Roles and permissions
Understand the five roles (owner, admin, finance, analyst and viewer) and choose the right one for each person you invite.
In the app:Members & invitations
On this page
Every member of an organization has one role. The role decides what they can change; it never hides the basics of the bills they can see. Pick the smallest role that lets someone do their job, and change it later if they need more.
The five roles at a glance
| Role | In short | Typical person |
|---|---|---|
| Owner | Everything: bills, members, settings and the company structure. | The person who set up Conduit TEM |
| Admin | Everything an owner can do, except handing over ownership. | IT or telecom manager |
| Finance | Reviews, posts, approves and voids any bill. Sees the whole company; can't change members or settings. | Accounts payable, controller |
| Analyst | Reviews and posts bills below the approval threshold; keeps inventory, people and findings current. Can be limited to part of the company. | Office manager, site coordinator |
| Viewer | Sees everything in their part of the company and can export, but changes nothing. | Executive, auditor, department head |
What each role can do
| Task | Owner | Admin | Finance | Analyst | Viewer |
|---|---|---|---|---|---|
| See bills, inventory, findings, reports and the dashboard | Yes | Yes | Yes | Yes | Yes |
| Export lists and reports | Yes | Yes | Yes | Yes | Yes |
| Upload bills and see the bill inbox address | Yes | Yes | Yes | Yes | No |
| Review bills: fix details, lines and locations | Yes | Yes | Yes | Yes | No |
| Post bills below the approval threshold | Yes | Yes | Yes | Yes | No |
| Post bills at or above the approval threshold | Yes | Yes | Yes | Asks for approval | No |
| Void a bill | Yes | Yes | Yes | No | No |
| Keep inventory, people, findings, notes and tags current | Yes | Yes | Yes | Yes | No |
| Invite people, change roles, remove members | Yes | Yes | No | No | No |
| Change settings, the company structure, vendor accounts and bill inboxes | Yes | Yes | No | No | No |
| Turn on employee self-service and invite people to it | Yes | Yes | No | No | No |
| Delete what Conduit AI has learned | Yes | Yes | No | No | No |
| Choose a plan and manage billing | Yes | Yes | No | No | No |
| Can be limited to part of the company | No | No | No | Yes | Yes |
When someone tries something their role doesn't allow, Conduit TEM tells them "Your role can view but not change this." Buttons they can't use are usually hidden, so a viewer won't see Upload bills at all.
Note: The approval threshold is optional. Owners and admins set it under Settings → Organization → Approvals and auto-post. Without one, analysts can post any bill. See Review and post a bill.
Choosing a role
- Most people who work on bills should be analysts. They can do the everyday work without being able to change settings or who has access.
- Give Finance to the people who sign off on large bills or need to void one that shouldn't count.
- Keep owners and admins few. They control who has access and how the organization is set up.
- Use Viewer for anyone who only needs to look, such as a manager who reads the monthly report.
Limit someone to part of the company
If your company has locations or divisions, you can limit an analyst or viewer to one part of it, such as the Ottawa store. They then only see that part's bills, lines, people and findings, and only get emails about that part. Finance, admins and owners always see everything.
Set this in the Sees column under Settings → Members & invitations. The full explanation is in Roles and scopes.
Change a role
Owners and admins change roles under Settings → Members & invitations by picking a new role on the person's row. Nobody can change their own role. See Invite your team.