Give finance access without full admin
Finance users often need balance and withdrawal visibility without control over products, pricing, checkout, or full business settings.
Use this guide when accountants, operators, or finance managers need Finance access with least privilege.
Finance permission areas
| Permission | Use it when |
|---|---|
| View balance | User monitors available, pending, and total funds |
| List withdrawals | User reviews payout history |
| View withdrawal details | User inspects a specific withdrawal |
| Create withdrawals | User is trusted to request payouts |
Not every finance viewer needs withdrawal creation. Separating view and create permissions reduces blocked withdrawal noise and payout risk.
When to grant finance access
| Scenario | Typical permission pattern |
|---|---|
| External accountant | View balance and withdrawal history |
| Internal finance manager | View plus create withdrawals |
| Founder oversight | View balance across launches |
| Support lead | Usually no finance access; use support sales access instead |
| Agency operator | Rarely needs payout creation; keep scope narrow |
Setup workflow
- Confirm the correct business workspace.
[Screenshot: App header — finance user's target business selected in workspace switcher.]
- Decide which finance actions the user truly needs.
[Screenshot: Permission planning checklist — view balance vs create withdrawals noted.]
- Invite or open the collaborator record.
[Screenshot: Team list — collaborator row selected or invite form open.]
- Choose a finance-focused role or limited role in team roles.
[Screenshot: Role dropdown — Finance user or limited Employee role selected.]
- Enable only the finance permissions the user needs.
[Screenshot: Collaborator permissions panel — finance toggles enabled separately from admin or product access.]
- Avoid granting full admin unless required.
[Screenshot: Admin role not selected — finance toggles only where needed.]
- Confirm the user can see Finance but not unnecessary product settings.
[Screenshot: Finance page accessible — Products admin settings not exposed to user.]
- Review permissions after the first withdrawal cycle.
[Screenshot: Withdrawal history — finance user viewed payout list successfully.]
- Remove or downgrade access promptly after offboarding. See remove collaborators.
[Screenshot: Team list — collaborator removed or finance toggles disabled after offboarding.]
What to verify after granting access
| Check | Why it matters |
|---|---|
| User can open Finance | Confirms permission assignment worked |
| User cannot edit unrelated business settings | Least privilege preserved |
| Withdrawal creation is limited to trusted roles | Prevents accidental or unauthorized payout requests |
| User is in the correct workspace | Multi-business accounts need careful scoping |
| Finance understands pending vs available balance | See settlement timelines |
Best practices
- Grant withdrawal creation only to users who own payout operations.
- Keep product and support access limited when not needed.
- Review permissions when someone changes jobs or contracts end.
- Pair finance access with education on fees and payout delay.
- Document who may request withdrawals in each business workspace.
Common mistakes
- Giving every finance viewer permission to create withdrawals.
- Using full admin because it feels faster than scoped roles.
- Forgetting to remove finance access in one workspace after offboarding from another.
- Letting support agents access Finance when they only need Sales.
- Assuming finance access implies bank account edit rights without checking role behavior.
FAQ
Can a user view Finance in multiple businesses?
Yes, but access is granted per workspace. Switch carefully using switch business workspaces.
Who should create withdrawals?
Usually an internal finance owner or founder-approved operator. View-only users should monitor withdrawal status without creating requests.
What if a withdrawal fails?
Finance viewers can inspect history, but fixing root cause may require admin or finance lead involvement. See blocked withdrawals.
Where do team roles fit?
See manage team roles and product access for the broader access model.