User roles and permissions
Last reviewed: 2026-08-07
Scope: The three built-in roles, the full permission matrix, how to build a custom role, and how to shape a role around a real job.
A user role is a named set of permissions. Everyone in your workspace holds one, and it decides which modules they see and what they can do in each of them.
Most teams never need to build one. JomeInvoice creates three roles for you when your workspace is created, and for a small team those three are usually enough. Build a custom role when someone needs more than view-only access but should not have everything.
Being able to see something does not mean being able to export it. Export is granted separately from View. If a role can open the Sales list but the export fails or the button does nothing, check that Export is granted on that row, not just View. This catches people out most often with auditors and accountants, whose whole job is to take data out.
The three built-in roles
Every workspace starts with these, under Settings → Workspace Settings → User Roles:
| Role | Description shown on screen |
|---|---|
| Owner | Full access to all features and settings |
| Admin | Full administrative access to all features and settings |
| Member | View-only access to all modules except Activity Trail and Settings |
These three cannot be changed or removed. On the User Roles list they offer only View Role, so you can open one and read what it grants, but there is no Edit or Delete. A role you create yourself offers Edit Role and Delete Role instead.
Member is view-only, and that includes exporting - a Member cannot export. If someone needs to pull data out for reporting, Member is not enough; build a custom role that grants Export on the rows they need.
Owner is a special case. It cannot be given to a colleague, and an Owner's own role cannot be changed - which is why Owner does not appear in the Role dropdown when you edit someone. There is exactly one ownership path per workspace, so for day-to-day administrative access give a colleague Admin instead. If ownership genuinely has to move, for example because the Owner is leaving the company, contact JomeInvoice to arrange the transfer.
How a custom role is put together
The Edit User Role screen is a long list of permission rows. Each row is one area of JomeInvoice, and the rows are grouped by module: Sales, Customers, Suppliers, Self-billed, Purchase, Activity Trail, Consolidation Log, Import Log, Email Logs, Integrations, and Settings.
For each row you choose what the role can do there. Most rows offer these options:
| Option | Meaning |
|---|---|
| None | The role has no access to this area |
| View | Open and read the records |
| Create | Add new records |
| Edit | Change existing records |
| Delete | Remove records |
| Export | Take the data out of JomeInvoice |
| All | Everything the row offers |
Throughout the rest of this guide, the full set means exactly those seven options. Some rows offer fewer, and those are listed explicitly below.
Picking more than one
View, Create, Edit, Delete, and Export combine. Choose any mixture of them on a row - View and Export together for someone who reports but never changes anything, or View, Create, and Edit for someone who works on records but should not delete them.
None and All do not combine, because each is a statement about the whole row. Choosing either replaces whatever else you had selected.
Select every one of View, Create, Edit, Delete, and Export and your selection switches itself to All. That is the same grant expressed more simply, not a change to what you chose.
Every permission row
| Group | Permission rows | Options offered |
|---|---|---|
| Sales | Request | None, View, Export |
| Sales | Invoices, Credit Notes, Debit Notes, Refund Notes | The full set |
| Customers | Customers Management | The full set |
| Suppliers | Suppliers Management | The full set |
| Self-billed | Invoices, Credit Notes, Debit Notes, Refund Notes | The full set |
| Purchase | Request | None, View |
| Purchase | Invoices, Credit Notes, Debit Notes, Refund Notes | The full set |
| Activity Trail | Activity Trail | None, View, Export |
| Consolidation Log | Consolidation Log | None, View, Edit, Delete, Export |
| Import Log | Import Log | None, View |
| Email Logs | View Email Logs | None, View |
| Integrations | Integrations | The full set |
| Settings | Workspace Setting, People | The full set |
| Settings | API Credentials | None, View, Regenerate |
Some rows deliberately offer fewer options, and it is worth knowing why before you plan a role around them:
- Sales → Request and Purchase → Request have no Create or Edit. Requests are created by your own customers on your public request page, so creating and editing them is always open to the people submitting them rather than something you grant to your staff. Sales → Request adds Export; Purchase → Request is View only.
- Import Log and Email Logs offer only None and View. Both are logs of what already happened, so there is nothing to create or edit - and no Export, which means a read-and-export role still cannot export from them.
- Activity Trail displays Create, Edit, and Delete, but they are greyed out and cannot be selected. It is an audit log, so the choices that mean anything are None, View, and Export.
- Consolidation Log has Create greyed out. Consolidations are produced by running a consolidation, not by adding a log entry by hand, so the choices are None, View, Edit, Delete, and Export.
- Purchase rows have no Export. Exporting from the Purchase module is not currently available.
- Settings → API Credentials covers your workspace's API client credentials and offers None, View, and Regenerate. Creating and deleting credentials are not currently available, which is why those options are absent. Regenerate issues a new Client ID and Client Secret, and a role cannot hold it without View.
Create a user role
- Go to Settings.
- Find Workspace Settings, then click View.
- Click on User Roles.
- Click on Create User Role.
- Fill in Name, Description, and select the appropriate permissions for this Role.
Give the role a name your colleagues will recognise, such as "Finance" or "Purchasing", and a description that says who it is for. Both appear on the User Roles list, so a vague description makes the list harder to maintain later.
Deleting a role you no longer need
A custom role can only be deleted once nobody holds it. If anyone is still assigned to it, Delete Role stops and tells you:
This role is currently assigned to users. Please reassign or remove users before deleting.
Move those people to another role first - or remove their access if they are leaving - then delete the role. Nobody loses access silently because a role disappeared underneath them.
Give someone a role
A role does nothing until someone holds it. People are managed in Settings → People, which lists everyone in your workspace with their name, email, contact, job title, role, and status.
Invite someone
- Go to Settings → People.
- Click Add User.
- Enter their email address and choose the role they should hold.
- Click Invite.
They receive an invitation by email and appear on the list once they have accepted and verified.
Change someone's role, or remove them
Open a person from the People list to reach their Edit User page. There you can change their Role, set a Job title and Contact, and save.
The Role dropdown offers Admin, Member, and every custom role you have created. Owner is not on the list, because ownership cannot be handed over this way.
Remove access on the same page takes someone out of your workspace. Use it when a colleague leaves. Their role is not deleted - only their access.
Changing someone's role changes what they can do immediately. It does not change which branches or sources they cover, or what they are notified about - those come from the teams they belong to. See Teams: branch access, sources, and notifications.
If your workspace uses single sign-on, see Set up Enterprise SSO for how a new SSO user gets their first role.
Choosing a role shape
Start from the job the person actually does, then grant only the rows that job touches. Every row not mentioned should stay at None.
| The person | Give them | Keep at None |
|---|---|---|
| Finance, issues and submits invoices | Sales → Invoices, Credit Notes, Debit Notes, and Refund Notes at All, so they can create, correct, and export. Customers Management with Create and Edit, so they can fix buyer details that block a submission. Sales → Request at View, or Export if they reconcile requests | All Settings rows |
| Accounts-receivable clerk, reads and reports but never edits | View and Export on the four Sales rows and on Customers Management. Export is what makes the role useful, so do not stop at View | Create, Edit, and Delete everywhere. All Settings rows |
| Purchasing, supplier side only | Suppliers Management, the four Self-billed rows, and the four Purchase rows, at the level they need. Purchase → Request at View | The four Sales rows, Customers Management, and all Settings rows |
| Auditor or external accountant, read plus export | View and Export on Sales, Self-billed, Customers Management, Suppliers Management, Activity Trail, and Consolidation Log. View on Purchase, Import Log, and Email Logs, none of which offer Export. Do not use the built-in Member role for this - it cannot export | Create, Edit, Delete, and Integrations. All three Settings rows |
| Anyone who must not change how the workspace behaves | Whatever their day job needs from the module rows | Settings → Workspace Setting, Settings → People, and Settings → API Credentials |
The built-in Member role already covers the plainest read-only case, but its description is explicit that it excludes Activity Trail and Settings. If someone needs to read the Activity Trail, they need a custom role.
Before you grant Settings access
Three permissions deserve a second thought, because their blast radius is the whole workspace rather than one record.
Settings → API Credentials → Regenerate. Regenerating your API credentials will stop a running integration from submitting until the new credentials are put into it. Grant this only to whoever also maintains the integration. The credentials themselves live on your Main HQ under the Client Secret tab, described in Organisation, Main HQ and branches. If submissions start failing on authentication after a regeneration, API submission errors covers what to update.
Settings → Workspace Setting grants access to settings that change how invoices behave for everyone, not just for that person. Submission address, submission date type, calculation-mismatch validation, and the customer and supplier matching rules all live there. See Workspace Settings and How JomeInvoice matches buyers and suppliers for what those settings do.
Settings → People covers managing people and user access, so a role holding it can invite colleagues, change their roles, and remove their access.
There is no permission row for teams. Roles govern the People area, not the Team tab, so grant Settings access with that in mind. What teams do is covered in Teams: branch access, sources, and notifications.
Related articles
- Workspace Settings - every settings tab at a glance
- Create your JomeInvoice account - inviting colleagues to the workspace
- Set up Enterprise SSO - corporate login, and the default role new SSO users receive
- Export invoices - what the Export permission lets someone take out
- API submission errors - authentication failures after API credentials change
- Activity Trail - the log a role needs an explicit permission to read