SaaSFlow
Concepts

Team & permissions

Invite team members, assign roles, and customize per-user permissions.

Open Settings → Users to manage team members. Each member belongs to one company and holds either a preset role or a custom set of permissions.

Inviting members

Invite by email from Settings → Users. The link in the invitation email is valid for 7 days. Signing up with the invited address joins the company directly, with no separate email confirmation step. Signing up or logging in under a different address shows an accept screen first, so an invitation can also be attached to an existing account.

Roles

RoleAccess
OwnerFull access — everything Editor can do, plus inviting and removing team members, creating API keys, managing integrations, and changing company settings.
EditorRead and write on all data: customers, vendors, accounts, transactions, subscriptions, balances, and financials. No admin rights.
ViewerRead-only access to everything in the company.

Most teams use roles. Switch to custom permissions when one user needs a narrower scope — for example, "the bookkeeper can edit transactions but cannot manage users".

Custom permissions

Open Settings → Users, edit a member, and open the permission picker. Choose a preset or change individual checkboxes to create a custom selection. Each row is a resource and offers some combination of Read, Write, and Manage:

ResourceReadWriteManage
SubscriptionsView MRR, subscription events, and subscription metrics such as churn and retentionEdit subscription events manually—
CustomersView customersCreate, edit, merge customers—
VendorsView vendorsCreate, edit, merge vendors—
AccountsView accounts and balancesAdd and edit accounts—
TransactionsView transactionsAdd, edit, split, recategorize—
BalancesView account balancesAdjust balances manually—
Financials (P&L, Plans)View P&L, planning data, and P&L and cash metrics such as burn and runwayEdit category plans and percentages—
User management——Invite, remove, and change roles of team members
API keys——Create and revoke API keys
Integrations——Add or remove integrations
Company settings——Change company name, base currency, etc.

Owner is everything in this table. Editor is every Read and Write box, nothing under Manage. Viewer is every Read box, nothing else.

Analytics metrics follow the data they are computed from. Metrics that only use subscription events (MRR, ARR, churn, net and gross revenue retention, growth rates) need Subscriptions read. Metrics from the P&L or bank accounts (revenue, margins, burn, runway) need Financials read. Metrics that combine both (CAC payback, lifetime value, Rule of 40, burn multiple) need both, as does the Valuation page. Dashboards hide the widgets a member cannot see.

P&L access without transaction details

In Settings → Users, edit a member and enable Read for Financials (P&L, Plans). Leave Read and Write for Transactions unchecked. To give only P&L and financial metrics access, leave all other permissions unchecked as well.

With only Financials Read, members can view P&L totals by month and category, financial metrics, and plans, and export the P&L table. They cannot edit data, open individual transactions, drill into counterparties, see vendor spending breakdowns, or read AI analyst reports.

Vendor spending breakdowns require Financials, Vendors, and Transactions Read. AI analyst reports, including their history, require Read access to Financials, Transactions, Subscriptions, Customers, Vendors, Accounts, and Balances because the reports can quote details from each source.

Notifications in the app and by email follow the same source permissions. Members without Transactions Read do not receive transaction assignments or comment details. Weekly and monthly summary emails include only sections you can access: subscription metrics require Subscriptions Read, named customer movements also require Customers Read, and cash flow requires Transactions and Balances Read. The uncategorized transaction notice requires Transactions Read; its action link also requires Transactions Write. Setup prompts appear only with access to the relevant data and setup pages. If no permitted content remains, no email is sent. Financials Read alone does not enable summary emails. Your weekly and monthly email preferences still apply.

Financials Read covers the whole company. It does not hide selected categories or restrict access by department. Totals can still reveal an individual amount when a category contains only one transaction.

On this page