Permissions control what actions an organization user can take within a specific domain. Each permission has a domain:action:scope key — permissions are assigned to roles, and roles are assigned to users. See the Roles guide for how to create roles and assign permissions.
Permission model
Permission keys follow a domain:action:scope pattern — for example, expense:read:org or payable:pay:self. The scope is either :org (all objects in the organization) or :self (the user’s own objects, plus their direct reports’ expenses). See Reporting manager for how direct-report relationships work.
write permissions cover create, update, and delete — and implicitly include read. read-only permissions are for roles that should see data but not change it.
Permissions reference
Users and roles
Organization
Bank accounts
Counterparts
Invoices (AR)
Invoice permissions cover the full accounts receivable surface: invoices, payment reminders, overdue reminders, delivery notes, products, and AR-side payment records.
Payables (AP)
Payable permissions cover the full accounts payable surface: payables, purchase orders, credit notes, and AP-side payment records.
Payment records
Expenses
Expense permissions cover transactions and receipts — read includes viewing receipts, write includes creating and updating them.
Transfers
Approval policies and requests
Accounting configuration
Accounting configuration permissions cover ledger accounts, tax rates, cost centers, tags, and projects.
Exports