Skip to main content
Permissions control what actions an organization user can take within a specific domain. Each permission has a domain:action:scope key — permissions are assigned to roles, and roles are assigned to users. See the Roles guide for how to create roles and assign permissions.

Permission model

Permission keys follow a domain:action:scope pattern — for example, expense:read:org or payable:pay:self. The scope is either :org (all objects in the organization) or :self (the user’s own objects, plus their direct reports’ expenses). See Reporting manager for how direct-report relationships work.
write permissions cover create, update, and delete — and implicitly include read. read-only permissions are for roles that should see data but not change it.

Permissions reference

Users and roles

Organization

Bank accounts

Counterparts

Invoices (AR)

Invoice permissions cover the full accounts receivable surface: invoices, payment reminders, overdue reminders, delivery notes, products, and AR-side payment records.

Payables (AP)

Payable permissions cover the full accounts payable surface: payables, purchase orders, credit notes, and AP-side payment records.

Payment records

Expenses

Expense permissions cover transactions and receipts — read includes viewing receipts, write includes creating and updating them.

Transfers

Approval policies and requests

Accounting configuration

Accounting configuration permissions cover ledger accounts, tax rates, cost centers, tags, and projects.

Exports