Invitations
Standard roles
| Role | Typical permissions |
|---|---|
| Admin | All: settings, billing, team, sensitive data |
| Manager | See/edit team data, create automations, approve requests |
| User | Manage own records + shared ones, create tasks, use integrations |
| Read-only | Read only (external consultants, accountants) |
| Guest | Limited access to a specific project (customer) |
Custom roles
For specific cases create custom roles:Per-module permissions
For each module (CRM, HR, Finance…) set:
- None: doesn’t see
- Read only: sees, doesn’t edit
- Edit own: create/edit only owned records
- Edit team: also team records
- Edit all: also others’ records
Teams and hierarchies
Single Sign-On (SSO)
For companies with identity providers (Google Workspace, Microsoft Azure AD, Okta):Audit log
Every change to team, roles, permissions is logged:- Who did what
- When
- From which IP
- What changed (before/after)