Roles and permissions
Console roles control the company. Workspace roles control each module.
Console roles
Owner: full control of the company, including billing.
Admin: manage users and workspaces.
Billing admin: billing only.
Viewer: read-only.
Workspace roles
Inside a workspace, a role decides which modules someone can see and whether they can edit them. Every workspace starts with a set of default roles for its type, and admins can create their own.
Set roles up in the workspace's settings, or start from the templates under Console → Users & Access → Roles.
Permissions are per module, usually View or Edit, with finer controls where they matter, such as documents or payments.
Someone with view-only access sees the information but can't change it.
Start from the default roles, and only create your own when someone needs something different.