Docs
/
EN DE

Users & Roles

Roles decide what each person in your company can see and do — invoices only, bank matching but no reports, everything except system settings. You define a role once, assign it to users, and neoo takes care of the rest: pages a role has no permission for are simply hidden from that user’s menu.

Access is managed in two places that do the same thing:

  • From the start page: click Manage Dataset on the company’s row (available to the owner and admins). The dialog has three tabs for access management — Users, Roles and Invites.
  • Inside the company, under System → Management. The page has the same Users, Roles and Invites tabs plus an API Keys tab, and is available to the owner, admins and anyone whose role carries the System → Management permission. That lets you delegate day-to-day user administration to, say, an office manager without making them an admin: such a person can invite users, assign roles and manage API keys, but cannot grant admin access, change an admin’s access, or touch the owner.

Roles

On the Roles tab, Add Role creates a new permission set; the pencil button on a role’s row opens it for editing. A role has three parts:

Field What it does
Role Name How the role appears when assigning it — “Accountant”, “Approver”, “Read-only”
Hidden Menu Items Menu entries to hide from everyone holding this role, even where a permission would technically allow them — useful for decluttering
Access Controls The permissions themselves, as checkboxes grouped the same way as the app menu

The permission groups are the same sections as the app menu: Cockpit, Customers, Vendors, Orders & Quotations, General Ledger, Services, System, Import and Integrations. Tick what the role should be able to open and do; everything else stays out of sight.

Changes to a role apply to everyone holding it. A user holds at most one role — roles can’t be combined — and a person at the User access level needs one to see anything at all.

Practical advice

  • Create roles before inviting people — an invitation can carry the role directly, so new users start with the right permissions. See Inviting Users.
  • Grant the minimum. Start narrow and add permissions when someone actually needs them — it keeps the books safe and the menus clean.
  • Let hiding work for you. Because unusable menu entries disappear automatically, a well-cut role doubles as a simpler interface for that user.

Two permissions that don’t do what their name suggests

  • Batch update also grants mass-deletion. There is no separate delete permission: whoever can bulk-edit journal entries or vendor documents can also permanently delete them — along with their payments and attachments — in one click. Grant it as if you were granting deletion, because you are. Batch Update explains what that removes, and how the reversal setting takes the delete away while keeping the edit.
  • Every import screen needs the General Ledger import permission, on top of its own. Each import validates against your accounts and currencies, and it loads them through the General Ledger import. Without it, the screen opens and then rejects every row. If an import works for you and fails for a colleague, this is almost always why — see Importing Your Data.

Users

The Users tab lists everyone with access, their access level and role:

  • Edit User Access — switch a person between the Admin and User access levels and change their role. The owner’s access cannot be changed.
  • Remove Access — takes this company off the person’s start page; their neoo account and other datasets are untouched.

What access levels mean — and how they differ from roles — is explained in Inviting Users.

Invites

The Invites tab shows invitations that haven’t been accepted yet. Cancel Invite withdraws one. Sending invitations is covered in Inviting Users.

API keys

The API Keys tab of System → Management lists the keys that integrations use to access this company. Create API Key asks for a label and shows the key exactly once — copy it straight away, it cannot be displayed again. A key can only be deleted by the person who created it; deleting it stops every integration using it immediately.