Under Admin → Users you add people and set what they can see.
- Add them with a work email, their name, and a temporary password you choose — at least 12 characters. Then tell them the email address and that password.
- Assign a role: Viewer (read published reports), Care agent (the customer care desk only), Operations (operational reports and reconciliations), Finance (financial reports and statements), or Admin (everything, plus settings and user management).
- Changing a role ends that person's open sessions. They sign in again with the new role.
The password you type is temporary, and the system enforces that. The first time that person signs in they are asked to set a password of their own, and the one you chose stops working. You never end up knowing a colleague's password, and you don't have to remember to chase them about changing it.
Two things follow from that, both worth knowing before you are surprised by them:
- Send them the temporary password by a route only they can read — in person, or a direct message. It is short-lived, but until they sign in it does open their account.
- If a password is refused when you type it, it is usually because it is too short or because it appears in a public list of leaked passwords. Choose another one; the check is there for a reason and cannot be waived.
Guidelines that keep this clean:
- Give the lowest role that does the job. It's a finance product — least access is the professional default, and you can always raise it later.
- Use Care agent for frontline care staff. A copied Ledger link and a direct Ledger API call are refused for that role; do not give Operations merely to open the desk.
- Individual reports can additionally be limited by role when published, so a sensitive report can be Finance-and-Admin-only even though the person can see the rest.
- When someone leaves, deactivate them here — their sign-in stops immediately, any session they have open is ended, and they come off your company's user list.
- If someone forgets their password, they can reset it themselves from the sign-in screen. You do not need to create them a second account, and you should not.
Deactivating someone is not erasing them
Deactivating ends a person's access. It does not remove them from your history, and that is deliberate: every report they approved, every figure they attested and every sign-off they made still shows their name.
A finance record that suddenly attributes an approval to nobody is worse than one naming somebody who has left — an approval whose author cannot be identified is not much of an approval. So there is no way to delete a person outright from this screen.
Reinstating somebody you deactivated is a support request rather than a button on the page. An action that can be undone in one click eventually gets undone by accident.