Help center

LBCAssist user guide

Plain-language help for registration, billing, projects, field assistants, files, reports, account administration, and security settings.

U.S.-based customers and authorized users only.

Start here

LBCAssist is organized around tenants, licensed users, and projects. Most day-to-day work starts on the portal, where you select a project and open the service you need: Diagram Assistant, Time Assistant, Mileage Assistant, Task Assistant, or Files.

What you can see depends on your permissions. Every page and control asks for the permission behind it, never for the name of your role, so editing what a role may do changes what its holders see. You see the pages and services allowed by your permissions, your project assignments, and an active license. The one exception is the account owner, below.
Guides Quick-start workflows for setup, projects, and field work. Legal Terms, Privacy, SLA, termination policy, and open-source notices. Email Contact admin@lbcassist.com. Do not email passwords, tokens, or sensitive project files.

Quick Workflows

New tenant setup

  1. Register the contractor business and default administrator.
  2. Select the initial license bundles and count.
  3. Complete Stripe Checkout to start the trial or paid subscription.
  4. Add users, assign licenses, and grant only the permissions each user needs.
  5. Create projects, enable the services each project needs, and assign users to the project.

Daily project work

  1. Sign in and choose a project from the portal.
  2. Select the project address if the project has more than one location.
  3. Open the relevant assistant for diagrams, files, time, mileage, or tasks.
  4. Use Reports to review completed work, invoices, file activity, task activity, time, and mileage.

When something is missing

  1. Confirm your user has an active assigned license.
  2. Confirm your permissions include the page or service you need.
  3. Confirm the project has that service enabled.
  4. Confirm you are assigned to that project — unless your role carries a manage permission for that service and is set to manage every project in the company, which reaches the project on its own. A role set to manage only its assigned projects still needs the assignment.

Access, Roles, Permissions, and Licenses

Access is tenant-scoped. Your tenant is the contractor business account you belong to. The application reads your tenant, permissions, billing status, license assignment, and project assignments from the server.

Control What it affects
Assigned license A user must have an active assigned license to sign in and use paid services.
Default tenant administrator Super user for the tenant, also called the account owner. This user always keeps one protected paid license, can see and manage every project whether or not they are assigned to it, and can list every project in the company without being on any of them. What is unusual about it is not that reach — other people in your company almost certainly have it too, see the next row — but that it cannot be granted. No permission confers it and no role edit hands it over; it moves only when the person who holds it transfers it. Every access that relies on it is written to the audit log. See The account owner for what it can do and how to move it.
How far a role’s manage permissions reach A setting on each role, and the usual reason several people in a company reach every project. A role set to manage every project lets everyone on it correct and delete other people’s time, mileage, tasks, files and drawings on every project in the company, assigned or not. A role set to manage only assigned projects does the same on its members’ own jobs only. Every role starts on the first setting except the one your company starts with called Project Lead, which manages everyone’s work on its own jobs only and carries no company administration and no legal holds. You set this on Roles and can narrow it at any time.
The permission to manage roles Decides who may edit what a role is allowed to do, which makes it the permission that governs every other one. A role can never be left without it — the built-in administrator role your company starts with always keeps it, and you cannot remove it from your own role — so there is always a way back in. Narrowing a role’s project reach does not touch it, or people, teams or billing management, so narrowing cannot lock you out.
Project assignment Controls which projects a user can work on. Whether they can open Time, Mileage, Tasks, Files, or Diagrams there is then decided by the service being enabled on the project and by the permissions their role carries. There is no separate per-service assignment list. Assignment is what the access permissions are scoped to. Whether the manage permissions consult it depends on the role: one set to manage every project does not, one set to manage only its assigned projects does — see below.
Billing status Setup, trialing, active, past due, suspended, terminated, or other Stripe-driven states.

Core permissions cover project create, edit, delete and staffing; managing people, roles and teams; viewing audit logs and reports; company settings and billing; time, mileage and task use and management; the four diagram permissions described under Diagrams; file upload, view, download, edit, delete, management and legal hold; and the between-company permissions described under Collaborate.

Access and manage reach different distances

Time, Mileage, Tasks, Files and Drawings each come as access and manage permissions, and the pair is not simply narrow and wide versions of the same reach:

  • Access is project-scoped, always. The holder sees and acts on the projects they are assigned to, and no others. Take them off a project and that service closes for them there. No setting widens this.
  • Manage means acting on other people’s records — reading, correcting and deleting them. How far it reaches is set on the role, on the Roles page, and it is the one thing about a permission you choose rather than inherit.

Choosing how far a role’s manage permissions reach

Each role answers one question: does it manage every project in the company, or only the projects its members are assigned to? You set it while editing the role, and each permission in the list shows which answer applies to it.

  • Every project in the company suits the back office. Correcting somebody’s timesheet should not require adding the office to every job, so assignment is not what grants this and unassigning does not remove it. This is what every role does unless you change it.
  • Only assigned projects suits somebody who runs the jobs they are on. They still correct and delete other people’s records — that is what manage means — but only on their own jobs. The seeded Project Lead role is set this way.

It is worth being concrete about where your company starts, because this catches people out. Of the five roles your company is created with, only Project Lead is limited to assigned projects; the other four are set to every project. That matters for the two of them that actually hold manage permissions. The role called Office manages time, mileage, tasks and files, so from the day the account is created everybody on it can open, correct and delete other people’s records in those four services on every job in the company, including jobs they have never been assigned to — and the built-in administrator role does the same, adding drawings. The remaining two, Field and Subcontractor, manage nothing, so the setting has nothing to apply to and changing it for them changes nothing.

That starting point is intended rather than an oversight: the back office is expected to work across the whole company without being added to every job. It is also entirely yours to change — switch any role to assigned projects only on Roles, and it takes effect for everyone on that role on their very next action.

The setting covers exactly five things: managing time, mileage, tasks, files and drawings. It does not narrow company administration. A role limited to its assigned projects still manages people, roles, teams, billing and company settings across the whole company, because none of those is about a project. It also does not touch the access permissions above — those stay project-scoped either way.

The setting only appears when the role actually holds one of those five permissions. On a role that holds none of them there is nothing for it to change, so it is not shown.

Two limits still hold. Manage stops at your company — it never reaches another company’s projects, whoever you collaborate with. And it never opens a service a project has switched off; deciding which services a project runs is a project setting, not something a manage permission overrides.

One thing manage does not do is list your company’s projects for you. It reaches any project a holder opens, but the cross-project views still show the projects they are on. Only the account owner sees every project listed without being assigned.

Roles belong to your company, not to the product. Your company starts with Field, Project Lead, Office, Admin and Subcontractor, and you can rename them and change what each one may do — see Roles. Because a role can be edited, LBCAssist never decides access from the name of a role. It asks whether you hold the permission for what you are trying to do, so removing a permission from a role takes effect straight away for everyone holding it.

Registration and First Billing Setup

Create an account

Registration collects contractor business information, the first administrator's user information, a password, legal acceptance, and an initial billing package. The first user becomes the default tenant administrator.

LBCAssist registration and billing are available only to U.S.-based customers. Business and billing addresses must be in the United States.

The default administrator can use the business contact info for the admin email, username, first name, and last name.

Select license bundles

Choose at least one paid license. Bundles can be mixed. The selected total becomes the starting paid license pool after Stripe Checkout completes. Trial eligibility applies only up to the configured trial license limit.

Complete Stripe Checkout

Stripe collects and verifies payment information. If a free trial applies, billing starts automatically when the trial ends. If the selected package exceeds the trial limit, paid billing starts immediately.

Complete Stripe Checkout within 7 calendar days after account creation. Until then, only the default administrator can use Billing and My Profile to resume setup; project and other Service workflows remain gated. If LBCAssist issued that administrator a cardless promotional access code, it may instead be redeemed from Billing during this same window. After the window, the tenant is hard terminated, new Checkout and cardless-code redemption are closed, and this setup-expiration rule does not itself start customer-data deletion or purge.

Use a promo code

Enter a Stripe promo code before checkout when one has been provided. These codes can be limited to certain tenants, bundles, dates, or redemption counts, and the billing service confirms eligibility before sending the discount to Stripe. They do not provide cardless access.

Redeem a promotional access code

A cardless promotional access code is a separate, support- or platform-admin-issued grant. Only the default administrator named for the grant can redeem it from Billing while the initial 7-day setup window remains open. It grants temporary promotional access without creating a Stripe Checkout Session, coupon, customer, or payment-method requirement. It cannot be redeemed after tenant termination.

Form Requirements

The guidance beside a field is the current requirement for that kind of value. Read it before submitting: a Team name, a person’s name, a project title, a reason, and a file name intentionally follow different rules. LBCAssist validates again on the server, including when another person changes a record at the same time.

Enter the value you mean

Leading and trailing whitespace is removed where the field permits text. Some title and name fields also normalize ordinary internal spacing. A form shows a clear error instead of silently shortening, substituting, or removing invalid text.

Names are not all the same

Project and diagram titles can use ordinary Unicode text and do not need to be unique. File display names also support ordinary Unicode text, but cannot be paths, control characters, or a name made only of periods. Reason and address-type labels are managed catalog values, so duplicates within your company are refused.

Teams and roles

Team names are 3 to 128 characters, use letters, numbers, hyphens, and underscores, and are unique in your company regardless of capitalization. Role names use their own displayed 2 to 64 character title rule and are also unique within your company without regard to capitalization. A case-only rename of the same Team or Role is allowed.

When the server refuses a value

Correct the value shown in the form and submit again. If a name is already in use, choose another name; do not expect the application to rename it automatically. A server response is final when a current rule or a concurrent change differs from what the page first showed.

Current rules, wherever you work

The same server-owned guidance is shown in the browser and mobile apps. Optional reasons can be left blank where the form says they are optional; when you provide text, follow the field guidance rather than relying on a character counter or a browser to change it for you.

Portal Home

The portal is the hub after sign-in. It shows account-level links, your project list, and a selected-service workspace for the project service you choose.

After a successful sign-in, Home opens at the beginning of the page.

Top links

Company, People, Roles, Teams, Collaborate, Billing, Reports, Audit and Profile appear based on your permissions. Today, My tasks and Running timers appear the same way — see Across projects. Profile and Help are available to every signed-in user.

Role-based navigation

LBCAssist shows the pages and service actions your role, license, tenant settings, and project assignments allow. Server authorization remains the source of truth if access changes while you work.

Workspace navigation

Every signed-in page carries the same workspace navigation bar, including My Profile, project create and edit, and the Time, Mileage, Tasks, Drawings and Reports consoles. Public pages — sign-in, Marketing, Pricing, Help, Guides, Support and the legal documents — do not carry it; each has its own way back. Fast workspace changes remain direct; when a destination needs more than a moment to confirm the existing browser session, LBCAssist shows a brief branded transition instead of a page-local loading state.

Location access

Location prompts help record field activity such as time and mileage. Users can still navigate without location access, but some field entries may need manual/admin override.

Billing setup state

New tenants have 7 calendar days from account creation to complete Stripe setup. During that window the default administrator can reach Billing and My Profile, but the project workspace stays closed. When the window expires, the tenant is hard terminated and Checkout cannot be resumed; this does not itself purge customer data.

Across Projects

Most screens in LBCAssist answer a question about one project. These three answer the same questions the other way round — across every project you are on, in one list.

My tasks

Everything on your plate, across every project you are on. Needs the Tasks access permission; the Tasks manage permission also opens it. If you hold Tasks manage you can widen the list to everyone’s tasks — that changes whose tasks are listed, never which projects. If the page says the project filter has been dropped, you are seeing the whole company because you are the pinned account owner, and every such request is recorded.

Running timers

Time entries that were started and never stopped. Needs the Time access permission. By default it shows only yours; with the Time manage permission it shows everyone’s in the company, and the page says at the top which of the two you are looking at. That matters when the list is empty: “you have none running” and “nobody has one running” are different answers. Each row names its project and, in the company-wide view, the person — a row reads “not named on this row” where no name is available, which happens for a project you are not assigned to. A row also names the job site when the timer was filed against one. If it names no site, the timer was not filed against one — the row simply omits the line rather than claiming the site could not be found.

Today

Tasks, time, billing and people, gathered in one place. Sources are included only when you are allowed to view them.

When the answer is incomplete

Today asks each included source separately, on a short time limit, so one slow service cannot hold the page. A source that times out or fails is listed as such; sources you cannot access are omitted. An empty worklist says “Nothing found”; when a visible source did not answer, its status explains that this is not a complete result. A long list says “showing 20 of 63” rather than quietly showing twenty.

Projects and Project Setup

Project list

The project list shows the projects you are on — the ones you have been assigned to directly, plus the ones assigned to a team you belong to. It is not a list of every project in the company, and the count beside it counts your projects rather than the company’s. If a job you expect is missing, you have not been put on it yet: ask someone with the project assignment permission to add you or your team in the project’s Project assignments section.

Two things do not change this. A manage permission still does not list other people’s projects for you — it decides what you may do on a job, not which jobs you can see — and you can still open a project you are not on if someone sends you a link to it. Its job site addresses are a narrower question: to list them, look one up, or see the ones that have been archived, you need to be on the project, to be able to edit projects, or to hold a manage permission that reaches the whole company. Otherwise the address section reports that it cannot load, which is the same answer it gives for a job that does not exist. The one person who sees the whole company’s list is the account owner, and every time they do, it is written to the audit log.

Active projects are shown by default. Use Reload Projects to refresh and Show archived to include your archived projects. Selecting a project opens project actions, project address selection, and a service switcher for Diagram, Files, Mileage, Tasks, and Time. Choose one service to work in its full-width panel.

Create project

Create Project captures project name, optional description, owner information, property address, property type, owner mailing address, enabled services, file retention override when Files is enabled, and the mileage tracking mode. Address validation uses the active address flow; parcel or tax identifiers are entered manually when needed.

Edit project

Edit Project lets permitted users update project details, owner information, property locations, mailing address, enabled services, Files retention override, legal hold where allowed, mileage tracking mode for future entries, and project assignments. Project assignments let a permitted user add people directly or assign a team; neither choice changes anyone’s role. Projects can also be archived, restored, or deleted. Once your session is confirmed, the Create and Edit pages use the same workspace width as People, so their project settings have the same working area as the rest of the Portal.

Files service setup

When Files is enabled for a project, the project can inherit the tenant document retention setting or use a project-specific retention override up to one year. Legal hold requires the legal hold permission, held explicitly: file management does not confer it, and no role name stands in for it. The retention override asks for file management instead, so the two controls can be available separately. While legal hold is active, file data is retained until the hold is released.

Project assignments

People can be added directly, or a whole team can be assigned to the project. Direct people stay on the project until they are removed; a team member reaches the project while they belong to that team. Access to a service on that project is then three things together: the service is enabled on the project, the person is assigned directly or through a team, and the person's role carries the access permission for that service. The Time, Mileage and Tasks manage permissions are the exception to the middle one — see below.

Users are no longer assigned service by service, so two people holding the same role on the same project have the same access to it. If two people should differ, give them different roles — that is what roles are for, and it applies everywhere they work rather than on one project at a time.

A management permission — time, mileage or task management — is company-wide. Its holder acts on that service on every project in your company, assigned to it or not: reading, correcting and deleting other people's records on jobs they have never been put on. Assigning them to a project is not what grants it, and unassigning them does not take it away. The matching access permission is the project-scoped one, and it is the one this page's assignment list governs.

Two limits still hold for a management permission. It stops at your company, so it never reaches another company's projects. And it never opens a service this project has switched off — that switch is a project setting and no permission overrides it.

The account owner — the tenant's default administrator — is separate and goes further: they can see and manage every project regardless of which permissions they hold, and every project is listed for them. It cannot be granted to anyone else, it follows the default administrator if you transfer it, and every access that succeeds only because of it appears in the audit log.

The project page has a Project access section that lists people who can reach the project and whether their assignment is direct or through a team. It is not the whole answer to “why can they see this?” — anyone holding time, mileage or task management reaches the matching service here without appearing on that list.

Teams

A team is a named set of people you can put on a project in one go, managed at Teams with the manage teams permission. It is a shortcut for where people work, nothing more: a team carries no permissions of its own, so putting somebody on a project through a team gives them exactly the access their own role already allows there.

Create a team, rename it, and add or remove people on the Teams page. A team name must be 3 to 128 characters long, start and end with a letter or number, and use only letters, numbers, hyphens, and underscores. Names are unique within your company regardless of capitalization, so you cannot create both “Field-Team” and “field-team”. Leading and trailing whitespace is removed before a valid name is stored; spaces and other invalid punctuation are not silently changed for you. Both Create and Rename forms show these rules and a clear validation result; the server remains the final authority.

The permission to manage teams controls the team’s name, membership, and deletion. The separate permission to assign people to projects controls putting a team on a project or taking it off. This separation lets a project manager staff a job without being able to change the company’s team roster.

Membership is worked out live rather than copied onto each project. Add somebody to a team and they reach that team's projects immediately, including on a session they already have open; remove them and the access goes the same way. Nothing is written per project, so nothing can fall out of step.

A team that is assigned to a project cannot be deleted. The refusal names how many projects are holding it and which, so the way out is to unassign it and then delete — the projects themselves are not affected. Teams stay inside your company; subcontractors are separate companies and are given work as subprojects through Collaborate.

Roles

A role is a named list of things a person is allowed to do anywhere in your company. Your company starts with five — Field, Project Lead, Office, Admin and Subcontractor — and they belong to you: you can rename any of them and change what each one may do. You cannot add a sixth role or remove one of the five.

Roles is where that happens, and it needs the manage roles permission. Managing people and deciding what a role may do are separate powers, so someone who can add users does not automatically get to change what a role is allowed to do. The page lists each role, how many people hold it, and what it may do. From there you can rename a role, tick or untick its permissions, and put a person on a role.

Role names follow their own displayed rule: 2 to 64 normalized Unicode title characters. Names must be unique within your company regardless of capitalization, but changing only the capitalization of the same role is allowed. The role form shows a validation message rather than silently truncating or changing a name.

A person can be on at most one role. Putting somebody on a role is what switches them over to it: from then on the role decides what they may do, and the per-person permission tick-boxes on the People page are no longer what is consulted for them. Somebody who has not been put on a role is still governed by the permissions on their own record on the People page. The account owner is placed on the built-in Admin role when the company account is created.

Changes take effect immediately, including for people who are already signed in. Take a permission off a role and everyone on that role loses it on their next action, without having to sign out and back in.

You cannot hand out more than you hold

You can only grant permissions you hold yourself. Anything you do not hold is shown greyed out with the reason, rather than letting you tick it and refusing afterwards. The same limit applies when you put somebody on a role: you cannot move a person onto a role that carries more than you hold.

You cannot lock yourself out

You cannot remove the manage roles permission from your own role, and the built-in Admin role always keeps it — otherwise nobody would be able to edit a role again. On the page it stays ticked and visible rather than hidden, because it is still in force.

Refusals name the cause

When a change is refused, the page marks the exact permissions that caused it. You are allowed to manage roles; it is that specific change that cannot happen.

Manage can be company-wide, access never is

For Time, Mileage and Tasks, ticking access scopes the person to the projects they are assigned to, and nothing widens that. Ticking manage reaches as far as the role is set to: every project in your company, assigned or not, which is where every role starts — or only the projects its members are on, if you have narrowed it. The Roles page marks which is which next to each tick. See Access, Roles, Permissions, and Licenses for the full rule.

Some permissions come as a set

Granting a broader permission grants the narrower ones inside it. Giving a role file management, for example, also gives it view, download, upload, edit and delete. Legal hold is the exception: it is a separate compliance control and is never included automatically.

Project Diagrams

Project Diagrams opens in project context at a diagram library. Each saved diagram has an Open action; people allowed to create diagrams can make a separate working copy; and a person with diagram management can permanently delete a diagram after an explicit, irreversible-delete confirmation. The library refreshes after a copy or deletion.

Opening a diagram uses a full-window editor with the same color preference, navigation, and responsive workspace width as the rest of the browser. Save and Close are the only editor exit actions. A changed diagram autosaves every minute; Close asks whether to discard unsaved work. Rename saves the new name, while Cancel restores the name that was there before editing.

The editor toolbar groups construction shapes, drawing actions, canvas-size choices, view/zoom controls, history, and export. Select a shape or note, then click the canvas to place it. The canvas scrolls in both directions and starts at a standard 1600 × 1000 working size; smaller and larger presets are available. A mouse wheel or trackpad scrolls the canvas. Hold Ctrl or while over the canvas to zoom it and its contents.

The editor keeps the most recent ten actions available for Undo and Redo. It also has keyboard shortcuts: arrow keys nudge the selected object, Enter renames it, Delete removes it, Esc clears the selection, +, and 0 control zoom, and the usual save and undo chords apply. Press ? for the full list. Shortcuts are ignored while you are typing in a field.

A project can hold as many diagrams as you need. Each one has its own name and its own owner — the person who created it — and the owner is shown in the editor. Use New diagram to start another and Rename to retitle one. The owner never changes: editing somebody else's diagram does not make it yours.

Labels and descriptions on the objects inside a diagram have their own displayed rules: notes may use a longer label than shapes and connectors, while descriptions are optional. Save checks every changed object against those current rules rather than silently shortening a drawing.

The buttons you see are the ones you may actually use, and that is decided for each diagram separately rather than once for the project. Delete and Rename are not shown at all when they are not yours to use, and Save is unavailable on a diagram you may open but not change. Deleting always asks you to confirm, and the confirmation names the diagram, because a project now has more than one.

What a person can do with diagrams Who has it by default
Open the diagrams on a project and work with them on screen Field, Project Lead, Office, Admin and Subcontractor
Start a new diagram Field, Office, Admin
Change or rename their own diagram Field, Office, Admin
Change, rename, or delete anyone's diagram, including their own Admin, and Project Lead on its own projects

Two things about that table are deliberate and worth knowing before someone reports them as a bug. Deleting a diagram needs the permission to manage everyone’s diagrams, so a person who drew a diagram cannot delete it themselves unless they hold that — removing work is treated as the destructive act regardless of who made it. And changing somebody else's diagram is that same permission, so a person who can edit their own work is not automatically able to edit a colleague's.

Those defaults are the ones your company starts with. Any of them can be moved between roles on the Roles page.

Each drawing is stored privately and separately from the list it appears in, and stays walled off from other companies, so opening a project's list of diagrams does not have to load every drawing on it. The customer-data export on the company page includes each diagram as its own file, named for the diagram rather than the project.

Diagrams can be exported to Project Files as PNG files for the selected project address. The export uses the normal Project Files scan-and-store flow before the file is available to web and mobile clients.

Time Assistant

Current session

Choose a start reason and start time tracking for the selected project. Open sessions appear until they are stopped. Closed entries show in the entry history.

Manual entries

Users granted time:manage can open Manual entry from the project Time Assistant to create, edit, or remove entries for people assigned to that project. The server enforces the permission and assignment checks and records manual/admin override metadata when location or device capture was not available.

Time reasons

Tenant managers with time permissions can add tenant-specific reasons and mark time reasons as billable or non-billable. Default reasons can be disabled or re-enabled.

Mileage Assistant

Mileage Assistant tracks project travel. The project controls whether new mileage activity is tracked per segment or per trip. Existing entries keep the mode they were created with.

Per segment

Users start a trip and later end it. The entry stores start and stop time, locations, reason, and distance when available.

Per trip

The system can update location during the trip and close when the user returns to the start area, or the user can end the trip manually.

Manual/admin entries

Users granted mileage:manage can open Manual entry from the project Mileage Assistant to create, edit, or remove entries for people assigned to that project. The server enforces the permission and assignment checks, and records manual/admin override metadata for entered times and addresses. Force close support remains available when appropriate.

Task Assistant

Task Assistant supports individual task views and management views for users with task management permission.

My Task View

Filter by start date, due date, and status. Task statuses include open, in progress, blocked, question, closed, not closed, and all.

Manage Tasks

Managers can create, update, assign, clear, reload, and page through project tasks. Tasks can be assigned to all assigned users or a specific assignee.

Comments and questions

Task rows support comments, questions, answers, edited note history, question assignee changes, and question withdrawal where allowed.

Files

Files are stored in project address context. The Files tab shows documents for the selected project and address, and the available actions depend on being assigned to the project and on the file permissions the user's role carries. Opening Files from a project rechecks the signed-in user’s current project access; the project in the browser address only selects the starting context and never grants access by itself.

Upload and scan

Upload uses the browser drop zone, Choose file button, or mobile device file picker, camera, photo library, or document picker. The normal upload limit is 100 MB per file. Platform service administrators can adjust tenant and project upload ceilings up or down when support approves a different limit. Files are isolated, validated, and scanned for security issues before they are stored with the project. Browser and mobile uploads show pending, successful, or failed confirmation from the server.

Diagram PNG exports use the same Project Files upload, validation, scanning, storage, and replacement controls as manually uploaded files.

View, edit, and download

View, download, edit, and delete are controlled by separate permissions. Supported files include common project documents such as PDF, Word, Excel, Draw.io, PNG, GIF, and JPG where the browser or mobile device can open them.

Retention and legal hold

Tenant document retention defaults to 180 days and is managed from Tenant. Projects can override the setting up to one year when Files is enabled. Legal hold keeps scoped file data until the hold is released; release schedules deletion of the held file data on the next daily purge. A legal-hold reason is optional; if you enter one, the current multi-line guidance beside the field explains what is accepted.

Collaborate: working with other companies

Collaborate is where work between your company and another company happens. It replaces the old Subcontractors page; the old address still works and takes you to Collaborate.

Companies can connect only through an invite and acceptance workflow. One company creates a one-time connection code, the other redeems it, and the company that issued the code reviews and accepts before the relationship becomes active. Both sides' acceptance is recorded, with who accepted on each side.

There is no separate document to read at this point. The subcontractor collaboration terms are part of the Terms and Conditions everyone in your company already accepted when they signed up, and you are asked to accept them again whenever they change.

What you are asked at the moment of connecting is different, and short: tick a box confirming you have authority to create the connection on behalf of your company. That confirmation is recorded with your name and the time.

The relationship itself is even-handed: it is recorded between two companies rather than as owner and subcontractor, and who is which is decided for each piece of work. The same connected company can therefore be your subcontractor on one job and the company sending you work on another, so Collaborate shows both directions and every row says which way it runs.

When assigning work, select one or more listed service scopes and follow the field guidance for the work title and optional scope summary. Relationship-close and workflow-rejection reasons, exchange subjects, and exchange messages each use their own current guidance; the browser does not silently shorten any of them.

Page What it is for
Collaborate The hub: what needs a decision from you, work you sent out, work sent to you, the companies you are connected to, and the form for sending a piece of work to a company.
Connect a company Share a connection code, see what you are waiting on, redeem a code somebody sent you, and read, accept or reject a proposal. Previewing a code tells you which company it belongs to before you redeem it, and every code you have shared and not yet had redeemed can be revoked.
Company page One connected company: the relationship, contacts, all the work running between you, and closing the relationship.
Work page One piece of work sent to or received from a company: where it has got to, its scope, what was reported, and its document exchanges.
Exchange page The conversation on one exchange: the documents, the thread, their scan state, and your reply.

The pages you can open and the sections inside them depend on your permissions. A section you may not read is replaced by a short sentence naming the permission you would need, rather than taking the whole page down or disappearing without explanation. It names a permission and not a role, because roles can be renamed and it is the permission that decided.

Connecting and disconnecting

People whose role carries the relationship permissions can create connection codes, redeem one, accept or deny a proposal, and close an active relationship. Answering an invitation and forming one are separate permissions: a company can be given the ability to accept incoming work without being given the ability to go out and connect to others. Invites, decisions, closures, and closures forced by LBCAssist support are written to both companies' audit logs.

Sending work out

You send a connected company a piece of work at one of your project's addresses. Their people stay inside their own company account throughout; they never become users on your project and never see the rest of it. The work names which services it covers, and a service that is not part of it is shown on the page marked as out of scope rather than quietly left off.

Document exchanges

Documents are reviewed through a send-back, question, response, and acceptance thread. Web and mobile can both submit and download exchange documents. A document has to finish security scanning and be stored before the review and acceptance controls turn on, so a fresh upload may be briefly unavailable.

Finishing

Both companies have to accept that a piece of work is complete. Anything done afterwards is allowed only with a closed-status banner showing, and is recorded in the audit log against the state the relationship was in at the time.

Reports

Reports are tenant-scoped and use the filters shown for the selected report type. Results can be viewed in the browser or exported as CSV, XLS, or PDF. Time reports honor the tenant report-time setting on Tenant: actual time, or rounded up/down to the nearest 15 minutes, 30 minutes, or hour. Time totals display as hours and minutes, such as 2h2m.

Report family Examples
Time Time by user/project, time by user/date range, total time, billable/non-billable project hours.
Mileage Total mileage by project, mileage by reason, and close-mode filtering.
Tasks Tasks by project, task note edits, task questions and answers.
Files Uploads, opens, downloads, edits, deletes, scan verdicts, retention changes, and legal hold activity.
Notifications Push notification coverage, enabled categories, devices, and latest delivery outcomes.
Billing invoices Stripe invoice lines for full-month charges, partial periods, prorations, credits, and upcoming previews.

Company Management

The Company page changes tenant-level settings. Treat these options carefully because they affect everyone in the company account.

Company settings are grouped on one page as Business, Security, Data & retention, Lists, and Ownership & closure. Each group keeps its current settings and controls together; direct Company links remain available when you have a saved destination.

Tenant option Impact
Contractor business Changes the tenant business name shown across the portal and reports.
Business information Updates contact number, primary email, website, license number, insurance provider, policy provider, and licensee name.
Audit log retention Controls how long tenant audit log entries are retained, within the allowed range.
Document retention Sets the tenant default for project file retention. The default is 180 days, and the maximum is one year.
Reports Controls how worker time is rounded in reports: actual, round up, or round down to 15 minutes, 30 minutes, or one hour.
Tenant MFA policy Sets multi-factor authentication as optional, required, or disabled for the tenant. Disabled mode bypasses configured user factors until the policy changes again.
Session timeouts Sets web idle timeout, web max session length, mobile access-token lifetime, and mobile refresh-token lifetime.
Password policy Controls minimum length, expiration, history reuse, complexity, and lockout attempt count. A new tenant starts at a minimum length of 8 characters and an expiry of 365 days. Those are the permissive ends of what the setting allows — 8 is the shortest length and 365 the longest expiry the field accepts — and they are a starting point, not a recommendation. We recommend raising the minimum length, shortening the expiry, and requiring multi-factor authentication for your tenant. Length does more for you than rotation does; a longer minimum with MFA required is stronger than a short password changed often. You choose these settings, and you are responsible for choosing ones that meet the legal, regulatory, contractual, and insurance obligations that apply to your business — see the responsibilities set out in the Terms and Conditions. LBCAssist does not assess, advise on, or warrant whether any configuration satisfies those obligations.
Tenant termination Default-admin-only request that keeps service active through the current billing period, then starts suspension, termination, and purge processing, including file data unless legal hold applies.
Customer data export Default-admin-only ZIP export of tenant-scoped persisted service data, including available project files, with security secrets redacted and unsafe or unscannable files omitted or represented by metadata.
Time reasons Adds, edits, enables, or disables tenant time reasons. Default reasons can be disabled or re-enabled but not edited or deleted.
Mileage reasons Adds, edits, enables, or disables tenant mileage reasons. Default reasons can be disabled or re-enabled but not edited or deleted.
Tenant default administrator Shows who currently holds the company account — the account owner — and is where that is handed to somebody else. This user keeps the required first paid license. See The account owner below.

The account owner

One member of your company holds the company account itself. They are shown on the Company page as the tenant default administrator, and three things belong to them alone: exporting the company’s data, closing the company account, and reaching every project whether or not they are assigned to it. They always keep one paid license, and they cannot be archived — though they can be locked, which is the reversible thing to do if their account is ever compromised.

What sets the account owner apart is not how far they reach. Reaching every project is common — it is a setting on a role, and both of the roles your company starts with that manage other people’s work, the one called Office and the built-in administrator role, start set to every project. If you believed the account owner was the only person who could see a job they are not on, read Access, Roles, Permissions, and Licenses. What is different is that the account owner cannot be granted. There is no permission for it, nothing on Roles confers it, and no administrator, however broadly permitted, can hand it to themselves. When it is used to open a project the holder is not assigned to, that is recorded in the audit log separately from an ordinary role reaching across projects, so reading the log back never confuses the two.

Moving the account owner to somebody else

The account owner can be handed to another member of your company. This is what you use when the founding account has been compromised, or when the person who registered the company has left it.

You do it on the Company page, on the Tenant default administrator card. Choose the member who is to receive it, tick the acknowledgement, and type that member’s username to confirm. The control is only shown to the person who currently holds it.

Only that person can move it, and only from a session that signed in in the last few minutes. That is deliberate on both counts. There is no permission that lets an administrator do it on the owner’s behalf, because any permission can be given away through a role, and ownership that can be given away through a role is not ownership. And requiring a recent sign-in means a session someone walked away from cannot be used to sign the company over. If your session is older than that the handover is refused and says so: sign out, sign back in, and do it straight away.

The person receiving it has to be:

  • a member of your own company — never somebody at a company you collaborate with;
  • somebody other than the current owner;
  • active, meaning neither locked nor archived. Handing the account to somebody who cannot sign in would strand the company, and only the new owner would be able to hand it back.

The handover gives the incoming owner a license and puts them on your company’s built-in administrator role, so they can act the moment it finishes. If your company has no license free, the transfer is refused rather than left half done. It is recorded in the audit log, naming both people and the role the new owner came from.

What moving it does not do

Read this before you use it, because the outgoing owner is left almost exactly as they were. That is intentional — handing over the company account is not a demotion, and you may well want the previous owner to carry on administering.

  • Nobody is signed out. No session ends on either side. Both people simply get the new answer on their next action, with no signing out and back in.
  • The outgoing owner keeps their role and their permissions. They are not moved off the administrator role and they lose no access. If you want them to have less, change that separately afterwards — see User Management and Roles.
  • The outgoing owner becomes lockable, archivable and demotable like anybody else. That is the whole point when an account has been compromised or its holder has left: the transfer is the step that has to happen before you can lock or archive them, and doing so is usually the very next thing you will want to do.

Billing and License Management

License pool

Billing shows paid licenses, assigned licenses, available licenses, monthly package amount, current billing status, and pending package changes.

Billing changes require U.S. customer eligibility and a U.S. billing address.

For an initial self-service setup, only the default administrator can resume Checkout during the first 7 calendar days after account creation. That administrator may also redeem an issued cardless promotional access code during the same window. Completion activates the trial, paid subscription, or temporary promotional access; expiry hard terminates the tenant and closes both recovery paths without starting a setup-specific deletion or purge.

Package changes

Added licenses are sent to Stripe for immediate prorated billing. Reductions are scheduled for the next billing cycle and do not create credits or refunds. The tenant cannot reduce below one paid license.

Promo codes

Stripe promo codes can discount eligible bundles for a fixed number of months, one invoice, or indefinitely. Codes are checked by tenant and package before Stripe receives them, and usage is reflected in billing audit history, monitoring, and invoice reporting where Stripe supplies discount details. They are distinct from cardless promotional access codes.

Cardless promotional access codes

An issued cardless access code may be redeemed only by the tenant default administrator during the unexpired initial setup window. Billing checks the grant's exact-email eligibility, redemption limit, validity, and access duration before it grants temporary promotional access. A terminated tenant cannot use a code to regain access.

Reducing licenses

If assigned users exceed the paid license count when a reduction takes effect, LBCAssist unassigns newest non-default-administrator license assignments first until assigned users fit the paid pool.

Payment method

The Update payment method button opens Stripe Billing Portal. Stripe handles card entry, required verification, invoices, and payment-method storage. LBCAssist does not store full card numbers, expiration dates, or CVV/CVC values.

Mobile clients open payment-method, subscription, paid-license, and checkout changes in the device system browser through a short-lived LBCAssist handoff. Store-distributed mobile builds show those purchase links only when the applicable App Store or Google Play rules allow them.

User Management

Users with user management permission can create users, assign licenses, set permissions, resend welcome email, create a one-time password when needed, lock or archive users, delete passkeys, and delete eligible users.

User option What it does
Assign license from pool Lets the user sign in if billing is active and a paid license is available.
Welcome email Sends a secure setup link so the new user confirms their email address, accepts current legal terms, and sets their own password.
Email confirmed Shows whether the user completed secure setup. Unconfirmed users cannot sign in until the welcome link is accepted.
Resend welcome Rotates the setup token and sends a fresh confirmation link when the prior welcome email expired or was lost.
One-time password Creates a temporary password the admin can send out-of-band. The user must still confirm email and must change that password at login.
Permissions Controls access to projects, people, roles, teams, audit logs, reports, company settings, billing, time, mileage, tasks, diagrams, working with other companies, and file actions including legal hold. These tick-boxes apply to a person who has not been put on a role. Once somebody is on a role, their role decides — change it on Roles instead.
Lock User Prevents sign-in without deleting the user record.
Archive User Hides the user from normal lists and removes them from day-to-day selection surfaces.
Require password reset Forces the user through password reset at next sign-in.
Delete passkeys Removes saved passkeys for that user so they must sign in by password or register a new passkey.
Delete User Removes eligible non-protected users. The current user and default admin are protected from unsafe deletion.

My Profile

Display mode

Choose Light, Dark, or System. System follows your device setting and changes with it. Your choice is saved to your account, so it applies on every browser you sign in to. The iOS and Android apps keep their own display setting and are not affected by this.

Multi-factor authentication

Add named authenticator-app or email-code factors, choose a default, and enable, disable, rename, or delete factors from My Profile. If tenant MFA is required, the server keeps at least one enabled default factor before normal web or mobile service access is enabled.

Task notifications

Configure push notification windows, event categories, task management notifications, project scope, and registered device cleanup.

Passkeys

Add or remove passkeys for passwordless sign-in.

Product feedback

Use Product feedback to send a short suggestion or product issue. Keep passwords, access tokens, payment data, files, and urgent support or account requests out of feedback; use Support for those. Your text is sent only after you select Send and is not stored in browser storage. Mobile apps use the same server-owned limits and their encrypted, bounded retry queue when that protocol is available.

Password

Change your password. The tenant password policy controls the allowed new password.

Mobile Access

Mobile clients are first-class LBCAssist clients. Every area available in the browser is reachable from the phone when a user has the required permission, including projects, time, mileage, tasks, files, diagrams, reports, audit logs, users, teams, roles and permissions, account administration, notifications, and subcontractor collaboration. Some of those areas open in the device browser, already signed in, rather than as a screen inside the app; that changes where the page is shown, not whether you can reach it.

Today

The phone opens on Today, which gathers what needs your attention across tasks, time, billing, and people. Each area is asked separately, so a slow or unavailable one never blanks the screen. Today always lists every area and says what happened to it: an area you do not have permission for names the permission it needs, and one that did not answer is shown as such. An empty Today means your day is clear only when every area answered, and it says so.

Teams and roles

Managing crews and editing what a role may do are native screens inside the app. Each control follows its own permission rather than the screen as a whole: someone who can staff a project sees the team list and can put a team on a project without being able to create or rename teams, and someone who manages people can read the roles list, which is what assigning a role needs, without being able to change what a role may do. Teams and Roles do not use a browser handoff as a fallback. The app shows the same current field guidance as the web form for each supported native write; an unavailable field rule disables only that write until it can be refreshed.

Registration

First-time registration opens the LBCAssist registration site in the device default browser. On iOS, an opaque, short-lived Universal Link state can securely complete the existing registration exchange. On Android, the App Link return is navigation only and the user signs in through the normal mobile login flow.

Offline field work

Supported mobile field-work screens can show a bounded protected cache and queue eligible time, mileage, task, file, or diagram changes while disconnected. A queued action is pending until the server accepts it. When the device reconnects, current access and server state are rechecked; revoked access, deletion, or a forced or administrative closure overrides stale device changes. Billing, security, tenant administration, legal, and irreversible actions require an online connection. Team and role changes are in that group: setting a team's members, putting a team on a project, and every role change replace what was there rather than adding to it, so a change made offline and sent later could quietly undo somebody else's. The team list can be read while disconnected; the roles list cannot, because it shows how many people each role affects and which permissions you are able to grant, and both have to be current to be safe to act on.

Billing changes

Subscription, license-count purchase, payment-method, and checkout changes open the LBCAssist website or Stripe-hosted flow in the system browser. The mobile app should follow the server-reported purchase-link policy for iOS, Android, enterprise, direct, and web distribution.

Working with other companies

Where your permissions allow it, you can see between-company action items on the phone, respond to proposals and completion actions, exchange messages, and upload or download scanned exchange documents. In the web portal these workflows live under Collaborate, not on the company page. Opening this area from the phone signs you into the same place.

Voice assistants

Future Siri and Google Assistant integrations must use the same mobile session, permissions, legal acceptance, billing status, tenant boundary, audit, and notification rules as in-app actions.

Monitoring

Administrators can review service health and operational metrics after the monitoring stack is enabled in the production portal. Monitoring covers service availability, API request volume, response times, browser and mobile sessions, mobile web handoffs, projects, addresses, license counts, subcontractor exchange health, questions, comments, and other key usage counts.

Prometheus

Prometheus is the detailed metrics view for service health, request rates, errors, pods, CPU, memory, and storage. Production retains 14 days of metrics.

Grafana

Grafana presents platform dashboards for the Cave2AI cluster — platform overview, capacity and right-sizing, scaling and replicas, node and disk, and mesh and ingress — alongside the LBCAssist tenant views for services and APIs, tenant and user activity, billing and licensing, project files, subcontractor collaboration, dependencies, and the mobile platform.

Alerts

Alerting is designed to notify the service owner when pods, endpoints, database-backed services, CPU, memory, disk, or error-rate conditions need attention.

Audit Logs

Audit Logs show tenant activity history for users with audit viewing permission. Filters include date range, user, log entry type, project, entry type, service, and admin override status. Use audit logs to review changes, troubleshooting history, file opens/downloads/edits/uploads/deletes, scan verdicts, retention changes, legal hold changes, billing/license events, and administrative actions.

Project staffing is recorded there too. Assigning people to a project and assigning a team to a project are both logged, because either one grants access to that project across every service — and a team assignment grants it to everyone on the team, including anyone added to it later. Each entry names the project and how many were assigned.

Open Source Notices

This customer-facing notice is intentionally limited to reviewed component names, applicable licenses, and any required public note. It does not publish implementation, service-scope, or deployment details.

Component License Notes
ClamAV GPL-2.0
YARA BSD-3-Clause
Oracle Linux Oracle Linux open-source package licenses
Grafana OSS AGPL-3.0
U.S. Census Bureau Data API and Geocoding Services Census API Terms of Service Note: This product uses the Census Bureau Data API but is not endorsed or certified by the Census Bureau.

The OSS attribution and license inventory is reviewed as part of the release process. When a reviewed component changes, this help notice and the legal references are updated together before production promotion. Public machine-readable artifacts are available at /legal/open-source.json and /legal/sbom.cdx.json.

Troubleshooting

I cannot sign in

Check username/email and password, confirm the account is not locked or archived, confirm a license is assigned, and confirm tenant billing is active, trialing, or otherwise allowed.

I was sent back to sign in

If a saved page such as Reports is refreshed after the browser session expires, the portal returns to the sign-in page and shows that the session ended. Sign in again before continuing work.

A service button is missing

The service may be disabled on the project, you may not be assigned to it, or your user may not have the required permission.

An uploaded file is not visible

The file may still be scanning, may have failed scanning, may be over the allowed upload limit, or your user may not have view permission for Files on that project. Files that fail validation or scanning are not added to the project.

Stripe checkout or billing portal does not open

Reload Billing and try again. If the tenant is still in setup state, finish checkout from Billing. If a payment method needs verification, Stripe will prompt for it in Checkout or Billing Portal.

Time or mileage location is wrong

Confirm browser or mobile location permissions. A user with the relevant manage permission can correct entries with manual/admin override where business rules allow it.