Custom roles and groups
See exactly what each role can do in the permission matrix, build your own roles, and give groups of people a role and the locations they look after.
In the app:Roles & groups
On this page
Every member has one role, and the role decides what they can do. Settings → Roles & groups shows the full picture in one table, the permission matrix: one row per permission, one column per role.
The five built-in roles (Owner, Admin, Finance, Analyst and Viewer) are fixed. On the Business plan, owners and admins can also make custom roles and groups.
Read the permission matrix
Permissions are grouped by area: bills and payments; inventory, people and findings; contracts and accounting; cloud and AI spend; reports; and your organization. A tick means the role includes the permission.
Two things hold for every role:
- Everyone sees the bills, inventory, findings and reports in their part of the company, and can export them. Permissions decide what people can change.
- Members, roles and groups and Plan and billing stay with owners and admins. A custom role can't include them, so nobody can give themselves more access.
Make a custom role
- Go to Settings → Roles & groups and select New role.
- Give it a name, such as "Store manager", and a short description.
- Under Start from, pick the built-in role closest to what you need. Its permissions are ticked for you.
- Tick or untick permissions, then select Create role.
To give someone the role, go to Settings → Members & invitations and pick it in their Role column, or choose it when you invite them. Their access changes the next time they open a page.
To change a role later, select its name at the top of the matrix. Deleting a role turns the people who hold it into Viewers.
Note: An owner always holds the Owner role. To give an owner a custom role, make someone else an owner first.
Make a group
A group gives everyone in it the same role, and can limit that role to some locations. For example, a "Store managers" group with an analyst-style role, limited to the stores.
- Under Groups, select New group.
- Name it, pick the role it gives (Finance, Analyst, Viewer or one of your custom roles) and, if you have locations, tick the ones it covers. Leave them all unticked for the whole company.
- Tick the people in the group, then select Create group.
Select a group in the list to change it or delete it. Groups can also be approvers in your approval flow, so a step can wait for "anyone in Store managers".
How a person's access adds up
A person gets everything their own role allows plus everything each of their groups allows.
What they see follows the widest access they have: if their own role or any of their groups covers the whole company, they see the whole company. Adding someone to a group never takes access away.
Tip: To keep someone to a group's locations, also limit them in the Sees column under Settings → Members & invitations. Otherwise their own role, which covers the whole company, wins. Sees the whole company is a permission of its own (Owner, Admin and Finance have it), and a role with it is never limited to locations.