Understand roles and access
Clerked separates what a person can do from which company data they can see. This keeps roles reusable without giving every person who shares a role the same visibility.
The six getting-started guides describe common job personas, not six more roles. AP Specialists, Approvers, and Auditors have guides that line up with built-in company roles. The AP Manager, Controller and Finance Manager, and CFO guides describe ways people may work in Clerked, so an administrator still assigns one of the built-in or custom roles described below. In particular, AP Manager and CFO are not built-in role names.
The five parts of access
Every user has:
- A primary role for organization-level actions.
- One company role for each company they can use.
- An invoice access setting for each company.
- An inbox access setting for each company.
- An Insights access setting for each company, when the role includes Insights.
For example, one person can be an organization Member, a Controller in the parent company, and an AP Specialist in a subsidiary. Their invoice, inbox, and Insights access can differ between those companies.
Primary roles
| Role | What it covers |
|---|---|
| Administrator | Organization administration, invitations, member changes, role management, and all company actions. |
| Member | Sign-in identity only. Company assignments provide company access and actions. |
An active primary Administrator who has no explicit assignment for a company inherits Administrator access to that company. If an explicit company assignment exists, that assignment controls the person's company role, invoice access, inbox access, and Insights scope.
Company roles
Five built-in roles cover common AP jobs. Built-in roles are read-only. Administrators can clone one into a custom role and choose a different set of action permissions.
Administrator
Has every company permission. Administrators can process invoices, manage people and settings, configure policies and validation, and manage Agents. Changing a user's company assignment still requires the separate primary member-update permission.
Controller
Runs AP operations. Controllers can process, approve, delete, restore, hold, cancel, and export invoices. They can also manage approval policies, validation checks, fields, Agents, and Agent Memories. They cannot administer organization members or primary roles unless their primary role grants that access.
AP Specialist
Owns invoice intake and review. AP Specialists can create, upload, edit, validate, approve, reject, delete, restore, hold, resume, cancel, and export invoices. They can override validation and approval routing by default.
Approver
Reviews invoices routed to them and approves or rejects those invoices. Approvers can edit, validate, hold, resume, or cancel invoices allowed by schema state, read Agent Memories, and manage their own approval delegation. They cannot upload, delete, or reroute invoices by default.
Auditor
Has read-only access to invoices, approval histories, settings, ERP data, emails, Agent Memories, and Clerked Agent when the company capability is on. The role editor still names that permission Use Mod Agent. Auditors do not receive Insights by default and cannot change records.
Default action matrix
| Action | Administrator | Controller | AP Specialist | Approver | Auditor |
|---|---|---|---|---|---|
| View invoices | Yes | Yes | Yes | Yes | Yes |
| Create or upload invoices | Yes | Yes | Yes | No | No |
| Edit invoices | Yes | Yes | Yes | Yes | No |
| Validate invoices | Yes | Yes | Yes | Yes | No |
| Delete or restore invoices | Yes | Yes | Yes | No | No |
| Override invoice routing | Yes | Yes | Yes | No | No |
| Approve or reject invoices | Yes | Yes | Yes | Yes | No |
| Manage approval policies | Yes | Yes | No | No | No |
| Manage validation checks | Yes | Yes | No | No | No |
| Manage Agents | Yes | Yes | No | No | No |
| Manage Agent Memories | Yes | Yes | Yes | No | No |
| View Insights | Yes | No | No | No | No |
| Manage company settings | Yes | No | No | No | No |
This table describes built-in action permissions. A custom role can use any valid combination from the role editor.
Invoice and inbox access
Invoice and inbox access are two independent parts of the person's company assignment, not role permissions.
| Setting | What the person can see for that resource |
|---|---|
| All | Every invoice or inbound email in that company, plus its inherited surfaces. |
| Assigned | Only invoices or inbound emails assigned through the canonical workflow participation paths, plus inherited surfaces. |
The invitation form shows separate Invoice access and Inbox access controls. Administrator, Controller, and Auditor default to All for both. AP Specialist, Approver, and custom roles default to Assigned unless their role declares different defaults. An administrator can choose either scope independently when assigning access.
Insights access
Insights has a separate access setting because a plant manager may need company-wide invoice and inbox work but only one plant's spend metrics, or the reverse.
| Setting | What Insights includes |
|---|---|
| All company data | Metrics across the selected company. |
| Restricted by dimension | Metrics limited to selected values from one configured dimension, such as Plant. |
Restricted Insights access supports 1 to 50 values from one schema-defined dimension. It changes Insights metrics only. It does not change which invoices or emails the person can open.
A person also needs the company:insights:view permission through their company role. If the role does not include it, the Insights navigation item stays hidden even when an Insights scope exists.
Custom roles
Custom roles define action permissions and suggested defaults for new invoice and inbox assignments. Each person's company assignment stores the effective invoice, inbox, and Insights scopes, so changing a role's defaults does not silently rewrite existing access. Once a member or pending invitation references a custom role, duplicate it to change permissions; descriptive information and defaults can still be edited.
Open Settings, select Organization, then select Roles & permissions to review both company and organization roles or create a custom role. See Configure roles and permissions.
How access gets assigned
An administrator sets the complete company assignment when inviting a person or changing existing access:
- Company role.
- Invoice access.
- Inbox access.
- Insights access, including a dimension and values when access is restricted.
One invitation can include separate assignments for multiple companies. To change an existing user's company assignment, open Settings, select Company, select People, open the linked person, and select Change access.
You cannot change your own assignment. Ask an administrator if you need a different role or data scope.
What the navigation shows
Clerked hides navigation items when you do not have the required permission. It does not show unavailable sections with lock icons. The API also checks the same action and data scope, so hiding a control is not the security boundary.
Some companies enable a focused restricted approver mode for approval-scoped users. That mode narrows the invoice list and removes unrelated navigation while the company setting is active.