# Users and Roles

Inviting somebody into Finance, building the role that decides what they may open, and the custom fields on a user preference.

Access to Finance is granted in two pieces: a user is somebody who can sign in, and a role is the list of things they may do once they are in. **Access Finance** explains how roles behave across apps; this page is the screen that edits them.

Go to **Settings > Finance > Users & Roles**. Three tabs: **Users**, **Roles** and **User Preferences**.

## Users

The people who can open Finance, with the role each of them holds.

- **Go to Settings, Finance, Users & Roles.**
- **Select Invite User.**
- **Enter their first name, last name and work email address.**
- **Choose a role.**

  The roles offered are the ones on the Roles tab. Somebody invited with no role signs in and finds an empty menu.
- **Select Invite User to send the invitation.**

  They join the workspace by following the link in the email.

The three-dot menu on a row edits the person's name and role, or makes them inactive. An inactive user keeps their history and stops being able to sign in.

## Roles

A role has a name, a description, and a permission for everything Finance can do.

![The Roles tab of Users & Roles, headed Roles above the line Define roles and the permissions granted to users assigned to them, with a blue Role button at the right. A table has columns ROLE, SCOPE, DESCRIPTION and ACTIONS. Finance Admin carries an Admin badge and a System badge, scope Finance, described as Full administrative access to the Finance app. Finance Member carries a System badge, scope Finance, described as Day-to-day Finance operations. Platform Admin carries Admin and System badges, scope Platform-wide, described as Full administrative access.](https://www.sorviai.com/help/settings/users-roles.png)

*Scope is the column that matters: a Finance role says nothing about any other app.*

*The role form on the Roles tab*

> **Note:**
>
> **Settings are granted section by section**
>
> Giving somebody Taxes does not give them Organisation. A role holding any section at all can open the gear, and the rail it finds is filtered to what it holds.

> **Warning:**
>
> **Editing roles cannot be delegated**
>
> Users can be granted to a role; Roles cannot, because granting role editing is granting the power to grant. Somebody who may manage users but not roles opens this screen without the Roles tab.

System roles are marked as such on the list and are not editable. Build your own beside them rather than trying to bend one.

## User Preferences

Custom fields on the user preference record, added the same way custom fields are added anywhere in Finance. It is a field-customisation screen, not a second place to manage people.
