Team & Security
Permissions & roles
Entitlement vs permission, the Billing permission keys, and role presets.
Two layers, again
- Entitlement decides whether the business can use Billing at all (see Access & trial).
- Permission decides whether a user can perform a specific action on that business.
Entitlement without permission means the module is visible but the action is blocked. Permission without entitlement means the module is not licensed.
Permission keys
Billing actions map to granular permission keys, for example:
| Action | Permission |
|---|---|
| View lists and detail | read |
| Create/edit invoices | invoice write |
| Issue a document | invoice issue |
| Cancel a document | invoice delete |
| Convert a quotation | quotation convert |
| Create credit/debit note | credit_note / debit_note write |
| Record a payment | payment record |
| Record a supplier payment | payment record |
| Create/edit customers | customer write |
| Create/edit suppliers | customer write (supplier directory) |
| Create/edit items | item write |
| Create/revoke share links | share create / revoke |
| Configure numbering | series configure |
| Configure GST rates | tax_rate configure |
| Edit business policies | policy configure |
| Manage members | members manage |
| Approve workflows | approve |
| Push IRN / e-Way | einvoice push |
Role presets
When you invite a member you pick a preset that bundles permissions:
| Role | Roughly can |
|---|---|
| Owner | Everything, including settings |
| Manager | Issue, credit notes, share; not policy/series configure |
| Executive | Prepare drafts, quotations, payments, customers, items, share |
| Viewer | Read and export |
| Accountant | Read, export, view payments |
An invite can never assign an owner-equal role.
Optional issue-approval policy
A policy can require a manager to issue documents; executives then save drafts that queue for approval (see Approvals).