Who this is for. Everyone.
Which roles exist, what each one can reach, and where reaching a screen differs from being able to change what is on it. Use it to answer “should this person be able to do this”, and to tell a permission problem apart from a feature that is switched off.
Two gates, not one. A surface appears only when your role carries the permission and the tenant has the feature enabled, so two colleagues on the same tenant can meet different rails.
The roles
Read each row as a boundary. Covers is the part of the product the role works in, and What they own is the responsibility it carries there, which for some roles stops at reading the configuration.
Table 1. The roles used in this guide
Role |
Covers |
What they own |
|---|---|---|
Super Admin |
The whole tenant. |
Connections, users and roles, tenants, audit logs. |
ProcureToPay Manager |
AP Invoices and AP Helpdesk. This role carries permissions across both products. |
The rules and thresholds the agent works by for either function: document intake, extraction, business rules and Write to SOR for AP Invoices; sender classification, categories, processing rules and task behavior for AP Helpdesk. Only a Super Admin can view or edit that configuration. ProcureToPay Agent AP Invoices and AP Helpdesk, at working level. Working invoices and tasks. |
AP Helpdesk Manager |
The helpdesk function only. |
Sender classification, categories, processing rules, task and SLA behavior. |
AP Helpdesk Specialist |
The helpdesk function, without the manager’s reporting scope. |
The same day-to-day helpdesk work as a manager, including creating and editing records. |
AP Helpdesk Analyst |
The helpdesk queue. |
Clearing tasks, working mail, checking records. |
SmartResearch Analyst |
SmartResearch and Metrics Studio. |
Granted in addition to an AP role. |
There is no single “AP Manager” role. Where a reader would expect one, the product uses ProcureToPay Manager for work spanning AP Invoices and AP Helpdesk, and AP Helpdesk Manager where only the helpdesk function is involved. This guide uses the role names as they appear in the product.
One person can hold several roles. Where they do, the role name in the account menu becomes a switcher and they choose which one they are acting as; someone with a single role sees the name but no alternatives. Roles are listed in Administration > User Management, which also carries a separate Team Roles column. Team membership is tracked independently of the role.
What each role sees in the queue
Access is about more than which screens open. Two roles can open the same screen and see different rows.
Role |
Rows returned on cards and review tasks |
|---|---|
Super Admin |
Everything in scope. No row filter. |
ProcureToPay Manager |
Everything in scope. No row filter. |
AP Helpdesk Manager |
Everything in scope. No row filter. |
AP Helpdesk Analyst |
Only tasks assigned to them, plus tasks with no assignee. |
This is why a manager and an analyst can report different counts for the same view. Before treating a discrepancy as a data problem, compare the two roles in Administration > User Management. An analyst is returned only their own tasks and tasks with no assignee, so a lower count from an analyst is the expected result.
Which screens each role can open
Available means the area is reachable for that role. Read only opens a screen without allowing any change. View only shows the data without the controls that change it. No access means the entry never appears.
Table 2. Access by area
Area |
ProcureToPay Manager |
AP Helpdesk Manager |
AP Helpdesk Analyst |
|---|---|---|---|
Homepage |
Available |
Available |
Available |
Agent Co-workers |
Read only |
Read only |
Read only, and no rail entry |
SmartVendor console |
Available |
Available |
Available |
AP Helpdesk |
Available |
Available |
Available |
AP Invoices |
Available |
No access |
No access |
Settings |
Available |
Available |
View only |
SmartVendor record tabs |
Available |
Available |
Available |
SmartResearch |
Only with SmartResearch Analyst |
Only with SmartResearch Analyst |
Only with SmartResearch Analyst |
System Settings |
View only |
View only |
View only |
User Management |
No access |
No access |
No access |
Team Management |
No access |
No access |
No access |
Tenant Management |
No access |
No access |
No access |
Audit Logs |
View only |
View only |
No access |
A missing rail entry and a blocked screen are not the same thing. Some areas are hidden from the navigation rail for a role but still open if the reader follows a direct link, in read-only form. Agent Co-workers behaves this way for AP Helpdesk Analysts and Specialists: no rail entry, but the list of agents opens and shows their status. Treat the rail as the supported route, not as the boundary.
Super Admin is not enumerated. The role definitions grant permissions to the other roles explicitly; Super Admin reaches everything in the tenant, so the table lists only the roles where access differs. Available means the screen is reachable, not that every action on it is permitted.
Reaching a screen is not the same as changing what is on it. Agent Co-workers is the clearest case: a manager can open the Agent Co-workers list and see every agent and its state, but cannot open the setup wizard at all. Following a direct link to it returns them to the homepage.
Owning a setting and being able to change it are different things. A manager is accountable for what sender classification, email categories and processing rules say, and is the person to ask when they are wrong. Making the change is a Super Admin action: the Agent Co-worker wizard does not open for any role except Super Admin, and AP Intelligence does not open for the AP Helpdesk roles at all. Where this guide says a role owns a setting, it means the decision, not the permission.
This table describes the shipped defaults. Roles are configurable, so your tenant may grant more or less than shown. The authority is the role assignment in User Management.
If you are a Super Admin
You own everything an agent depends on but do not normally configure agents yourself.
What Administration Covers
If you are a ProcureToPay Manager or AP Helpdesk Manager
You own the rules and thresholds the agent works by, and answer for what it produces. Changing the Agent Co-worker configuration itself is a Super Admin action; no other role can view or edit it.
If you are an AP Helpdesk Analyst
You work the exception queue and the mail behind it.
When access looks wrong
Table 3. Diagnosing access
Symptom |
Check first |
|---|---|
One person cannot see a screen |
Their role assignment in User Management. |
Nobody can see a screen |
The tenant’s feature enablement, not the role. |
A screen opens but an action is missing |
The action-level permission on the role, such as CREATE or UPDATE. |
An agent cannot write to the system of record |
The integration user’s permissions in the connected system, not the AP role. |
Related information
User Management