Inviting your team
Accounts payable is not a one-person job, and a product that priced it as one would be quietly encouraging you to do it badly. This page covers adding people to a workspace, choosing a role, and the rules that govern who may approve an invoice once they are in.
Nobody is charged per seat
Every plan carries unlimited users, including the free one. Approvers, property managers, your principal and your outside bookkeeper never appear on the bill.
This is a deliberate position rather than an introductory offer. Per-seat pricing makes organizations ration approvers, and rationing approvers is exactly how you end up with a shared login, a controller approving things they never saw, and an audit trail that names the wrong person. Charging for documents instead removes the incentive to cut corners on the control.
Add the people who genuinely make the decisions. The volume you process is what you pay for.
The three roles
There are three roles, and there is no facility for custom ones.
| Role | Shown as | What it is for |
|---|---|---|
admin | Admin | Full access, including team, billing and connector settings |
controller | Controller Approver | Approves invoices at every tier, and manages coding rules |
ap_specialist | AP Specialist | Reviews and codes invoices, and approves within the first tier |
They are not a hierarchy with a dial on it. Each restricted action names the roles it accepts, and a role either appears in that list or does not. That is why custom roles are absent: a role no route has ever heard of would grant its holder nothing while looking, on screen, as though it granted something.
The full matrix of who may do what — connectors, mappings, mailboxes, tiers, billing, rules, exports — is in roles and permissions. It is worth reading once before you assign anything, because two of the sensible-sounding assignments are wrong: an outside bookkeeper rarely needs Admin, and a property manager who only approves does not need to code.
Reading the member list is open to everyone in the workspace. Changing it is restricted to Admins. Hiding the list from an AP specialist would buy no security — the same names are already on every approval in their queue — and would stop them finding out who to send an invoice to.
Sending an invitation
Invitations live on the Team tab in settings. An Admin supplies an email address and a role, and the person receives a link.
| Property | Behavior |
|---|---|
| Validity | The link expires seven days after it is issued |
| Uses | One. A redeemed link cannot be redeemed again |
| Who may redeem it | Only somebody signed in as the address it was sent to |
| Pending list | Outstanding invitations are listed, with who sent them and when they expire |
| Withdrawal | An Admin can revoke an invitation before it is accepted |
The address requirement is the part that matters. A link forwarded to a colleague, or found in a mailbox backup years later, still cannot be used by whoever holds it — they would have to be signed in as the person it names. An expired invitation drops off the pending list on its own; issue a new one rather than trying to revive it.
Inviting somebody who is already in the workspace is refused rather than duplicated. If they need different access, change their role instead.
The outside bookkeeper
Bringing in an external bookkeeper or a fractional controller is a normal case, not an edge one, and it costs nothing.
Invite them like anyone else, with the role that matches what they actually do. If they close your books and post to the ledger, Controller Approver fits. If they are coding invoices for you and somebody internal signs, AP Specialist fits. Reserve Admin for the people who should be able to change your billing and your ledger connection.
When the engagement ends, remove them. Their access stops; the audit trail keeps every decision they made, with their name on it, because the trail is append-only and nothing in the product deletes from it.
Who can approve what
Approval authority is not a general grant that a role carries around. It attaches to a specific approval on a specific invoice.
- An approval addressed to you is yours to decide, whatever your role.
- An approval that names nobody can be claimed by a Controller Approver or an Admin. It is not an open door for the whole workspace.
- The same person cannot sign twice. A tier that requires two approvers requires two people, which is the only thing that makes the number worth stating.
Tiers themselves — the amount bands, the SLA in hours and the number of signatures each band needs — are set by an Admin and are covered in approval tiers. The rules engine and its approval tiers begin at the Starter plan.
Changing roles and removing people
Both are Admin actions, and both are recorded.
There is one refusal you may meet: the workspace will not let you demote or remove its last remaining Admin, whether you are doing it to somebody else or to yourself. A workspace with no Admin has no one who can connect a ledger, change a plan or invite anybody back, and it cannot repair itself from the inside. Promote a second Admin first, then make the change.
Two Admins is a good steady state for most organizations. One is a single point of failure attached to one person's holiday plans.
Where to go next
- Roles and permissions — the full matrix, action by action.
- Approval tiers — encode who signs for what, and how quickly.
- Audit trail — what is recorded about every person in the workspace.
- Plans and limits — what each plan includes, and what it does not.