A permission profile is a reusable set of permissions that you configure once and then assign to several employees. Think of profiles like Sales, Invoicing or Warehouse.
Instead of ticking all the boxes again for every new colleague, you simply assign the right profile. If you change a profile later, that change applies immediately to everyone who has it.
💡 Tip: Permission profiles only apply to users with the Employee role. An Admin has access to everything anyway.
An employee’s permissions are the sum of all profiles you assign to them. If someone has the profiles Sales and Warehouse, that person gets everything ticked in both profiles.
You no longer grant individual extra permissions per user. If one employee needs something extra, create a profile for it. That keeps your permission management clear and auditable.
ℹ️ Good to know: Employees who already had permissions before permission profiles were introduced may still have manually granted permissions. You recognise them by the Custom permissions label in the user list. Those permissions apply on top of their profiles.
Permission profiles depend on your subscription. If the module isn’t included in your plan, you can add it as an add-on. As long as the module is not active, employees only get access to the mobile app.
You can also get there via the tab bar at the top of the settings pages, next to Users.
You see an overview showing each profile’s Name, Description and the number of assigned Permissions.
How that matrix works exactly is covered in Setting permissions per module.
Is the profile you need not there yet? Use the + Create a new permission profile link in that same screen.
💡 Tip: Work from small to large. Start with a profile that only grants read permissions and add permissions only when a colleague runs into a limit.
Go to Permission profiles and click the pencil icon next to the profile to edit it, or use the three-dot menu to delete it.
⚠️ Please note: Editing a profile immediately changes the permissions of all employees who have that profile. Deleting a profile means those employees lose the permissions that ran only through it.
| Profile | Typical permissions |
|---|---|
| Sales | Read, create and update clients; manage quotes with View prices; read products |
| Invoicing | Fully manage and export invoices, credit notes and payments, with View prices |
| On-site | Enter time and production registrations without View prices; read projects |
| Accounting | Read and export everything with View prices, create or change nothing |
💡 Tip: In most modules, a profile without View prices can only read. If you want someone to create purchase orders, for example, they also need to be able to see the amounts. Exception: time and production registrations can be entered without prices. More on this in Setting permissions per module.
For more about roles and adding users, see Can I add multiple users to my account?