Skip to content

Team, Roles & Permissions

Kraal is built for firms where several people work the books together. This page explains how to add teammates, what each role is allowed to do, how access is scoped to the clients a person works, and who controls Kraal's autonomy safety switches.

Team seats are free on every plan, so invite everyone who touches the books and give each person the role that matches their work. See Admin & Billing for how billing and seats work.

The four roles at a glance

Every firm team member holds one of four roles. Owners and Administrators run the organization; Managers do day-to-day accounting on the clients they are assigned; Employees have read-only access to the clients they are assigned.

What they can doOwnerAdministratorManagerEmployee
Invite and remove teammates, change roles, manage billing and org settingsYesYes
Appoint another OwnerYes
Create and manage clients, and set who can access each clientYesYes
Set a client's autonomy policy (authority mode, caps, presets)YesYes
Create or change revenue contracts and performance obligationsYesYes
Post entries, draft and send invoices, record payments, approve bills, upload documentsYesYesYes
Approve Kraal's prepared high-risk actions: release a prepared payment run, lock a close period, approve Kraal's prepared client sends, raise autonomyYesYes
Pause autonomy — org-wide or for a client they can accessYesYesYesYes
Resume autonomy after an org-wide pauseYesYes
Resume autonomy for a client they can accessYesYesYes
View reports, transactions, bills, invoices, and close statusYesYesYesRead-only
Clients they can seeAllAllAssigned onlyAssigned only

The rest of this page walks through each of these in practice.

Inviting teammates

Only Owners and Administrators can invite firm teammates. For security, you may be asked to re-verify your identity (a fresh multi-factor challenge) before team changes take effect.

To invite someone:

  1. Open your team roster in the admin area of your profile settings.
  2. Choose Add a team member and enter their email address.
  3. Optionally preassign the clients they should work — you can scope a teammate to specific clients right from the invite.
  4. Send the invite.

What the invitee sees

  1. They receive an email invitation with a secure link.
  2. Opening the link takes them through sign-in (or account creation for a first-time user).
  3. Once they sign in, their organization access is finalized and they land in the workspace, already scoped to the role and clients you set for them.

An invite that hasn't been accepted yet shows as pending in your roster until the person completes sign-in.

Inviting a client's own people

The steps above are for firm teammates. To give someone on the client's side limited, client-only access — for uploading documents, answering requests, or reviewing invoices — use the client portal instead. See External Client Portal. Client-side collaborators are always scoped to a single client and only what you share with them, and an invite raised by a non-admin teammate waits for firm-admin approval before it is sent.

Roles in detail

Owner

The Owner is the firm's top role and can do everything in Kraal:

  • Manage the organization — invite and remove teammates, change roles, and manage billing and organization settings.
  • Manage every client — create, edit, and archive clients, and control who can access each one.
  • Do all day-to-day accounting and approve high-risk work.
  • Set and change client autonomy policy, and resume autonomy after a pause.
  • See every client in the portfolio.

Only an Owner can appoint another Owner. This keeps the most powerful role deliberate and hard to grant by accident.

Administrator

Administrators have the same broad reach as Owners — full organization management, full client management, all accounting and approvals, and autonomy resume — with one difference: they cannot appoint a new Owner. Use Administrator for the people who run the firm day to day alongside the Owner.

Manager

Managers do the accounting work, scoped to the clients they are assigned:

  • Post journal entries, draft and send invoices, record payments, approve bills within policy, and upload documents.
  • Generate, export, share, and lock reports and report packs.
  • Handle routine approvals in their judgment queue.

Managers cannot administer the organization (no inviting or role changes), cannot create clients or change who can access a client, and cannot change a client's autonomy policy (authority mode, caps, or presets). Approving Kraal's prepared high-risk actions is also reserved for Owners and Administrators — releasing a payment run Kraal has prepared, locking a close period, approving Kraal's prepared client-facing sends (collection reminders, client requests, report-pack deliveries it queued), or raising what Kraal may do on its own. This is distinct from a Manager's own routine client-facing work: sending an invoice they drafted or sharing a report pack themselves is always within a Manager's reach. A Manager can pause autonomy and — for a client they are assigned — resume it as well: the client-level safety switch is theirs to trip and to clear, since they already run that client's books. Resuming an org-wide pause still stays with Owners and Administrators. Managers see only the clients assigned to them.

Revenue-contract setup is also reserved for Owners and Administrators. Managers can review eligible revenue work for their assigned clients, but they cannot create or rewrite the contracts and performance obligations that drive the recognition schedule.

Employee

Employees have read-only access to the clients they are assigned. They can view reports, transactions, bills, invoices, and close status, but cannot post, send, approve, or change settings. Employees still have one action available to everyone on the team: they can hit the autonomy pause (see Autonomy safety controls below).

How close and reconciliation actions reflect access

The Close Sheet and Reconciliation Hub separate permission from readiness:

  • An action that your role cannot take is not offered as an executable control.
  • An action you are allowed to take may still be unavailable until a named prerequisite clears—for example, stale evidence must be rerun before signoff, or a reviewer cannot approve work that has not been prepared.
  • Viewing a close or reconciliation does not imply permission to prepare, review, override, reopen, or lock it.

If a teammate should own a missing action, first confirm that they are assigned to the client and hold the right firm role. Do not share another user's session or move the work to a different client scope to work around the control.

Client-scoped access

Access in Kraal follows least privilege: a person sees the clients they work, not the whole firm — unless their role grants firm-wide visibility.

  • Owners and Administrators see the entire client portfolio.
  • Managers and Employees see only the clients they are assigned. That scope applies everywhere — the Daily Board, transactions, close, reports, and search all show only their assigned clients.

This scoping is enforced by Kraal's backend on every request, not by the interface merely hiding rows, so a teammate can never reach a client they are not assigned to. Assign or change a teammate's clients from the same team area where you invite them (Owners and Administrators only), or preassign clients at invite time.

External client-portal collaborators are the most restricted of all: each one is tied to a single client and can only do what you explicitly grant. See External Client Portal.

Autonomy safety controls by role

Kraal can post routine, low-risk work on its own for clients you have placed in a supervised mode. Two switches let your team stop that autonomy instantly, and the rules around them are a deliberate safety design. For the full model of what posts automatically and what always waits, see Autonomy & Safety.

The guiding principle: pausing only tightens autonomy, so anyone can do it; resuming restores it, so it is role-gated. An org-wide pause is cleared only by Owners and Administrators; a client's pause is cleared by an Owner, an Administrator, or a Manager assigned to that client.

ControlWho can do itWhat happens
Pause one clientAnyone on the team assigned to that client (Owner, Administrator, Manager, or Employee)That client switches to approval-first — nothing posts without a person — and a notice appears on the Daily Board for teammates who work that client, showing who paused it and when.
Pause the whole organizationAnyone on the teamEvery client switches to approval-first, and the organization's Owner (and Administrators) are emailed that automatic posting was paused, by whom, and when.
Resume one clientOwners and Administrators, or a Manager assigned to that clientThat client's autonomy returns to its stored settings.
Resume the whole organizationOwners and Administrators onlyEvery client's autonomy returns to its stored settings.

You manage these switches from the Autonomy controls, and paused clients surface on the Daily Board.

Why anyone can pause but resuming is role-gated

If a teammate spots something wrong, they should be able to stop autonomous posting immediately — waiting for an admin would defeat the purpose of a safety stop. Pausing can only make Kraal more cautious, never less, so it is safe to allow for everyone. Turning autonomy back on is a deliberate decision that returns Kraal to posting on its own, so it stays role-gated: an org-wide resume is held to Owners and Administrators, and a client's resume additionally to a Manager assigned to that client — the person already trusted to run that client's books — while read-only Employees cannot resume at all.

Pausing never loses work: anything Kraal would have posted simply waits in the judgment queue for approval, and work already awaiting review is unaffected.

Common tasks

Change a teammate's role

Owners and Administrators can change a teammate's role from the team roster. A few guardrails apply:

  • Only an Owner can grant someone the Owner role.
  • You cannot remove your own administrative access, so the firm can never lock itself out.
  • Role changes are recorded in the audit trail.

Remove a teammate

Owners and Administrators remove a departing teammate from the team roster. Removing someone revokes their organization roles and disables their sign-in immediately. You cannot remove yourself.

What happens to their client assignments

When you remove a teammate, their access — including every client they were assigned — ends with their account. Reassign their clients by assigning another teammate to those clients. Nothing they did is lost: their posted work and history remain intact in the audit trail.

Offboarding a client or the whole firm

Removing a person is different from offboarding a client or your whole organization from Kraal. For a controlled, export-first client or organization departure, use the staged offboarding workflow.

Kraal — AI-powered accounting for modern firms