On Settings, the product states it plainly: Admin only — Standard users can't change settings. That is the whole permission model for the workspace.
What each role can do
| Task | Admin | Standard |
|---|---|---|
| View invoices, debtors, reminders, activity, reports | Yes | Yes |
| Chase, approve Firm/Final, work disputes and replies | Yes | Yes |
| Change business settings, defaults, notifications | Yes | No |
| Invite, change roles, archive users, transfer ownership | Yes | No |
| Issue or revoke API keys | Yes | View only |
| Halt or resume all sending (kill switch) | Yes | See status only |
Change someone's role
- Open Settings → Team as Admin.
- Find the person in the list (not the Owner badge row if you are only adjusting staff).
- Pick Admin or Standard from their role control.
- Press Save role.
The change applies on the next action they take. There are no custom roles and no per-screen permission matrix.
Owner is special
The original account is the Owner. It is an Admin who cannot be archived or demoted in place. To hand the company to someone else, promote another Admin with Make owner — see transfer ownership.
What this will not do
- Standard is not a read-only guest mode. They can still act on invoices and debtors; they just cannot reconfigure the business.
- There is no SSO or custom RBAC on normal plans.