Skip to content

Roles and permissions

Everyone who works in an entity holds one of five roles. The role decides two separate things: whether you can change anything, and which sections you can reach at all.

Roles are set per entity. The same person can be an admin of one entity and a guest in another.

The five roles

Owner: whoever creates the entity. There is exactly one, it is assigned automatically, and it cannot be handed to someone else or changed to another role. Owners have complete access.

Admin: everything an owner can do in day-to-day use: full read and write, plus team management, entity settings and the audit trail.

User: full read and write across every section, but no access to team management, entity settings or the audit trail.

Viewer: read-only across the whole entity. Every section is visible; any attempt to create, edit or delete is refused.

Guest: read-only and restricted to a handful of sections. The narrowest role, intended for someone who should see holdings and activity but nothing else.

What each role can do

OwnerAdminUserViewerGuest
Entity dashboardYesYesYesYesYes
View all sectionsYesYesYesYesLimited
Create, edit and deleteYesYesYesNoNo
Invite members and change rolesYesYesNoNoNo
Entity settingsYesYesNoNoNo
Audit trailYesYesNoNoNo

The entity dashboard is deliberately open to everyone, including viewers and guests, so every member has somewhere to land.

What guests can see

A guest is limited to these sections:

  • Portfolio
  • Balances
  • Wallets
  • Token cards
  • Transactions

Anything outside that list is hidden from the sidebar, and reaching it directly is refused with "Guest access is limited to wallets, portfolio, balances, token cards, and transactions".

Note this is narrower than a viewer. A viewer sees every section but cannot change anything; a guest sees only the five above.

Read-only roles in practice

Viewers and guests can open pages, filter, sort and read detail. What they cannot do is submit anything: creating a wallet, posting a transaction, editing a reconciliation and so on all fail with a view only error. Buttons that would change data are generally hidden rather than shown and rejected.

Managing your team

Team management lives under Settings → Team, which only owners and admins can open.

Team management under entity settings

From there you can:

  • Invite someone by email, choosing the role they join with
  • Change an existing member's role
  • Cancel a pending invitation, only while it is still pending

There is no way to remove a member once they have joined. If someone should no longer have access, change their role down. Guest is the narrowest, leaving them only Portfolio, Balances, Wallets, Token cards and Transactions.

Four rules constrain this, and the product enforces all of them:

RuleWhy you will hit it
Owner cannot be assignedOnly Admin, User, Viewer and Guest can be given out. Ownership comes from creating the entity.
An owner's role cannot be changedNot by an admin, and not by the owner.
You cannot change your own roleThis prevents an admin from locking themselves out or promoting themselves.
Only pending invitations can be cancelledOnce an invitation is accepted it is no longer an invitation; see below.

Choosing a role

Admin for anyone who needs to run the entity: adding people, changing settings, reviewing the audit trail.

User for the people doing the actual work. It is the right default for a colleague who posts and reconciles but should not be changing entity configuration or team membership.

Viewer for an auditor or reviewer who needs the full picture but must not alter it.

Guest for an outside party: someone who should see wallets and balances without any view of your postings, reconciliations or accounting integrations.

Next

In an accounting entity, connect QuickBooks before you start posting. Otherwise go straight to adding a wallet.

Crypto accounting, finally automated.