انتقل إلى المحتوى

لم تُترجم هذه الصفحة بعد

تعرض هذه الصفحة النص الإنجليزي حتى تصدر ترجمتها.

Roles and permissions

Every person in an organisation has exactly one role. The role decides what they may do; it is not a job title.

The four roles

Role In one line
Admin Runs the organisation. The only role that can change the plan, manage users, edit the company profile, and connect to ZATCA.
Accountant Works with money and documents end to end, but does not administer the organisation.
Create invoice Issues invoices and manages the clients and items behind them.
View invoice Reads everything, changes nothing.

Which role to give

flowchart TD
    A{"Should this person<br/>change anything?"}
    A -->|"No — an auditor or owner<br/>who only looks"| V["<b>View invoice</b>"]
    A -->|"Yes"| B{"Do they close the books —<br/>VAT report, bank statements?"}
    B -->|"Yes — a bookkeeper<br/>or accountant"| AC["<b>Accountant</b>"]
    B -->|"No — they sell"| CI["<b>Create invoice</b>"]
    O["Whoever created the<br/>organisation"] --> AD["<b>Admin</b>"]

What each may do

Admin Accountant Create invoice View invoice
Read invoices, clients, items yes yes yes yes
Create and submit invoices yes yes yes —
Credit and debit notes yes yes yes —
Manage clients and items yes yes yes —
Record, reverse and match payments yes yes yes —
Read purchases and vendors yes yes yes yes
Record purchases, manage vendors yes yes yes —
VAT filing report yes yes — —
See branches, ZATCA connections, company profile, plan yes yes yes yes
Add or change branches yes — — —
Connect to ZATCA, renew certificates yes — — —
Users and invitations yes — — —
Edit company profile yes — — —
Change plan and billing yes — — —
API keys yes — — —

Read this table as a guide, not a specification

It reflects how the roles behave in the app today. Where a screen disagrees with this table, the screen is correct — tell us at support@goclix.ai so the table can be fixed.

Why View invoice exists

Auditors, bookkeepers and owners who want oversight without the risk of a mistaken submission. A cleared invoice cannot be deleted — only corrected with a credit note — so read-only access is a real safeguard, not a courtesy.

One role per person, per organisation

If someone belongs to two organisations they have a role in each, and the roles need not match. The role applies to the organisation you are currently working in; the sidebar always names it.

Changing someone's role

An Admin changes a role from User Management. The change takes effect the next time that person loads a page. A person cannot change their own role, and an organisation must keep at least one Admin. Admin is not offered when you invite someone or change a role: "Admin can't be granted — it belongs to whoever created the organization."