Add a user
Users → New (or the Invite your team checklist step). Enter the e-mail and name; the person receives a link to set a password (or signs in with your organization's SSO).
Roles decide what people can do
Every app comes with roles, for example Accounts User / Accounts Manager, Sales User, Projects User, HR User, Stock User. Give people the roles for their work — they then see the matching apps in the launcher and can only open the records those roles allow.
- Role profiles bundle roles for a job ("Accountant", "Site engineer").
- User permissions restrict a person to particular companies, projects, customers or warehouses.
- The display mode (Simple / Advanced) only changes what is shown; it never grants permission. Settings, roles and the "All tools" groups appear in Advanced for administrators only.
Seats
Your subscription includes a number of seats. Apps & subscription shows who uses them:
| Group | Takes a seat? |
|---|---|
| Active users (have signed in) | Yes |
| Invited users (not signed in yet) | Yes |
| Disabled users | No |
| Service accounts (integrations, API) | No |
| System accounts | No |
Adding an enabled user when every seat is in use is refused; disable someone or request more seats from Apps & subscription → Add seats.
Removing access
Disable the user instead of deleting it. A disabled user cannot sign in and frees the seat, but everything they created stays, with their name in the history. With SCIM (see Sign-in, SSO and two-factor authentication), people removed in your identity provider are disabled automatically.