The Owner Is Not Just the Biggest Admin.

Some actions are structural rather than operational, and they stay with one person.

Only the Owner can

  • Invite, edit or remove another Admin.
  • Change the plan or manage billing.
  • Transfer ownership of the business.
  • Change the base currency.
  • Close the account.

Why it is drawn there

These are the actions that change who controls the business, rather than how it runs day to day.

Because Admin management sits outside every Admin profile, no Admin can quietly widen their own access or appoint someone who would. Transferring ownership requires the Owner to re-enter their password and is recorded.

Four Admin Profiles, and What Each One Reaches.

An Admin is not one permission set. The profile decides which slice of the business that person can work in, and the differences are real rather than cosmetic.

What each role can do, as enforced by the application
Role Run delivery Manage the team Client records and portal Client money and invoicing Team pay and payouts Cost on the work
Owner Plus the things only an Owner can do: invite or remove Admins, change the plan, transfer ownership. Yes Yes Yes Yes Yes Yes
Full Admin Everything except the Owner-only actions above. Yes Yes Yes Yes Yes Yes
Operations Admin Runs delivery on Engagements that already exist. Cannot create Clients or Engagements. Yes Yes No No No Yes
Finance Admin Owns the money on both sides. Cannot assign work or change the team. No View only View only Yes Yes Yes
Client Admin Owns the client relationship and the portal. Never sees what the team is paid. No No Yes View only No No
Checker Reviews work and sees their own earnings. View only No No No No No
Assistant Does the work and sees their own earnings. Yes No No No No No

Run delivery covers creating, editing, submitting, reviewing and delivering Tasks. A Checker reviews and delivers but does not create work; an Assistant creates and submits but does not review. Cost on the work means pending, approved and paid cost on the Engagements a person works on, which is a separate permission from seeing what any individual has earned across the business.

Assistants Do the Work. Checkers Check It.

An Assistant creates, edits and submits Tasks, and can log work that was not planned. A Checker reviews what has been submitted and decides whether it is ready.

Both see their own earnings and their own advances, and neither sees anybody else's. Keeping the person doing the work and the person checking it as separate roles is what makes review mean something.

A Permission Is Not the Same as Access to a Record.

Permission + Resource Authorization = Allowed Action

Holding the permission to review work does not let someone review any submission in the business. It lets them review the ones they are the Checker on.

Both checks run on the server, on every action. A button that is not shown is not shown because the check already failed, not instead of it.

Set the Team Once Per Engagement.

Each Engagement can name a Primary Assistant and a Default Checker, and every Task created in it starts with both already chosen. The routine case needs no decision, and the exception is still one click away.

On plans that include it, an Engagement can carry additional team members beyond those two, for work that genuinely needs more hands.

People Change. History Should Not.

Someone can turn down an assignment with a reason, which flags the Task for a decision rather than leaving it stuck. Reassigning it keeps everything the previous person did: what they were assigned, what they submitted, how it was reviewed.

Team members are deactivated, never deleted. Access ends immediately, and the record of their work stays intact.

What Your Plan Affects.

Full Admin is available on every plan, because a business with one Owner and one deputy needs a deputy. The three specialised profiles, Operations, Finance and Client Admin, come with the plans built for splitting responsibilities across several people.

Seat limits work the same way: Admin seats and team seats are counted separately, and the Owner is never one of them. Moving to a smaller plan stops new growth rather than deleting anyone.

Access Changes Are Recorded.

Role changes, profile changes, deactivations and ownership transfers are written to the audit trail with who did it and when.

Sessions are revalidated against the database on every request rather than trusted until sign-out, so removing someone's access takes effect on their next click, not their next login.

Questions About Roles and Access

No. Inviting, editing and removing Admins are Owner-only actions, and they are absent from every Admin profile including Full Admin. An Admin cannot promote a colleague, cannot change their own profile, and cannot appoint another Admin.

No. They can see what the work they run is costing on the Engagements they work on, because that is part of running delivery. Seeing an individual worker’s earnings or the payout book across the business is a separate permission they do not hold.

No. A Finance Admin can read Tasks for context, but cannot assign, review or deliver them, and cannot change team memberships. They own compensation, payouts, client billing and invoicing.

Not today. There are four Admin profiles plus Assistant and Checker. A configurable per-Admin permission builder is a planned capability, not a current one.

Their access ends and their history stays. People are deactivated rather than deleted, so every Task they worked on, every submission and every review they made remains attached to the record. Removing a person never removes what happened.

Admin seats count active Admin memberships and team seats count active Assistant and Checker memberships. The Owner is never counted as a seat. There is no seat category for Client Portal users.

No. There is no SSO, no SCIM and no directory sync. People are invited by email and set their own password.

Delegate the Business Without Giving Everyone the Whole Business.

Hand each person the slice of the operation their job needs, and keep the rest where it belongs.