Your Role and Access

Who this is for. Everyone. See the Roles and Access.

Several roles run an accounts payable department, and they do not see the same product. The navigation rail is filtered by the permissions on your role, so the rail shows only what your role carries.


Who owns what

If a screen or setting is missing for you, find its area here. Each row names whose permission it is.

Table 1. Who can change what

Area

Who can change it

Who can see it

System of record and mailbox connections

Super Admin

Super Admin

Users, roles and tenants

Super Admin

Super Admin

Audit logs

Super Admin

Super Admin, and managers, view only

Agent Co-worker configuration: work scope, functions, capabilities, activation

Super Admin

Super Admin Sender classification, categories and processing rules Super Admin Super Admin Task and SLA behavior Super Admin Super Admin

The exception queue

AP Helpdesk Analyst

AP Helpdesk Analyst

Agent Co-worker configuration is a Super Admin task. The whole wizard sits behind one permission check, Update on AP procurement. In the shipped role definitions no AP-side role carries it. ProcureToPay Manager and ProcureToPay Agent hold Read; AP Helpdesk Manager, Analyst and Specialist hold less again. A manager cannot open the wizard at all. What a manager can open is the Agent Co-workers list, which shows every agent and its state.

Owning a setting and being able to change it are different things. Where this guide says a role owns a setting, it means the decision, not the permission. For what each role can open and change, see the Roles and Access.


If you run the accounts payable department

You own how the accounts payable department operates and answer for what it produces. Four decisions shape everything else, and they are worth settling in this order:

Decision

What it settles

Autonomy level

How much the agent may do without a person. This is the authorization boundary; everything else operates inside it.

Sender classification

Who the agent will act on behalf of. Misclassify a sender and the agent either ignores real work or answers someone it should not.

Categories and rules

What the agent recognizes and what it does next. A category that is wrong or missing shows up later as a rule that never fires.

Task and SLA behavior

What lands in the queue, how urgent it looks, and who is accountable for clearing it.


If you work the queue

Every task exists because the agent reached a point it could not settle alone, so the task itself says something about what was missing. Work arrives like this:

  1. Mail arrives in the connected mailbox.

  2. The agent classifies the sender and the message.

  3. Rules decide what happens next: a reply, a label, a note, or a task.

  4. Anything outside the agent’s autonomy level becomes a task for you.

If the same task type keeps arriving, the fix is configuration rather than more clearing. Raise it with your manager, who decides whether the fix belongs in classification and rules or in the connection, and with a Super Admin, who makes either change.


What this means in practice

When a vendor’s mail is not recognized, the fix is in classification and rules. When the connection behind it has stopped syncing, the fix is in the connection. Telling those two apart is most of the diagnostic work; a manager decides which it is, and a Super Admin makes either change.


Related information