Manage people, roles, and access
Invite members, assign organization and company roles, and verify the work and records they can access.
Invite or update an organization member
-
Open Settings > Organization > Members. Invite a person’s work email or open an existing member.
-
Choose the organization role. Select the smallest role that supports the person’s organization-level job. Roles control actions; they do not by themselves grant every company or every record.
-
Assign companies and company roles. Add only the companies the person needs. Set the company role and any visible record scope shown in the form.
-
Send or renew the invitation. The person must accept before signing in. Use the invitation status to distinguish someone who has not joined from someone who lacks access.
Link a company person to a business identity
Open Settings > Company > People when an approver or other person must be linked to a synchronized employee record. Confirm the correct record with its identifier and company, not the display name alone.
Manage roles
Built-in system roles are read-only. Duplicate one when you need a custom permission set, then edit the custom role directly even after people or pending invitations reference it. Saved permission changes apply to server requests immediately; people who are already signed in may need to sign out and back in before every screen reflects the change.
Every active custom role is available for assignment. A role that still has members or pending invitations cannot be deleted; move those references to another role first.
Verify effective access
Check three things separately: the action permission, the assigned companies, and the record visibility inside each company. Insights scope is also separate from invoice and email visibility. Remove membership when a person should no longer sign in. Give each person their own account.