Skip to main content

Understand roles and access

Clerked separates what a person can do from which company data they can see. This keeps roles reusable without giving every person who shares a role the same visibility.

The six getting-started guides describe common job personas, not six more roles. AP Specialists, Approvers, and Auditors have guides that line up with built-in company roles. The AP Manager, Controller and Finance Manager, and CFO guides describe ways people may work in Clerked, so an administrator still assigns one of the built-in or custom roles described below. In particular, AP Manager and CFO are not built-in role names.

The five parts of access

Every user has:

  1. A primary role for organization-level actions.
  2. One company role for each company they can use.
  3. An invoice access setting for each company.
  4. An inbox access setting for each company.
  5. An Insights access setting for each company, when the role includes Insights.

For example, one person can be an organization Member, a Controller in the parent company, and an AP Specialist in a subsidiary. Their invoice, inbox, and Insights access can differ between those companies.

Primary roles

RoleWhat it covers
AdministratorOrganization administration, invitations, member changes, role management, and all company actions.
MemberSign-in identity only. Company assignments provide company access and actions.

An active primary Administrator who has no explicit assignment for a company inherits Administrator access to that company. If an explicit company assignment exists, that assignment controls the person's company role, invoice access, inbox access, and Insights scope.

Company roles

Five built-in roles cover common AP jobs. Built-in roles are read-only. Administrators can clone one into a custom role and choose a different set of action permissions.

Administrator

Has every company permission. Administrators can process invoices, manage people and settings, configure policies and validation, and manage Agents. Changing a user's company assignment still requires the separate primary member-update permission.

Controller

Runs AP operations. Controllers can process, approve, delete, restore, hold, cancel, and export invoices. They can also manage approval policies, validation checks, fields, Agents, and Agent Memories. They cannot administer organization members or primary roles unless their primary role grants that access.

AP Specialist

Owns invoice intake and review. AP Specialists can create, upload, edit, validate, approve, reject, delete, restore, hold, resume, cancel, and export invoices. They can override validation and approval routing by default.

Approver

Reviews invoices routed to them and approves or rejects those invoices. Approvers can edit, validate, hold, resume, or cancel invoices allowed by schema state, read Agent Memories, and manage their own approval delegation. They cannot upload, delete, or reroute invoices by default.

Auditor

Has read-only access to invoices, approval histories, settings, ERP data, emails, Agent Memories, and Clerked Agent when the company capability is on. The role editor still names that permission Use Mod Agent. Auditors do not receive Insights by default and cannot change records.

Default action matrix

ActionAdministratorControllerAP SpecialistApproverAuditor
View invoicesYesYesYesYesYes
Create or upload invoicesYesYesYesNoNo
Edit invoicesYesYesYesYesNo
Validate invoicesYesYesYesYesNo
Delete or restore invoicesYesYesYesNoNo
Override invoice routingYesYesYesNoNo
Approve or reject invoicesYesYesYesYesNo
Manage approval policiesYesYesNoNoNo
Manage validation checksYesYesNoNoNo
Manage AgentsYesYesNoNoNo
Manage Agent MemoriesYesYesYesNoNo
View InsightsYesNoNoNoNo
Manage company settingsYesNoNoNoNo

This table describes built-in action permissions. A custom role can use any valid combination from the role editor.

Built-in role and action matrix

Invoice and inbox access

Invoice and inbox access are two independent parts of the person's company assignment, not role permissions.

SettingWhat the person can see for that resource
AllEvery invoice or inbound email in that company, plus its inherited surfaces.
AssignedOnly invoices or inbound emails assigned through the canonical workflow participation paths, plus inherited surfaces.

The invitation form shows separate Invoice access and Inbox access controls. Administrator, Controller, and Auditor default to All for both. AP Specialist, Approver, and custom roles default to Assigned unless their role declares different defaults. An administrator can choose either scope independently when assigning access.

Insights access

Insights has a separate access setting because a plant manager may need company-wide invoice and inbox work but only one plant's spend metrics, or the reverse.

SettingWhat Insights includes
All company dataMetrics across the selected company.
Restricted by dimensionMetrics limited to selected values from one configured dimension, such as Plant.

Restricted Insights access supports 1 to 50 values from one schema-defined dimension. It changes Insights metrics only. It does not change which invoices or emails the person can open.

A person also needs the company:insights:view permission through their company role. If the role does not include it, the Insights navigation item stays hidden even when an Insights scope exists.

Custom roles

Custom roles define action permissions and suggested defaults for new invoice and inbox assignments. Each person's company assignment stores the effective invoice, inbox, and Insights scopes, so changing a role's defaults does not silently rewrite existing access. Once a member or pending invitation references a custom role, duplicate it to change permissions; descriptive information and defaults can still be edited.

Open Settings, select Organization, then select Roles & permissions to review both company and organization roles or create a custom role. See Configure roles and permissions.

How access gets assigned

An administrator sets the complete company assignment when inviting a person or changing existing access:

  • Company role.
  • Invoice access.
  • Inbox access.
  • Insights access, including a dimension and values when access is restricted.

One invitation can include separate assignments for multiple companies. To change an existing user's company assignment, open Settings, select Company, select People, open the linked person, and select Change access.

You cannot change your own assignment. Ask an administrator if you need a different role or data scope.

What the navigation shows

Clerked hides navigation items when you do not have the required permission. It does not show unavailable sections with lock icons. The API also checks the same action and data scope, so hiding a control is not the security boundary.

Some companies enable a focused restricted approver mode for approval-scoped users. That mode narrows the invoice list and removes unrelated navigation while the company setting is active.

We use cookies to understand how visitors use our site.