Skip to main content

Roles & permissions

A user's role determines what they can do in CloseCore. CloseCore ships with a set of built-in roles and also lets you create custom roles tailored to your team.

Roles are assigned on the Users page and managed on Admin → Roles.

tip

Most users should start as Accountant. Use Limited User for people who only need to sign off on checklist tasks (no ERP refresh and no cloud-storage access), and create a custom role when the built-in roles aren't a precise fit.

Built-in roles

RoleWhat it's for
AdminFull access to every workflow, integration, and setting. Always sees all subsidiaries.
System AdminAdministers integrations, users, and org settings, but has no access to close workflow data. It is intended for people who configure integrations without doing close work and does not count toward user limits. Always sees all subsidiaries.
ManagerFull workflow access plus org configuration: tags, close calendar, report templates, rules, and audit logs.
AccountantFull workflow access, including refreshing reconciliation data from the ERP and cloud-storage access.
Limited UserWorkflow access without ERP refresh or cloud-storage access. Good for sign-off-only users.
Read OnlySees every close workflow surface but cannot change anything.
AuditorExternal auditor with read-only access to the surfaces you toggle on. Auditor access is managed on the Auditors page.

Built-in roles are read-only, so you can't edit their permissions, but you can clone one to create a custom role (see below).

Custom roles

When the built-in roles don't fit, create a custom role on Admin → Roles:

  1. Click to create a new role. Start from a blank role, or clone a built-in role as a starting point (CloseCore names the copy "<Role> (Custom)").
  2. Give it a name and select the individual permissions it should grant.
  3. Optionally grant full entity access so the role always sees every subsidiary and can't be scoped. Otherwise, subsidiary access applies as usual.
  4. Save. The role is now assignable to users.

Permission reference

Permissions are organized into the following sections, so you can build a role precisely:

Workflow

  • Checklist and reconciliations: read, write, and sign off. Reconciliations also include refresh.
  • Journal entries: draft, sign off, and post to ERP.
  • Other workflow features: agent tasks, documents, cloud file storage (open links and download), folders (manage structure and access restricted folders), review notes, reporting, analytics, transaction monitoring, query, and the AI Assistant.
  • Sign off on behalf of others: a cross-cutting permission for signing off another person's work.

Integrations

  • Connect and configure ERP connections and cloud storage.
  • Manage Microsoft admin consent.
  • Connect a messaging account.

Org Configuration

  • Manage subsidiaries, the close calendar, tags, report templates, and budgets.
  • Manage assignee rules, monitoring rules, auto-rec rules, and journal-entry rules.

User & Access

  • Manage users and auditors, 2FA, and roles.

Org Settings

  • Manage org settings, view and manage billing, and view audit logs.
note

Some permissions may refer to features that aren't enabled for your account (for example, agent tasks may not be enabled for your account). Read and sign-off are independent from "write" so that, for example, a Limited User can complete assigned work without editing task configuration.