Skip to content

Roles & permissions

Detailed breakdown of roles, hierarchy levels, and granular permissions.

Three roles with hierarchical access control. Users can only manage team members with lower privilege levels.

Role Comparison

CapabilityOwnerEditorAuditor
View dashboardYesYesNo
View invoicesYesYesYes
Create/edit/delete invoicesYesYesNo
Export invoicesYesYesYes
Download attachmentsYesYesYes
Upload attachmentsYesYesNo
Connect emailYesYesNo
Trigger scansYesYesNo
View scan historyYesYesNo
View reconciliationsYesYesYes
Manage reconciliationsYesYesNo
Access analyticsYesYesNo
Manage settings (Company)YesYesNo
Manage settings (Email)YesYesNo
Manage settings (Categories)YesYesNo
Manage settings (AI Rules)YesYesNo
Manage membersYesNoNo
Manage billingYesNoNo
Access affiliate programYesYesYes
Delete accountPrimary owner onlyNoNo

Granular Permissions

Owners can grant specific admin capabilities to Editors through granular permissions:

PermissionDescription
roles.manageChange team member roles
billing.manageView and manage subscription
settings.manageModify account settings
members.manageAdd and remove team members
invites.manageSend and revoke invitations

Owner

Full access to every feature in the workspace. Best for founders and senior finance managers. Owners control invoices, all settings tabs, billing, and team management.

Editor

Full operational access to the day-to-day workflow. Editors can use the dashboard, manage invoices, run reconciliations, view analytics, and configure workspace settings (Company, Email, Categories, and AI Rules). Editors cannot manage billing or team members unless granted specific granular permissions.

Auditor

Read-only access designed for external reviewers. Auditors can view and export invoices and reconciliations, and access the affiliate program. They cannot see the dashboard, analytics, email connections, settings, or billing.

Safe for external accountants, auditors, and compliance reviewers.

Best Practices

  • Start new members as Auditors, promote to Editor when they need operational access
  • Reserve Owner for executives and senior finance leaders
  • Remove former employees promptly and adjust roles as responsibilities change