Inviting your team

Accounts payable is not a one-person job, and a product that priced it as one would be quietly encouraging you to do it badly. This page covers adding people to a workspace, choosing a role, and the rules that govern who may approve an invoice once they are in.

Nobody is charged per seat

Every plan carries unlimited users, including the free one. Approvers, property managers, your principal and your outside bookkeeper never appear on the bill.

This is a deliberate position rather than an introductory offer. Per-seat pricing makes organizations ration approvers, and rationing approvers is exactly how you end up with a shared login, a controller approving things they never saw, and an audit trail that names the wrong person. Charging for documents instead removes the incentive to cut corners on the control.

Add the people who genuinely make the decisions. The volume you process is what you pay for.

The three roles

There are three roles, and there is no facility for custom ones.

RoleShown asWhat it is for
adminAdminFull access, including team, billing and connector settings
controllerController ApproverApproves invoices at every tier, and manages coding rules
ap_specialistAP SpecialistReviews and codes invoices, and approves within the first tier

They are not a hierarchy with a dial on it. Each restricted action names the roles it accepts, and a role either appears in that list or does not. That is why custom roles are absent: a role no route has ever heard of would grant its holder nothing while looking, on screen, as though it granted something.

The full matrix of who may do what — connectors, mappings, mailboxes, tiers, billing, rules, exports — is in roles and permissions. It is worth reading once before you assign anything, because two of the sensible-sounding assignments are wrong: an outside bookkeeper rarely needs Admin, and a property manager who only approves does not need to code.

Reading the member list is open to everyone in the workspace. Changing it is restricted to Admins. Hiding the list from an AP specialist would buy no security — the same names are already on every approval in their queue — and would stop them finding out who to send an invoice to.

Sending an invitation

Invitations live on the Team tab in settings. An Admin supplies an email address and a role, and the person receives a link.

PropertyBehavior
ValidityThe link expires seven days after it is issued
UsesOne. A redeemed link cannot be redeemed again
Who may redeem itOnly somebody signed in as the address it was sent to
Pending listOutstanding invitations are listed, with who sent them and when they expire
WithdrawalAn Admin can revoke an invitation before it is accepted

The address requirement is the part that matters. A link forwarded to a colleague, or found in a mailbox backup years later, still cannot be used by whoever holds it — they would have to be signed in as the person it names. An expired invitation drops off the pending list on its own; issue a new one rather than trying to revive it.

Inviting somebody who is already in the workspace is refused rather than duplicated. If they need different access, change their role instead.

The outside bookkeeper

Bringing in an external bookkeeper or a fractional controller is a normal case, not an edge one, and it costs nothing.

Invite them like anyone else, with the role that matches what they actually do. If they close your books and post to the ledger, Controller Approver fits. If they are coding invoices for you and somebody internal signs, AP Specialist fits. Reserve Admin for the people who should be able to change your billing and your ledger connection.

When the engagement ends, remove them. Their access stops; the audit trail keeps every decision they made, with their name on it, because the trail is append-only and nothing in the product deletes from it.

Who can approve what

Approval authority is not a general grant that a role carries around. It attaches to a specific approval on a specific invoice.

  • An approval addressed to you is yours to decide, whatever your role.
  • An approval that names nobody can be claimed by a Controller Approver or an Admin. It is not an open door for the whole workspace.
  • The same person cannot sign twice. A tier that requires two approvers requires two people, which is the only thing that makes the number worth stating.

Tiers themselves — the amount bands, the SLA in hours and the number of signatures each band needs — are set by an Admin and are covered in approval tiers. The rules engine and its approval tiers begin at the Starter plan.

Changing roles and removing people

Both are Admin actions, and both are recorded.

There is one refusal you may meet: the workspace will not let you demote or remove its last remaining Admin, whether you are doing it to somebody else or to yourself. A workspace with no Admin has no one who can connect a ledger, change a plan or invite anybody back, and it cannot repair itself from the inside. Promote a second Admin first, then make the change.

Two Admins is a good steady state for most organizations. One is a single point of failure attached to one person's holiday plans.

Where to go next