Skip to content

People and access

Open settings from the workspace name at the top of the sidebar. Members, Roles and General are visible to administrators only.

Whoever created the workspace already holds full access, so roles are needed once somebody else joins.

  1. Open Members and choose Invite member.

  2. Enter the email address.

  3. Set the Workspace role — Owner, Admin or Member. This governs the workspace itself: who may reach these settings pages.

  4. Add any number of roles. These govern the data — what the person may see and change once inside.

  5. Choose Send invitation.

The members list — each person, their roles, and whether the invitation is accepted

The invitation sits under Members with the status Invited until it is accepted, and can be resent or revoked from its row. Removing an active member takes their access away immediately; letting them back in takes a new invitation.

A role is a set of permissions. Members and service accounts hold roles, never permissions directly.

  1. Open Roles and choose Create role, or click an existing role. It opens in a dialog.

  2. Name the role.

  3. Set each business object to None, Read, Write or Full. Read-only objects such as Tax Jurisdictions stop at Read.

  4. Expand a business object to grant its actions — releasing an order, cancelling an invoice — one by one.

  5. Choose Save. The role’s permissions are replaced whole; nothing is written until then.

The role dialog — an access level per business object, with its actions beneath

Level Grants
None nothing
Read viewing records and lists
Write reading, creating and changing, but not deleting
Full everything, deletion included

Actions are separate from all four. A role with Full on sales orders still cannot release one until Release is granted under that object.

Integrations authenticate with an API key rather than a password — see Service accounts.