Team Members & Access: Who Sees What
A firm holds other people's financial records, so access is deliberately tight: a new team member sees nothing until you say otherwise. This guide covers the four roles, the two independent permission layers, and the one misunderstanding behind most “why can't they open this?” questions.
The Four Firm Roles
Owner
Full access to everything, permanently. An owner cannot be locked out of any section or any client — no permission setting applies to them. This is on purpose: a firm must never end up with nobody able to reach its own records.
Admin
Full access as well, and can manage members. The everyday role for a partner or practice manager.
Senior
A restricted role — sees only what has been granted.
Member
Also restricted, and the usual role for staff working a defined set of clients.
Only owners and admins can assign roles and grant access. Seniors and members cannot widen their own permissions or anyone else's.
New Members Start With Nothing
A new senior or member joins with no access at all — not a reduced set, not a sensible default. Nothing is visible until it is explicitly granted.
This trips people up on day one, and it is worth understanding why it was built that way. A default that granted “the basics” would mean every new hire silently receiving access to some set of client financial records that nobody deliberately chose. Starting from nothing means every piece of access exists because someone decided it should.
Two Separate Permission Layers
This is the part worth getting straight, because the two layers are independent and granting one does not imply the other:
- Firm-wide sections — the areas of your practice: projects, templates, invoices, timesheets, team members, and so on.
- Per-client access — which specific clients someone can open, and what they can do inside each one.
Someone can have broad firm-wide access and no clients, or one client and nothing else. Both layers are granted per person.
Firm-Wide Sections
Each section is granted at one of three levels: None (hidden), Read (view only) or Write (view and act). The sections you can grant include:
- Overview and Analytics
- Firm Books — your firm's own bookkeeping
- Projects, Templates and Timesheet
- All Clients — the client list itself
- Invoices & Payouts
- Team Members
- Upload Links and Client SMS
- E-Sign and Live Calls
- Audit Log and Practice Settings
Grant conservatively. Team Members, Practice Settings and Invoices & Payouts in particular let someone change how the firm itself operates, which is a different thing from doing client work.
Per-Client Access
Access to a client is granted per client, and within a client it is granted per area of their workspace — bookkeeping, projects, documents, notes — again at None, Read or Write.
You can set a default pattern for a team member that applies to the clients they are given, and override it for a particular client where the usual pattern does not fit — read-only on a sensitive account, for instance, while they have full access elsewhere.
What someone can do to the books follows from their bookkeeping access: viewing, editing, or approving are progressively higher levels rather than separate switches.
Assigning Work Is Not Granting Access
The single most common surprise: assigning someone a task or a project for a client does not give them access to that client. They will see the task and be unable to open the client it belongs to.
It reads like a bug and is not one. Assignment says who should do a piece of work; access says whose financial records a person may read. Keeping them separate means a hurried task assignment can never hand out access to a client's books as a side effect — but it does mean granting access is a step you have to remember.
When Someone Cannot See Something
Work down this list — it resolves nearly every case:
- Is their invitation accepted and their seat active? An invited but unjoined person has no access to anything.
- Is it a firm section or a client? The two layers are separate, so check the right one.
- For a firm page: is that section granted to them at Read or Write?
- For a client: have they been given access to that client — not just assigned work on it?
- They can open it but cannot change anything: they have Read where they need Write.
Frequently Asked Questions
Can I stop a team member seeing one particular client?
Yes — for seniors and members, simply do not grant that client, or override it to None. Owners and admins see every client by design, so a genuinely restricted person should not hold either role.
Someone left the firm. What happens to their work?
Deactivate their seat rather than deleting anything — their access ends immediately while the record of what they did stays in the audit trail, which is what you want if a return they touched is ever questioned. Their open work can be transferred to someone else.
Why can a member see the client list but not open a client?
Because those are two different grants. Seeing the list is a firm-wide section; opening a client is per-client access. Grant the specific clients they work on.
Can there be more than one owner?
For a partnership, admin is usually the right role for the other partners — it carries full access and the ability to manage the team, without multiplying the accounts that can never be restricted.