Roles and permissions
Four roles — Owner, Bookkeeper, Employee, and External Accountant — each scoped to what that person actually needs.
The four roles
- Owner — full access, including billing, team management, and locking periods.
- Bookkeeper — everything Owner has except billing and managing users; the day-to-day books role.
- Employee — submits their own expenses and reimbursements, and sees only their own submissions.
- External Accountant — read access to every report, adjusting-entry rights (including into locked periods), and tax exports; invited per business, not billed as a seat.
Inviting your team
Invite people by email and assign a role at the same time; every plan includes unlimited team members. Someone can belong to more than one business, which is how an External Accountant works across clients, or how a bookkeeper covers two entities under the same owner.
What each role can do
Posting transactions, approving reimbursements, invoicing customers, and locking periods are all Owner-and-Bookkeeper capabilities. Running reports is open to Owners, Bookkeepers, and External Accountants. Billing and user management stay with the Owner alone.
Changing someone's role
Roles can be changed at any time from settings. A role change doesn't touch history that's already been recorded — every action already carries who did it and when. Removing someone also disconnects any AI tool they had connected to this business.
Connected AI tools follow the role
An AI assistant someone connects to their books (see Connecting your own AI) can only do what that person's role allows. An Employee's assistant sees an Employee's view; a Bookkeeper's can post. Nobody gains access through a tool that they don't already have themselves.