Team members, roles and permissions
Invite staff, assign roles and tune permissions so your accounting team sees the right clients, work items and settings in Finye.
Getting your team into Finye correctly is the foundation for everything else: work assignment, client confidentiality, billing visibility and who can change firm-wide settings. This guide walks through inviting team members, choosing the right role for each person, and refining permissions so staff see exactly what they need and nothing they should not.
Before you start
Decide who in your practice needs access and what they do day to day. A typical Australian firm has a principal or partner, senior accountants, graduates or bookkeepers, and an administrator who manages billing and onboarding. Mapping people to responsibilities first makes role selection straightforward.
Inviting a team member
You add staff by sending an email invitation. Each person sets their own password, so you never handle their credentials.
- Open Settings and choose Team (or Users).
- Select Invite member.
- Enter the person's name and work email address.
- Choose a role from the list (see the next section).
- Send the invitation. The person receives an email with a secure link to set their password and sign in.
Until someone accepts, their invitation shows as pending. You can resend or revoke a pending invite at any time from the same screen.
Understanding roles
A role is a bundle of permissions that sets the baseline of what a person can do. Choosing the right role first means you rarely have to adjust individual permissions later.
Administrator
Full access to the practice. Administrators manage billing and the subscription, invite and remove team members, change branding and theming, configure integrations such as Xero and email-to-ticket, and adjust firm-wide settings. Reserve this for principals and your practice manager.
Staff member
Your accountants, bookkeepers and graduates. They work clients and work items, log time, raise invoices, manage compliance obligations and use the client portal and knowledge base. They do not change billing or firm settings unless you grant those permissions.
Limited or restricted access
For contractors or junior staff who should only see the clients and boards assigned to them. Use this when you want to keep visibility tight.
Refining permissions
Roles cover most needs, but you can tune what an individual or group can do. Permissions in Finye govern access to areas such as clients and contacts, work items and boards, time and WIP, invoicing and payments, the compliance engine, engagement letters, documents and AML/KYC onboarding, and the AI credit wallet.
- Open the team member's profile from Settings > Team.
- Review their assigned role and the permissions it grants.
- Toggle specific permissions on or off where the role baseline is not quite right.
- Save. Changes apply the next time the person loads that area.
Permission groups for related tasks
Some capabilities are grouped so you can grant a whole area at once rather than ticking individual boxes. For example, you might give a senior staff member administration of a specific module while leaving billing untouched. Grant these deliberately, as they widen what a person can change.
A practical example
Say you are bringing on a graduate to handle quarterly BAS lodgments. You would:
- Invite them as a staff member.
- Assign them to the relevant clients and boards so they see the right work items.
- Confirm they can view the compliance engine and log time against jobs.
- Leave invoicing approval and firm settings switched off until they are ready.
This keeps the graduate productive on lodgment work without exposing fee data or letting them change practice-wide configuration.
Removing or deactivating access
When someone leaves the practice or moves on from a contract, remove their access promptly to protect client data.
- Open Settings > Team and find the person.
- Choose Deactivate to suspend access while keeping their history, or Remove to revoke access entirely.
- Reassign their open work items to another team member so nothing falls through the cracks.
Their completed work, time entries and comments remain on the record for audit purposes even after access is removed.
Strengthening account security
To protect client financial data, enforce multi-factor authentication for the whole practice. When enforced, any staff member who has not yet enrolled is held at the two-factor setup page until they complete it, so there is no gap. You will find this under Settings > Security. Combined with role-based permissions, MFA gives you defence in depth that suits TPB obligations and good professional practice.
Good habits for managing access
- Apply least privilege. Start people on the narrowest role that lets them do their job, then add permissions if needed.
- Review quarterly. At the start of each new quarter, check who has access and confirm it still matches their role.
- Use deactivate for leave. For staff on extended leave, deactivate rather than remove so you keep their setup intact.
- Keep administrators few. Limit full administrator access to one or two trusted people.
With your team invited, roles assigned and permissions tuned, you are ready to put work in front of them. Continue with our guides on setting up work items and boards and configuring your client portal so staff and clients connect smoothly. You can browse the full series any time from the guides library.