, avoid approving the sign-in or change, use a known official support route, and notify the company's security or IT contact.
What is special about the Jobber account owner?
The account owner holds unique authority, and other users cannot edit the owner's information. Jobber allows ownership to transfer to another Admin, so the company should verify the present owner, business-controlled recovery path, and succession plan before a departure, sale, or emergency.
Should a departing Jobber user be deactivated or deleted?
Deactivation is generally safer when the company must retain history: it removes access and frees a seat while preserving an inactive record. Deletion is more destructive and may remove historical associations. Apply the company's legal and retention policy, and document the decision before deleting.
What should happen before a Jobber user is deactivated?
Reassign incomplete calendar items, active customer work, approvals, and recurring duties; inventory devices and keys; identify apps or Zapier connections authorized by that user; transfer durable integration ownership; coordinate the cutoff; and verify both denied access and uninterrupted operations afterward.
How can ALLMSP support Jobber access governance?
ALLMSP can create the responsibility and permission matrix, test office and mobile roles, align company identity and device controls, document owner and payment safeguards, inventory connected apps, execute joiner-mover-leaver checklists, and retain validation evidence for Georgia contractors.


