Browse the manual
Roles and permissions
Every role in Made with Pepper and the permissions each role grants.
On this page
For: owners and admins who manage team access.
Made with Pepper has four built-in roles and supports custom roles. Each installation has one owner. Enabled modules and guest scopes can further restrict access.
Role summary
| Role | Purpose |
|---|---|
| Owner | Full access. The primary account holder. |
| Admin | Operational and account administration. Owner-only installation controls remain unavailable. |
| Accountant | Read-only financial access. Can view documents, customers, items, and export data. Cannot create or modify documents. |
| Employee | Operational access. Can create and manage invoices, customers, and items. Cannot see aggregate financial data or access settings. |
Permission matrix
| Permission | Owner | Admin | Accountant | Employee |
|---|---|---|---|---|
| Documents | ||||
| View all documents | ✓ | ✓ | ✓ | ✗ |
| View own documents | ✓ | ✓ | ✗ | ✓ |
| Create documents | ✓ | ✓ | ✗ | ✓ |
| Edit all documents | ✓ | ✓ | ✗ | ✗ |
| Edit own documents | ✓ | ✓ | ✗ | ✓ |
| Delete own drafts | ✓ | ✓ | ✗ | ✓ |
| Delete any draft | ✓ | ✓ | ✗ | ✗ |
| Issue documents | ✓ | ✓ | ✗ | ✓ |
| Email documents, send reminders and record deliveries (employee: own documents) | ✓ | ✓ | ✗ | ✓ |
| Settle, cancel and duplicate all documents | ✓ | ✓ | ✗ | ✗ |
| Settle, cancel and duplicate own documents | ✓ | ✓ | ✗ | ✓ |
| Customers | ||||
| View customers | ✓ | ✓ | ✓ | ✓ |
| Manage customers | ✓ | ✓ | ✗ | ✓ |
| Items | ||||
| View items | ✓ | ✓ | ✓ | ✓ |
| Manage items | ✓ | ✓ | ✗ | ✓ |
| Purchases | ||||
| View all purchases and their files | ✓ | ✓ | ✓ | ✗ |
| Record, change and void own purchases | ✓ | ✓ | ✗ | ✓ |
| Change and void all purchases | ✓ | ✓ | ✗ | ✗ |
| Open tax periods and download them (needs the financial summary and export permissions) | ✓ | ✓ | ✓ | ✗ |
| Manage purchase categories | ✓ | ✓ | ✗ | ✗ |
| Financial | ||||
| View financial summary | ✓ | ✓ | ✓ | ✗ |
| Settings | ||||
| Manage settings | ✓ | ✓ | ✗ | ✗ |
| Users | ||||
| Manage users | ✓ | ✓ | ✗ | ✗ |
| Transfer ownership | ✓ | ✗ | ✗ | ✗ |
| Recurring schedules | ||||
| Manage recurring schedules | ✓ | ✓ | ✗ | ✓ |
| Data | ||||
| Export data | ✓ | ✓ | ✓ | ✗ |
| Audit log | ||||
| View full audit log | ✓ | ✓ | ✗ | ✗ |
| View own audit log | ✓ | ✓ | ✓ | ✗ |
"Settle" means: record and reverse payments, issue credit notes, and record and reverse refunds. Made with Pepper checks these rights again when it saves, so a role change takes effect at once.
Notes
Owner vs. admin. Both roles manage operational settings. Security policy, module changes, optional-provider settings and external connections have owner-only boundaries. Admins cannot edit the owner. Neither role may delete or deactivate themselves, or change their own role through ordinary user editing.
Only the owner can transfer ownership, and the target must be an active admin. Invitations cannot assign the owner role. Only one user can be the owner at a time.
Employee visibility. Employees can view and manage their own documents. They cannot see aggregate financial data, including Home's money figures, receivables, overdue totals and credit owed. The money pipeline, largest-debtor table, issued-invoice analysis and six-month figures are hidden too. They can see customer records and the item catalog. Document lists, customer history, search results, tag suggestions and linked-document panels show only documents the employee created. A shared customer record does not grant access to another person's documents.
Customer financial summaries, payment counts, payment timing and last invoice date are hidden from employees. Employees can still see amounts and payments on their own documents. The built-in Employee role cannot export CSV, XML or reports, including its own documents. Export actions need data.export and record access. A custom role can include that permission.
Accountant access. Accountants have read-only access to all financial data. They can view documents, customers, and items, and export data (CSV, XML). They cannot create, edit, or send documents.
Accountant audit log. The accountant opens Settings > Audit log from Your profile and sees only their own events. The page names no other person and has no Actor filter.
Purchases. Employees see, change and void only the purchases they recorded, and cannot open tax periods. Accountants read every purchase and file, open tax periods and download them, and change nothing. See Record purchases.
Recurring schedules. Only roles with invoices.manage permission (owner, admin, employee) can access recurring invoice schedules. Accountants cannot view or manage recurring schedules. Employees see and manage only the schedules they created. Generated invoices keep the schedule creator as their owner. Employees can open invoices from their own schedules.
Related pages
Files, people and custom permissions
| Action | Owner | Admin | Accountant | Employee |
|---|---|---|---|---|
| Read permitted files and people | Yes | Yes | Yes | Yes |
| Manage files | Yes | Yes | No | Yes |
| Share files | Yes | Yes | No | No |
| Manage people and teams | Yes | Yes | No | No |
| Manage custom roles | Yes | Yes | No | No |
| Change enabled modules or security policy | Yes | No | No | No |
| Grant external connections or configure optional suggestions | Yes | No | No | No |
The table describes built-in roles. Record scope still applies to each action. File access does not grant access to a linked financial record.
Only the owner can enable or grant external client connections. Active staff with built-in or custom roles can be delegates. Their current permissions still apply. Approval tools need invoices.finalize; client issuance also checks invoices.manage and invoice access. See Agent connections.
Custom roles
Owners and admins use Settings > Roles to select permitted actions. Custom roles cannot grant settings.manage or users.manage. Built-in roles cannot be edited. A custom role needs a unique name and at least one permission.
Changing a role signs out its holders and stops their existing external credentials. A role cannot be deleted while users or pending invitations use it.
Guest scope
A guest uses Accountant, Employee or a custom role. Owner and Admin cannot be guests. Select permitted modules, then named customers or engagements when needed.
Named records narrow access. Without named records, the selected modules expose the records allowed by the role. A scope never grants a missing permission or access to a disabled module. Guests cannot hold agent connections. Changing the scope signs out the guest.
Need help with the product?
Contact support