Configure roles and permissions
Roles control what people can do, while each person's company assignment controls which invoices, inbox items, and Insights data they can see.
Who can do this
The page and its controls appear only when your organization permissions allow you to review or manage roles. Built-in roles are read-only.
Open roles and permissions
- Select Settings in the main navigation.
- Under ORGANIZATION, select Roles & permissions.
- Select a card under Company roles or Organization roles.
The current page is /settings/organization/roles. Bookmarks to /settings/company/roles no longer open the roles list.
The built-in company roles are Administrator, Controller, AP Specialist, Approver, and Auditor. The built-in organization roles are Administrator and Member. Each built-in role carries a Built-in badge.
Create a custom role
- Select Create role at the top-right of the roles list.
- Choose a Source role to copy.
- Enter the required Role name.
- Add a Description if it helps other admins understand the role.
- Set Available for new assignments.
- Select Create role.
The new role opens on its detail page, where you can review its defaults and permissions before assigning it.
Duplicate a role
- Open the built-in or custom role you want to copy.
- Select Duplicate role in the header.
- Review the locked Source role and enter the new role details.
- Select Create role.
Both Create role and Duplicate role copy an existing role. Use Duplicate role when you are already looking at the source you want.
Read the permission matrix
The Permissions area is split into product categories. Each category has a matrix where:
- Resource rows name the part of the product affected.
- Action columns name what the role can do with that resource.
- A selected box grants that action.
- A required view permission stays selected while another chosen action depends on it.
For company roles, access defaults set the starting invoice and inbox visibility for new assignments. Changing a default does not change existing assignments. Use Manage company access to change one person's role or data access.
Save a custom role
- Open a custom role.
- Change its role details, assignment defaults, or permission boxes.
- Select Save in the header action bar.
When the page has unsaved changes, Cancel and Save remain in the header. Clerked also warns you if you try to leave before saving.
What you should see
The role detail page shows the saved role name, its Custom badge, assignment counts, access defaults for company roles, and the permission matrix.
If something goes wrong
- If the controls are read-only, the role may be built in or its permissions may be locked because members or pending invitations use it. Select Duplicate role to create a new permission set.
- If Create role is unavailable, your organization permissions do not allow role creation at that level.
- If a role name already exists at that level, enter a different Role name and try again.