# Users, roles and permissions

> Add team members, choose Owner, Admin, Member or Viewer, fine-tune individual permissions, suspend or remove users.

Canonical: https://docs.getonebooks.com/settings/users-roles/
Language: en
Documentation index: https://docs.getonebooks.com/llms.txt

**Settings → Users & Permissions** (owners and admins) controls who can sign in to your business and what they may do. Every action in OneBooks — and every AI tool — checks the same permissions.

![The Users & Permissions page listing team members with their roles](https://docs.getonebooks.com/screenshots/en/settings-users.webp)

## Roles

| Role | Can |
|---|---|
| **Owner** | Everything, including billing and managing users. One per business; cannot be removed. |
| **Admin** | Everything except owner-only settings such as billing. |
| **Member** | Day-to-day work: create customers, suppliers, items, invoices, quotes, purchases, returns, expenses and bank reconciliation. Cannot record payments, void, delete, write off, change settings or manage users unless granted. |
| **Viewer** | Read-only: every list, document and report, no changes. |

## Add a user

1. Select **Add user**.
2. Enter the person's **name**, **email**, an initial **password** (at least 12 characters; they can change it) and pick a **role**.
3. Select **Save**. Share the sign-in details with them.

![The Add user dialog with name, email, password and role](https://docs.getonebooks.com/screenshots/en/settings-users-invite.webp)

## Fine-tune permissions

Open a user to **grant** or **revoke** individual permissions on top of their role — for example allow a member to **record payments** or **void invoices**. Nobody can grant a permission they do not hold themselves.

![A user's permission overrides listed by area](https://docs.getonebooks.com/screenshots/en/settings-role-permissions.webp)

## Suspend or remove

**Suspend** blocks sign-in without deleting history; **Delete** removes the user from the business. Documents they created stay.

## Where permissions apply

- Every screen and action in the app.
- The **AI assistant** and connected agents: a viewer gets read-only answers; proposals are checked again when confirmed.
- Connected apps act with the permissions of the user who authorised them.

## Related

  - [Safety, privacy and limits](https://docs.getonebooks.com/ai/safety/)
  - [Security and privacy](https://docs.getonebooks.com/reference/security-privacy/)
