How to invite your team and choose roles
Team access lives under Settings → Access. Inviting someone is four steps: who they are, what they can do, per-app access, send.
1
Who they are
Type their full name and work email — or pick their existing record from the People directory first, which links their login to their HR record. That link is what makes clocking in, leave requests and timesheets work as self-service.
2
Their workspace role
One role sets their default everywhere. Owner — full control including billing. Admin — full control short of transferring ownership. Manager — runs the team’s work (schedules, assignment, approvals), no billing or settings. Collaborator — does the work: creates and edits; the everyday employee role. Viewer — read-only.
3
Per-app access
The workspace role is the default in every app, and any app can override it: raise someone to admin of just one app (they get that app’s settings), lower them, or remove the app from their launcher entirely. Under Advanced you can also set their department.
4
Send it
The invite email is valid for 7 days. They accept, sign in, and land in a short welcome tour of the workspace.
Money is a label, not a role
Amounts, prices and financial documents stay hidden from everyone without the finance or legal label — whatever their role. Granting the label (under Advanced in the invite, or later on their member record) is a deliberate act: give it to your accountant, not to everyone.
Collaborator is the everyday answer
Most staff belong at collaborator: they see the directory and their own department, manage their own attendance, leave, timesheets and goals, and work in the apps you give them — without touching billing, roles or workspace settings.