All guides▾
Users, Roles & Permissions
How to invite teammates and control what each of them can see and do with Roles and Permissions.
Every account has more than one person working in it — and not everyone should be able to do everything. This is where you invite your teammates and decide what each of them is allowed to see and change.
What this does for you
- Users are the people you invite into your organization.
- Roles are named permission sets (like "Admin" or "Finance") you assign to a user — the role determines what that person can view and change.
- Permissions are the individual capabilities (view invoices, create plans, edit users, and so on) bundled into a role.
Who can use it
Managing users and roles is an admin function. You'll only see "+ Add user," role management, and the ability to suspend or reassign people if your role includes the relevant permission — user.view/user.create/user.edit for users, role.view/role.create/role.edit for roles. The organisation owner is automatically given a full-access Admin role, so there's always at least one person who can invite others and set things up.
Where to find it
Go to Settings → Users & Roles, which expands into three pages: User management, Roles, and Permissions.
How to use it
Inviting a teammate
- Go to User management and click + Add user.
- Fill in the details in the Create user panel — exact fields depend on how your organization has configured this record type, but typically include name, email, and a role assignment. Once a user is Active (or their invite hasn't been sent), their email locks from further edits.
- Click Create — the person receives an invitation email and shows as Invite sent until they accept.
Editing or suspending a user
Click Edit on a user's row, or use the row action to Suspend/Unsuspend them (hidden on your own row). Confirm in the dialog — a suspended user keeps their account but loses access to this organization until reactivated.
Resending an invitation
Use the row action Resend invitation on a user with Invite sent status, then confirm. This also happens automatically whenever you change a user's email on an existing invite.
Creating a role
- Go to Roles and click + Add role.
- Enter a Role Name (2–50 characters) and optional Description (up to 500 characters); leave Active checked to use it right away.
- In the permissions picker, use Search objects or features to find a module, then check individual permissions — or use a module's All permissions checkbox to grant everything in that module at once.
- Click Publish to save the new role.
Editing or deleting a role
Click a role in the Roles list to edit its name, description, status, or permissions — the save button here reads Update, not Publish. To delete, confirm ("Delete Role"); if people are currently assigned, you'll first pick a Reassign to role, then confirm ("Reassign & delete") to move everyone over and delete the old role in one step.
Viewing available permissions
Go to Permissions to browse the full catalog (name, description, category, and how many roles include it). This page is entirely view-only, and unlike most of the app, it has no permission gate on viewing it at all.
Tips / things to know
- A role's permissions apply per organization — someone in more than one organization can hold a different role (or none) in each.
- Suspending a user is reversible and doesn't delete their account or history.
- Deleting a role never leaves anyone without access — a replacement role is required first if the role still has people on it.
- There's currently no interface for creating or managing Teams (grouping users, team hierarchy), even though users can belong to teams behind the scenes.
- The Permissions page is read-only — you can browse what exists but can't create, edit, or remove permissions there.
- "Designation" and similar profile-style fields on a user are simple text labels your organization sets, not tied to a managed list you configure in the interface.