Roles and Access

Who this is for. Everyone.

Which roles exist, what each one covers, and why two people looking at the same screen can see different numbers. Use it to answer whether someone should be able to do something, and to tell a permission problem apart from a feature that is switched off.

Two gates, not one. A surface appears only when your role carries the permission and your tenant has the feature enabled. Two colleagues on the same tenant can meet different menus.


The roles

Read each row as a boundary. Covers is the part of the product the role works in, and What they own is the responsibility it carries there, which for some roles stops at reading the configuration.

Table 1. The roles used in this guide.

Role

Covers

What they own

Super Admin

The whole tenant.

Connections, users and roles, tenants, and audit logs.

ProcureToPay Manager

AP Invoices and AP Helpdesk. This role carries permissions across both products.

The rules the agent works by for either function. Only a Super Admin can edit tenant configuration.

AP Helpdesk Manager

The helpdesk function only.

Sender classification, intents and outcomes, email templates, and task behavior.

AP Helpdesk Specialist

The helpdesk function, without the manager’s reporting scope.

The same day-to-day work as a manager, including creating and editing records.

AP Helpdesk Analyst

The helpdesk queue.

Clearing tasks, working mail, and checking records.

There is no single AP Manager role. Where you would expect one, the product uses ProcureToPay Manager for work spanning AP Invoices and AP Helpdesk, and AP Helpdesk Manager where only the helpdesk function is involved. This guide uses the role names as they appear in the product.

One person can hold several roles. Where they do, the role name in the account menu becomes a switcher and they choose which one they are acting as. Someone with a single role sees the name but no alternatives. Roles are listed in Administration > User Management, which also carries a separate Team Roles column, because team membership is tracked independently of the role.


What each role sees in the queue

Access is about more than which screens open. Two roles can open the same screen and see different rows.

Table 2. Rows returned by role.

Role

Rows returned

Super Admin

Everything in scope. No row filter.

ProcureToPay Manager

Everything in scope. No row filter.

AP Helpdesk Manager

Everything in scope. No row filter.

AP Helpdesk Analyst

Only tasks assigned to them, plus tasks with no assignee.

This is why a manager and an analyst can report different counts for the same view. Before treating a discrepancy as a data problem, compare the two roles. An analyst is returned only their own tasks and unassigned tasks, so a lower count from an analyst is the expected result, not a fault.


Record Access Control

Record Access Control restricts which records a user can reach, separately from their role. Where it is enabled, it is aligned to entitlements in your ERP, so two users holding the same AP Helpdesk role can still see different vendors, bills, and payments.

Role decides which actions are available. Record Access Control decides which records those actions apply to. When a record a colleague can see does not appear for you, check Record Access Control before checking the role.


Where roles are managed

Roles are assigned in Administration > User Management by a Super Admin. Changes to roles and team assignments are recorded in the audit log.


Related information