Documentation

Users, roles and permissions

Invite team members and apply least-privilege access consistently across departments.

Updated 5 min read

Give each person the access their work requires

Roles should describe responsibilities rather than individual people. Create stable roles for common responsibilities, then assign users to the smallest appropriate set.

Invite and review users

  • Use a verified business email address.
  • Choose the correct workspace and role.
  • Review pending invitations and remove expired ones.
  • Revoke access promptly when responsibilities change.

Protect sensitive actions

Restrict user administration, refunds, exports, payroll, financial close and configuration changes. Test permissions before assigning a role widely and review administrator access every month.

Was this guide useful?For more help, our support team is ready.
Get support →