A role is a named set of permissions. Each team member has one role, and the role decides which pages and actions they can use. You manage roles on the Role Management page.
Screenshot to come: Role Management → role list and Role Details with the Permissions groupspublic/help/team/roles-and-permissions-1.png
Before you start
- Roles are part of the Pro or Enterprise plan.
- You need the Manage Roles permission (in the Team Management group). The owner always has it.
- To give a role to a person, you need Assign Roles. See Invite team members.
Open the Roles page
- Open Settings (under your name, bottom left of the sidebar), then Team & Roles.
- Click Manage Roles.
The left column lists every role with its member count. Built-in roles carry a System tag. Click a role to see its details and permissions.
Create a role
- Click + Create Role.
- Enter a Role Name, for example "Market Manager". Names must be unique.
- Pick a Color. The color marks the role on the Team Management page.
- Optional: add a Description.
- Tick the permissions the role needs.
- Click Create Role.
Change or delete a role
- To change a role, select it, click Edit, make your changes and click Save Changes. People with that role get the new permissions.
- To delete a custom role, select it and click Delete. You can only delete a role nobody has. Move its members to another role first.
- System roles cannot be deleted. The Owner role cannot be renamed.
- Only the owner can change the Owner role's permissions. Anyone else who saves it sees "Only an organization owner can change the Owner role".
Permissions
Permissions are grouped on screen like this:
| Group | Permissions |
|---|---|
| Dashboard & Analytics | View Dashboard, Customize Dashboard |
| Client Management | View Clients, Create Clients, Edit Clients, Delete Clients, Invite Clients |
| Invoice Management | View Invoices, Create Invoices, Edit Invoices, Delete Invoices, Send Invoices |
| Payment Management | View Payments, Process Payments, Issue Refunds |
| Team Management | View Team, Invite Members, Edit Members, Remove Members, Manage Roles, Assign Roles |
| Box Counting | Enter Box Counts, Review & Post to QuickBooks, Manage Box Counting Configuration |
| Widget Permissions | View All Widgets, Manage Widget Access |
| Settings | View Settings, Edit Settings, Manage Billing, Manage Integrations, Manage Branding |
| QuickBooks Tools | Sync QuickBooks, Import to QuickBooks, Export from QuickBooks |
| File Exchange | View Files, Upload Files, Download Files, Share Files, Delete Files |
| Audit Log | View Audit Log, Export Audit Log |
| Reports | The reports view, export and template permissions (reports.view, reports.export, reports.configure) |
| Advanced Analytics | View Analytics Dashboard, Sync Analytics Data, Export Analytics Data, Configure Analytics |
A permission only matters if your plan includes the feature. For example, the Box Counting permissions do nothing unless Box Counting is turned on for your organization.
Some sidebar items need a specific permission:
| Sidebar item | Permission |
|---|---|
| Dashboard | View Dashboard |
| Library | View Analytics Dashboard |
| QuickBooks Online Invoicing | View Invoices |
| QuickBooks Online Import, QuickBooks Online Batch Modify, Square Sales Import | Import to QuickBooks |
| Data Warehouse | The reports view permission (reports.view) |
| Box Counting | Enter Box Counts |
| File Exchange | View Files |
The settings pages live under Settings (under your name, bottom left of the sidebar). Each card there needs a permission too:
| Settings card | Permission |
|---|---|
| Team & Roles | View Team |
| Widget Access | Manage Widget Access |
| Audit Log | View Audit Log |
| Client Payment Settings | Edit Settings |
| Brand | Manage Branding |
| Billing & Plans | Manage Billing |
| QuickBooks connection and sync | Manage Integrations or Sync QuickBooks |
| Box Counting configuration | Manage Box Counting Configuration |
| Analytics settings | Configure Analytics or Manage Box Counting Configuration |
System roles
Every organization has these five built-in roles from the moment it is created, and the person who created it holds the Owner role. Open a role to see exactly what is ticked.
| Role | Description on screen |
|---|---|
| Owner | Full access to all features, settings, and billing. Cannot be deleted. |
| Administrator | Full administrative access except billing management |
| Manager | Can manage day-to-day operations and view reports |
| Team Member | Standard access for team members - can view and create but not delete |
| Viewer | Read-only access to view data without making changes |
The Administrator role has every permission except Manage Billing. When ClientSynq adds a permission, the Owner and Administrator roles get it too. The Manager, Team Member and Viewer roles keep their own lists, which you can change.
What the owner can always do
The person who created the organization is its owner. The owner has every permission in the list above, whatever the Owner role's boxes say, including permissions added to ClientSynq later. The owner:
- always sees every sidebar item the plan includes
- is the only person who can remove team members
- is the only person who can invite someone as Owner, grant the Owner role or change the Owner role's permissions
- cannot be removed, and their role cannot be changed on the Team Management page
Good to know
- Someone invited without a role joins with the Team Member role. Change it on the Team Management page if they need more or less.
- Each person has one role. Picking a new role replaces the old one.
- Which dashboard widgets a role can see is set separately. See Choose what each role sees on the dashboard.