Skip to main content

Roles and permissions

How access works in aOS: three roles, seven permissions, tool access, and client scope.

Access in aOS is built from four separate things. Understanding them as separate is the key to setting someone up correctly, because changing a person's role doesn't change what they can see.

1. Role

Every user is an owner, an admin, or a member.

Owners and admins have every permission automatically. You don't grant them individually and you can't take them away without changing the role.

Members start with nothing beyond basic access, and you build up what they can reach using the permissions below.

2. Permissions

Seven switches, each granted per user. They only matter for members, since owners and admins already have all of them.

  • View team rates — see what your team costs

  • Edit team rates — change those figures

  • View client billing — see what clients are charged

  • View agency financials — see Agency Analytics and your own books

  • Manage integrations — connect and disconnect data sources

  • Manage team — invite people and change their access

  • Manage org settings — change organization-wide settings

The two worth being deliberate about are View agency financials and View team rates. Those expose your margins and what you pay people, which is usually a narrower group than everyone who needs to use aOS day to day.

3. Tool access

Separately from permissions, each tool can be switched on or off for the organization and for individual users.

This is why someone can be a fully trusted admin and still not see Time Tracker — the tool isn't enabled for them. If a colleague says a section is missing rather than locked, tool access is almost always the reason.

4. Client scope

A member sees either all clients or only assigned clients.

All clients is the default. Switching someone to assigned means they see only the clients they're linked to, which is useful when account managers shouldn't see each other's books of business.

Assigning clients to people is separate from this setting — the setting decides whether the restriction applies at all.

Inviting someone

Go to Settings → Team and send an invite. You'll set their name, email, role, and permissions at the point of invitation, so they arrive with the right access rather than needing it fixed afterwards.

An email can only belong to one organization. If the invite is rejected because the person is already a member, they already have an account with you.

Working out why someone can't see something

Check in this order, because each one can mask the others:

  1. Is the tool enabled for them? A missing section, rather than a locked one, points here.

  2. Do they have the permission? Agency Analytics needs View agency financials; connecting a data source needs Manage integrations.

  3. Is their client scope limited? If they can see the tool but not a particular client's data, they're probably on assigned scope and not linked to that client.

Changing someone's access

Settings → Team, open the person, and adjust. Changes apply the next time they load the page.

Promoting a member to admin grants all seven permissions at once. Demoting them back to member does not restore whatever they had before, so it's worth noting their previous setup first if you might reverse it.

Did this answer your question?