# Users and Roles

Inviting somebody into Inventory, building the role that decides what they may open, and the custom fields on a user preference.

Access to Inventory is granted in two pieces: a user is somebody who can sign in, and a role is the list of things they may do once they are in. **Access Inventory** explains how roles behave across apps; this page is the screen that edits them.

Go to **Settings > Users & Roles**. Three tabs: **Users**, **Roles** and **User Preferences**.

## Users

The people who can open Inventory, with the role each of them holds.

- **Go to Settings, Users & Roles.**
- **Select Invite User.**
- **Enter their first name, last name and work email address.**
- **Choose a role.**

  The roles offered are the ones on the Roles tab. Somebody invited with no role signs in and finds an empty menu.
- **Select Invite User to send the invitation.**

  They join the workspace by following the link in the email.

The three-dot menu on a row edits the person's name and role, or makes them inactive. An inactive user keeps their history and stops being able to sign in.

## Roles

A role has a name, a description, and a permission for everything the app can do.

![The Roles tab of Users & Roles in Inventory Settings, headed Roles above the line Define roles and the permissions granted to users assigned to them, with a blue Role button at the right. A table with columns ROLE, SCOPE, DESCRIPTION and ACTIONS lists roles carrying Admin and System badges, each showing the app its scope covers and a short description.](https://www.sorviai.com/help/inventory/settings/users-roles.png)

*Scope is the column that matters: a role scoped to one app says nothing about another.*

*The role form on the Roles tab*

> **Note:**
>
> **Settings are granted section by section**
>
> Giving somebody Taxes does not give them Organisation. A role holding any section at all can open the gear, and the rail it finds is filtered to what it holds.

> **Warning:**
>
> **Editing roles cannot be delegated**
>
> Users can be granted to a role; Roles cannot, because granting role editing is granting the power to grant. Somebody who may manage users but not roles opens this screen without the Roles tab.

System roles are marked as such on the list and are not editable. Build your own beside them rather than trying to bend one.

## User Preferences

Custom fields on the user preference record, added the same way custom fields are added anywhere in Inventory. It is a field-customisation screen, not a second place to manage people.
