Team, permissions & API

Roles and permissions

Define what a kind of person may do once, then assign the role.

Last updated 22 September 2026 · More in Team, permissions & API

Setting rights per person looks flexible and becomes unmanageable at about the fifth employee, because nobody can answer “who can see the invoices?” any more.

Where to find itSecurity / admin → Setup → Roles.

Step by step

  1. Open Security / admin → Setup → Roles.
  2. Create a role for each kind of person you have — for example office, sales, technician, accounting.
  3. Set the permissions on the role. Most areas distinguish view, create, edit and delete, and many distinguish “all” from “own”.
  4. Assign the role on each person's record under Central → Team.
  5. Change the role when the job changes, rather than editing one person's rights.

Three principles worth following

  1. Start narrow. Adding a right when somebody asks is easy; discovering that everybody could delete invoices is not.
  2. Prefer “own” over “all” where the work is personal — own leads, own tasks, own time.
  3. Review the roles when the team changes shape, not when something goes wrong.

Two-factor on top

Roles decide what somebody may do once they are in. Security / admin → MFA decides how sure you are that it is them — MFA management, reports and settings. See Sign in with an email code.

The rest of Setup

Security / admin → Setup also holds staff, tenants, help, leads, finance, contract types, estimate requests, modules, e-mail templates, custom fields and GDPR. Settings next to it is the workspace-wide configuration.

Was this article helpful?

Nothing is tracked — the buttons only open a message so you can tell us what was missing.

Related articles

idup

All-in-One Accounting, Payroll & Digital Finance — Simplified

Copyright © 2026 - IDup. All rights Reserved.