Help Article
Team Management
Staff & Roles
Control who sees what, who can approve what, and who touches your financial data — with permission sets that match how your firm actually works
4 min read
Updated August 28, 2026
Role-Based Access
Each staff member is assigned one or more permission sets that control feature access:
- Owner — full access to all features
- Admin — full access except ownership transfer
- Standard — configurable per-feature access
- Contractor — limited access, typically time entry only
Service Roles
In addition to permission sets, staff can hold additive service roles that grant cross-cutting access:
- Finance — access to invoicing, billing, and financial reports regardless of base permission set
- Sales — access to quotes, proposals, and pipeline data
Service roles stack on top of base permissions — they never remove access, only add it.
Granular Permissions
Permission sets control access to: jobs (view/edit/delete), clients, invoices (create/approve/export/void), costs, quotes, reports, settings, and more. Each permission can be toggled independently.
| Permission Area | Examples |
|---|---|
| Jobs | View, edit, delete, mark no-invoice-expected |
| Clients | View, edit, manage folders |
| Invoices | Create, approve, export, void |
| Costs | View, manage, approve POs |
| Reports | View reports, view salary data |
| Settings | Manage organisation settings |
Staff Groups (Teams)
Staff can be organised into groups for:
- Client and job visibility scoping
- Team-based reporting
- Batch assignment in job templates
Staff Configuration
- Cost rate, sell rate, and overtime rates per person
- Group/team membership for visibility scoping
- Capacity planning with available hours and leave tracking
- Default assignments for job templates
- MFA status tracking
- Salary and capacity visibility controlled by permissions (hidden from non-authorised users)