Invitations
1
Settings → Team → + Invite
Email or bulk CSV.
2
Pick role
See next section.
3
Custom message (optional)
For invitation context.
4
Send
Recipient gets email with registration link.
Standard roles
Custom roles
For specific cases create custom roles:1
Team → Roles → + New role
Name, description.
2
Per-module permissions
For each module (CRM, HR, Finance…) set:
- None: doesn’t see
- Read only: sees, doesn’t edit
- Edit own: create/edit only owned records
- Edit team: also team records
- Edit all: also others’ records
3
Field-level permissions
For sensitive fields (salary, IBAN) hide or make read-only.
4
Save and assign
Apply new role to existing users.
Teams and hierarchies
1
Create team
Sales, Operations, HR, etc.
2
Assign members
Each user can belong to multiple teams.
3
Team manager
Designate manager. Sees/edits member data.
4
Sub-teams
Teams can have sub-teams (multi-level hierarchy).
Single Sign-On (SSO)
For companies with identity providers (Google Workspace, Microsoft Azure AD, Okta):1
Settings → Team → SSO
Pick provider.
2
Configure
SAML / OpenID Connect metadata. Arya provides exact instructions.
3
Verify
Test login.
4
Force SSO
Option: disable password login, SSO only (more secure).
Audit log
Every change to team, roles, permissions is logged:- Who did what
- When
- From which IP
- What changed (before/after)
User deactivation
1
Team → User → Deactivate
Doesn’t delete, preserves history.
2
Record transfer
Arya asks to whom to reassign user’s deals, tasks, projects.
3
Access revocation
Tokens and sessions invalidated immediately.
4
Reactivation
Always possible from the panel.