Somebody on your team can't see a report. Somebody else can see payroll numbers they have no business seeing. And your dispatcher just moved a job on a board they shouldn't have been touching in the first place.
Permissions in ServiceTitan are one of those things nobody sets up on purpose. You get through onboarding, everybody gets whatever the default was, and then you spend the next two years playing whack-a-mole every time someone says "hey, I can't find this." So let's fix that. Here's how permissions actually work, where they hide, and the settings I'd get right before you touch anything else.
Start with roles, not people
You can set permissions two ways in ServiceTitan, by role or by individual employee, and almost everywhere you go you'll see that same toggle. Set them by role. It's faster, it's consistent, and when you hire someone new you just drop them into the role and you're done. Individual permissions are for exceptions, not for building your whole system. Set permissions person by person for twenty employees and you'll end up with twenty slightly different setups and no way to remember why.
There's a catch though. When you edit permissions at the role level, the change doesn't automatically apply to people already in that role. Most of these screens have a checkbox at the bottom that says something like "update existing employees." Skip it and your change only affects new hires. That one trips up a lot of people. They make the change, tell the team it's fixed, and nothing happened.
And here's the flip side. If you do check that box, you'll wipe out any custom permissions that were set on individuals in that role. So if Jamie in accounting had one special permission somebody granted her a year ago, that's gone. Usually that's fine, honestly it's kind of the point. Just know it's happening.
The business unit field is the strongest lock in the system
This is the one most people don't know about, and it's the most powerful permission tool you have.
Go to Settings, then People, then Employees, and click into any employee. There's a business unit field on the profile. It's optional, no red star next to it. If you leave it blank, that person can see everything. But if you assign a business unit there, ServiceTitan hard-locks that employee to it. They can only view or use features tied to that one business unit.
Let's say you've got a dispatcher who only handles HVAC service. Normally they'd apply a filter on the dispatch board, and that filter follows them around the product. Which is nice, but it's still just a filter. They can clear it and get to everything else. Assign them to the HVAC Service business unit on their profile and that filter turns gray. They can see it's applied. They can't change it. No more accidentally rescheduling an install job in a business unit they've never worked in.
This carries into dashboards too. Assign a business unit to an employee and their dashboard gets limited to it, whether you wanted that or not. The downside is you only get one. You can't assign someone to "all of HVAC" if HVAC is split across service, install, and sales. So this works great for people with a narrow lane and not at all for anyone who moves between them.
Reporting permissions live in three different places
Reporting is where permissions get genuinely confusing, because there are three separate layers and they all have to agree before someone can see a report.
Layer one: employee permissions
Go into an employee or role's permissions tab and search for reports. You'll find a handful. Can they view scheduled reports associated with them, can they view all scheduled reports, can they edit or delete them, can they view job costing reporting. That last one also affects the job costing flyout, not just the report, which is probably why it's parked there.
Layer two: report template permissions
Go to Settings and search for reporting. Under Operations you'll find Reporting Settings, and the last tab is Reporting Permissions. This controls which report templates and categories a role can view and edit.
Templates are the data sets, and that's the key idea. Every report built on the jobs data set is basically the same report. The only difference is how it's filtered and which columns show. Give someone view and edit access to the jobs template and they can open any jobs-based report and add whatever column they want.
ServiceTitan's defaults here are pretty reasonable. The dispatch role, for example, sees the jobs template and that's it. No invoices, no inventory, no payroll. For most companies that's exactly right, so mostly you'll be in this screen to troubleshoot when somebody swears a report should be there and it isn't. While you're in there, do yourself a favor and take away everybody's permission to view legacy report categories. Legacy reports should just stop existing in your account. That's my opinion, but I'd stand behind it.
Layer three: sharing on the individual report
Open the Reports tab, find a report, click the kebab menu, and there's a Share Access option. Manage by role and you only control who views. Manage by individual user and you control view and edit. I don't have a good explanation for that one.
You'll also see exclamation points next to some names in that list. That means the person is missing a permission somewhere else, and checking the box here won't fix it. Click the exclamation point and it tells you what's missing, usually template access from layer two, with a Give Permission button right there.
Now here's the part that actually matters. Say there's one KPI on one report you don't want a certain person seeing. Revoking their access to that specific report doesn't do it. If they can see any other report built on the same template, they can just add that column back in. To really block it, you have to take away their edit access on the template. Otherwise you've locked the front door and left the window open.
Dashboard permissions are separate again
Settings, Operations, Dashboards. Three tabs: Permissions, Modular, and Custom Dashboards.
The Permissions tab controls who can view dashboards, who can edit them, and who can export from the modular dashboard drill-down. That export one is worth a thought. Some modules have a download button that lets anyone pull the raw data out into a spreadsheet. If you don't want that, this is the switch.
The Modular tab is more interesting than it sounds. Two settings in there change what your numbers actually mean. One is whether adjustment invoices count toward revenue on technician scorecards. Turn it on and the KPI renames itself from Completed Revenue to Completed Revenue With Adjustments, on the modular dashboard, the tech scorecard, and the dashboard your techs see on their phones. The other is whether billable efficiency uses all invoice items or only ones tied to income GL accounts. Default is income only.
Further down that tab you can control access to individual modules. If you don't want a certain group seeing the 18 month trend but you're fine with them seeing everything else, pull that one module and leave the rest alone. And on the Custom Dashboards tab, the lock icon is where you share. Quick tip while you're there: you can't edit a prebuilt ServiceTitan dashboard, but you can duplicate it, and the copy is yours to change however you want.
Managed versus non-managed technicians is a permission decision that costs money
This one isn't in the permissions screen at all, but it's the biggest access decision you'll make for field users, and ServiceTitan bills you per managed technician.
A managed tech is anybody who needs to collect revenue or get credit for selling or performing work. Service techs, lead installers, comfort advisors, salespeople. A non-managed tech is a helper paid hourly. They still get the mobile app, dispatch themselves, arrive, clock in and out, and fill out forms. What they can't do is touch the pricebook, add tasks to invoices or estimates, convert estimates, or take a payment alone. They also can't carry a split above zero percent, so no commission pay through ServiceTitan.
Every job needs a managed tech on it. And I'll save you some trouble here: don't create a floater managed tech account that you assign to jobs so your helpers can close them out. People have tried it. ServiceTitan now checks whether the managed tech was actually on site before it lets the job close, and you can't force it from the office either. Beyond getting caught, it wrecks your reporting. There are legitimate cases where a managed tech never shows up, like installation subcontractors or techs who just don't use the mobile app. If that's you, walk your CSM through the workflow and they can make an exception.
The timesheet permissions everyone forgets
On the employee side, open the permissions tab and look for the timesheets section. To clock in and out at all, an employee needs "view employee time tracking and edit page" checked. From there you decide whether they can edit their own entries, whether they can edit everyone else's, and who gets the reporting.
On the technician side, anyone set up for hourly pay can clock in and out by default, and some of it is automatic. When a tech taps dispatch, ServiceTitan clocks them into the driving activity on its own. If you want them clocking into activities that aren't automated, you have to allow manual timesheets. Decide up front whether techs can fix their own mistakes too. I lean toward yes, because the alternative is your office manager rebuilding somebody's week every Friday.
Test it before you ship it
Two habits that will save you a lot of pain. First, use your Practice environment. You've got two sandboxes, Next and Practice. Next has the upcoming release in it and overwrites its data every Friday night, so it's for training on what's coming, not for general use. Practice runs the same release as your live account and refreshes much less often. That's the one you want.
Second, actually log in as the person. Not check the boxes and assume. Log in and look at their screen. It takes two minutes and it's the only way to know your dispatcher sees the four technicians they're supposed to see instead of all forty.
Wrapping up
Permissions in ServiceTitan aren't one screen, they're four or five screens that all have to line up. Set them by role, remember the update existing employees checkbox, use the business unit field when you need a real lock instead of a filter, and remember that reporting access is only as tight as the loosest of its three layers. Get those right and most of your "I can't see this" tickets go away.
If this was useful, the guide goes much deeper. The Ultimate ServiceTitan Guide has searchable video lessons covering permissions, user management, reporting, payroll, and every other part of ServiceTitan, built for every role on your team. You can check it out at bluecollarnerd.com.