Team permissions
Invite your team, keep control of the money
Invite the people who write invoices, the person who does the books and the partner who runs the business, and give each of them exactly the reach their job needs. Four roles, no custom permission matrix to maintain.
The problem
Sharing one login is how mistakes stop having a name
When the whole team uses the owner's account, anyone can void an invoice, change the bank details or invite a stranger, and nobody can say who did. Separate accounts with sensible roles cost nothing and answer the question before it is asked.
Step by step
How it works, in three steps
Invite by email
Choose a role, send the invitation, resend or revoke it. A shareable accept link exists for the owner or admin who prefers it.
They sign in their own way
Password, an emailed login code, or a passkey, with two-factor authentication available to everyone.
Work within the role
Staff write and send; the accountant records money; owners and admins change settings and manage the team.
Roles
Four roles that match how a small business actually works
Staff create and edit customers, items and invoices and send them, but cannot record a payment, apply a credit, delete, void or write off. The Accountant can do all of those money actions. Owners and Admins additionally manage settings, gateways, branding and the team, and only an Owner can hand the workspace to someone else.
- Staff: create, edit and send, never move money
- Accountant: everything Staff can, plus recording and adjusting payments
- Owner and Admin: all of that, plus settings, gateways, branding and the team
Sign-in
Strong sign-in without a security team
Every member can add two-factor authentication with an authenticator app, sign in with a passkey, or use a one-time code sent by email. Sensitive changes such as adding a custom domain or resetting workspace data ask for the password again first.
- Two-factor authentication and passkeys for every member
- Emailed login codes as an alternative to a password, never a bypass of two-factor
- Password step-up before the settings that matter most
Accountability
Settings changes are recorded by name
Changes to workspace settings are logged with who made them and which field changed, never the value itself, so a bank account update or a numbering change has an author. Every role sees the same dashboard figures; what differs is who can change them.
- Audit trail of settings changes by field name, with the member who made them
- Read-only settings pages for Accountant and Staff, so nothing is hidden and nothing is at risk
- A person can belong to several workspaces and switch between them
In practice
A practical example
Northline Studio has four people. Jordan owns the workspace, Priya is an Admin who manages branding and the team, Sam is the Accountant who records payments and reconciles the bank, and Lee is Staff who writes and sends most of the invoices. When Lee sends INV-1042 and the customer pays by transfer, it is Sam who confirms the claim, and the audit trail says so.
Northline Studio is a fictional business; none of these figures are real.
Outcomes
What you get
- Everyone has their own login and their own name on their actions
- Money actions stay with the Owner, Admin and Accountant
- Two-factor authentication and passkeys for the whole team
- Invitations you can resend, revoke or share as a link
- One person can work across several workspaces
What it does not do
- It does not offer custom permission sets; the four roles are the roles
- It does not hide dashboard figures from any role; every member sees the same numbers
- It does not provide single sign-on with a company identity provider
Questions about team permissions
Create your first invoice in minutes
Free to use today, with no card on file and no trial clock. Add a customer, send the first invoice, and the rest of the workspace is there when you need it.