Skip to main content

User roles, and what each one can do

A
Written by Andy

When you invite someone, the Role dropdown decides what they can do once they are in. There are five built-in roles, and the dropdown defaults to Preparer.

Picking a role is not permanent. You can change it from the Users tab any time, so start with the closest fit rather than agonizing over it.


The five roles, shortest version

Role

Use it for

Technical Admin

Whoever runs the firm's IT. Everything, including SSO, MFA, API keys, webhooks, and sessions.

Manager

Partners and practice leaders. Everything except the technical and security setup.

Preparer

The people doing the work. Add, import, and edit assets, run depreciation, take elections.

Reviewer

Someone who checks work without changing it. Look, recalculate, sign off.

Read-Only

Anyone who needs visibility and nothing else.


Where to see exactly what each one grants

Go to Settings → Users & SSO → Roles. The Built-in roles card lists all five with the number of permissions each carries.

The Roles tab in Settings, showing the Built-in roles card listing Technical Admin with 25 permissions, Manager with 20, Preparer with 10, Reviewer with 5, and Read-Only with 2

There are 25 permissions in total, grouped into seven areas: Assets & data entry, Depreciation & elections, Review (maker-checker), Reports & exports, Users & access, Firm settings & billing, and Technical & security.


Technical Admin

All 25 permissions. It is the only built-in role that can:

  • Configure single sign-on (SSO)

  • Set the firm MFA policy

  • Manage API keys

  • Manage webhooks

  • View sessions and force sign-out

Those five are the entire difference between Technical Admin and Manager. If nobody at your firm needs them, you do not need a second Technical Admin.


Manager

Everything a Technical Admin can do, minus those five technical items. A Manager can invite and deactivate users, assign roles and build custom roles, grant and revoke client access, manage firm settings and tax defaults, manage billing and seats, view the audit log, export firm data, and reopen a return that has already been reviewed.

This is the right role for a partner who runs the practice but does not want to be the person configuring SSO.


Preparer

The default, and the role most of your team should have. A Preparer can:

  • Create, edit, delete, and import assets

  • Run depreciation

  • Override Section 179 and bonus elections

  • Mark a return ready for review, and mark a return reviewed

  • View and run reports

A Preparer cannot invite users, change firm settings, touch billing, or reopen a return once it has been marked reviewed.


Reviewer

Built for firms that want the person checking the work to be a different person from the one who did it. A Reviewer can view everything, run depreciation, override Section 179 and bonus elections, mark a return reviewed, and run reports.

A Reviewer cannot create, edit, delete, or import assets, and cannot mark a return ready for review. That step belongs to whoever prepared it.


Read-Only

Two permissions: view clients, entities, returns and assets, and view and run reports. Nothing else. A Read-Only user changes nothing anywhere in the product.

Note that the firm-wide data export under Settings → Data Export is a separate permission that Read-Only does not have. It sits with Technical Admin and Manager.


Changing someone's role later

On Settings → Users & SSO → Users, each row has a Role dropdown. Change it there and it takes effect immediately. Manage access on the same row is the other route to it.

Two rules the product will enforce for you:

  • You cannot grant a role that holds permissions you do not hold yourself. A Manager cannot create a Technical Admin. If you try, you get "You cannot assign a role with capabilities you don't hold yourself."

  • You cannot remove the last person who can manage users. Give someone else that ability first.


Two things the role does not decide

Which clients someone sees. That is the firm's client access mode, set separately on the Users tab and managed per person through Manage access. Role answers "what can they do," client access answers "to whose work."

Whether they cost you a seat. Every user you invite takes a seat regardless of role, so a Read-Only user costs the same as a Technical Admin. The seat count sits at the top of the Users tab.


When none of the five fit

New custom role on the Roles tab lets you pick permissions individually, from the same 25. Most firms never need one. Reach for it when you want a specific mix the presets do not offer, like a preparer who can also onboard clients.

Did this answer your question?