Skip to content

Team permissions

Apply workspace and legal-entity-aware permissions without trusting client-supplied roles or ownership claims.

Access controlsSample company

Viewer

Requests a protected change

Permission check

Change blocked

Authorized role required

Who may view, prepare or approve this work?

Financial control weakens when access, identity, audit evidence, and sensitive actions are governed by informal assumptions rather than explicit workspace policy.

Least privilege
Giving a person only the access needed for their responsibilities.
What it works with
Trusted workspace membership, role, granular permissions and Legal Entity restrictions.
What you get
Server-enforced access appropriate to the user's authority, not claims supplied by the browser.

How the work progresses

Who uses it

Workspace owners and authorized administrators assigning access and reviewing sensitive activity.

  1. Resolve authoritative workspace membership and role.
  2. Apply the supported granular and Legal Entity restrictions for the responsibility.
  3. Check permission at the protected action; browser-provided roles do not authorize it.

A concrete example

Illustrative, not customer data.

Who may view, prepare or approve this work?

A viewer inspects an allowed report but cannot approve accounting work. The protected action checks permissions again on the server.

Explore the sample company

What still needs judgment

Controls support a customer's security program but do not by themselves guarantee compliance. SCIM and service-account public pages are intentionally omitted because general availability is unconfirmed.

AI cannot grant permissions, enforce identity policy, erase audit history, disclose credentials, or bypass security controls.

Available workflows depend on your plan, permission scope, configuration and supported data. Compare plans before choosing.

Before you use team permissions

Can I explore this before connecting company data?
The public demo is a fixed, read-only sample company. It illustrates supported product areas without creating an account or accessing customer data; it is not proof that every configured workflow is available in the tour.
What should I verify before relying on an output?
Confirm scope, source coverage and timing. For this capability, review trusted workspace membership, role, granular permissions and Legal Entity restrictions. An operating status or AI explanation does not replace the required review of accounting evidence.
Does an explanation automatically authorize a financial action?
No. AI cannot grant permissions, enforce identity policy, erase audit history, disclose credentials, or bypass security controls.

Continue the workflow

See the work in context.

Explore a read-only sample company, or start with your own supported data.