LedgerOS
Open LedgerOS
Knowledge HubTeam & permissionsRoles and permissions
Team & permissions

Roles and permissions

What each role can reach, and how to grant access more precisely than a role allows.

5 min readUpdated July 24, 2026Requires Manage roles and permissions

Roles are the shorthand. Permissions are what actually decide access, and understanding the difference is what lets you give someone exactly what they need.

Where to find it

SettingsFirmTeam and roles

Two tabs: Members and Roles.

The four roles

Owner — everything, including subscription and billing. Some permissions are owner-only and can't be granted to anyone else.

Admin — everything operational: settings, team, pipelines, clients, money.

Staff — clients and work, without firm-level configuration. The working role.

Read-only — sees, doesn't change.

Permission groups

Underneath the roles, permissions are organised into seven groups:

  • Team and firm — team, roles, firm settings, offices, subscription, integrations, audit log
  • Clients — view, edit, delete, and manage the client portal
  • Work — tasks, pipelines, and how much work someone can see
  • Documents — view, manage, and export, with client and firm exports separated
  • Comms — sending communications
  • Tax and compliance — compliance, research, comp studies, credentials
  • Sales and proposals — proposals and invoicing

Some permissions are deliberately split where the two halves carry different risk. Viewing a credential is one permission; revealing its contents is another. Exporting a client's documents is separate from exporting the firm's.

Why a page might be missing

A tab or page someone can't reach doesn't appear at all — it isn't shown greyed out.

That's why two people can open the same client and see a different tab strip. When a colleague says something is missing, check their permissions before assuming a fault.

Granting precisely

The reason for permissions underneath roles is the person who doesn't fit a role.

A bookkeeper who needs to see documents but never client health. A part-time reviewer who needs work access but not billing. An office manager who runs the team page without touching clients. Roles get them roughly right, and permissions get them exactly right.

Start from the least access that lets someone do their job, then add. Starting from Admin and removing things is how firms end up with everyone an admin.

Notes and limits

  • Owner-only permissions can't be granted to a non-owner. Transfer ownership instead.
  • Changing someone's role resets their access to that role's defaults.
  • Permissions are firm-wide. There's no per-client permission.
  • Removing access doesn't remove the record of what someone did — that stays in the audit log.
Was this article helpful?
Related articles