Skip to Content
DocumentationAdminTeam & access

Team & roles

Everything here lives at Settings → Company → Team & roles.

Two things decide what someone can do

This is the part that confuses people, so it’s worth reading once properly. Membership level and role are separate axes, and a person has both.

Membership level is the coarse one:

MembershipAccess
OwnerEverything, including billing and deleting the organization.
AdminFull operational access and team management. Not billing, not deletion.
MemberWhatever their role allows.

Roles are the fine-grained part. LawnLedger ships four ready to use:

RoleBuilt for
EstimatorQuoting. Customers, properties and estimates; can see invoices but not touch them. No team settings, no billing.
Crew LeadRunning crews. Schedule and complete jobs, assign work, approve time, log expenses. Financials are view-only.
Mobile CrewThe field. Assigned jobs, clock in/out, checklists, photos. Mobile app only.
AccountantAn outside bookkeeper who keeps the books: the chart of accounts, journal entries, the monthly close, and entering bills. Reads and exports every financial surface. See below.

A custom role named “Administrator” is not the Admin membership level. It holds whatever permissions you gave it and nothing more. If someone needs to manage the team, raise their membership level - don’t name a role after it and hope.

The Accountant seat

The Accountant role used to be read-only. It is not any more - it is the seat you give the person who actually maintains your books, and it can do the work rather than only look at it.

An Accountant can:

  • Set up and maintain the chart of accounts
  • Post and reverse journal entries
  • Set the fiscal year and the accounting basis
  • Lock a period and run the monthly close
  • Activate the ledger and enter opening balances
  • Enter and edit vendor bills
  • Read and export every financial surface - customers, properties, estimates, invoices, projects, expenses, vendors, banking, budgets, service costs and reports
  • Reach the QuickBooks mapping page, to check how accounts and items line up
  • See the bill, budget, bank-feed and payout alerts in the bell and the Notification Center. That page also lists the company’s customer emails and texts, as it does for anyone who can open it

An Accountant cannot:

  • Pay, approve or delete a bill. Entering what you owe and deciding to part with money are different jobs, and this is where that line sits.
  • Reopen a closed year, or rewind a period lock. Both are owner-only.
  • Rebuild or revert the ledger.
  • Connect, disconnect or trigger a QuickBooks sync.
  • Set up taxes.
  • Create, edit or delete anything operational - jobs, customers, estimates, invoices. They can read all of it.
  • Generate the public year-end share link.
  • Edit notification templates or settings, or resend a message.

The books surfaces an Accountant works in are Professional and up. On Growth they can still read the GL statements and registers, but the journal, the close and opening balances are not there to maintain.

Adding someone

Settings → Company → Team & roles → Invite

Enter their email

Set the membership level

Member for nearly everyone. Admin for someone who genuinely needs to manage the team.

Pick their role

This is where the day-to-day permissions come from.

Send the invitation

They get an email, accept, and set up their own account. Pending invitations stay in the Team list - resend or revoke any time before they accept.

Invitations offer Admin or Member only - ownership is transferred, not invited. And you can’t grant access you don’t hold yourself: only an Owner or Admin can issue an Admin invite, and a Member with permission to invite can’t attach a role more powerful than their own.

Custom roles

Start from a built-in role and clone it. Building from an empty role means discovering the ten permissions you forgot one support call at a time.

Permissions are codes grouped by area, and they follow a consistent shape:

customers.view customers.create customers.edit customers.delete jobs.view jobs.create jobs.edit jobs.assign jobs.complete invoices.view invoices.create invoices.send invoices.record_payment invoices.refund

The verbs are the useful part. invoices.view is not invoices.send, and invoices.record_payment is separate again - so an office assistant can chase payments without being able to issue or void an invoice.

invoices.refund and banking.manage move real money. Grant them deliberately, to people you’d hand the chequebook to.

A worked example: the new office assistant

They answer the phone, book work, and chase payments. They should not be able to delete a customer or see the books.

Clone Estimator, then:

  • Add jobs.create, jobs.edit, jobs.assign - they book work
  • Add invoices.send, invoices.record_payment - they chase payments
  • Leave out invoices.refund, invoices.delete, customers.delete
  • Leave out everything under banking, reports, settings

Membership level: Member. Now the worst mistake they can make on a bad Monday is one you can undo.

Changing and removing people

Change someone’s role from the dropdown next to their name in the Team list. It takes effect on their next request - no re-invite.

Nobody edits a teammate above their own level, whatever their role allows:

To change…You need to be
A Member’s pay rate, crew team or phoneanyone whose role lets them edit the team
An Admin’s pay rate, crew team or phonean Owner or an Admin
The Owner’sthe Owner
Deactivate, remove or reactivate an Adminthe Owner

The Team list only offers Edit and Reactivate on the people you can act on. Deleting a crew team follows the same rule, because it takes everyone on the team off it: if the team holds someone above your level, ask an Owner or Admin to delete it.

Removing a member revokes access immediately. Their history stays: jobs they completed, invoices they created, time they logged. That’s deliberate - an audit trail with people deleted out of it isn’t an audit trail.

Removing your only Owner would lock the organization out of its own billing. Promote someone else first.

Someone forgot their password

If they have an email on their account, Forgot password on the sign-in page is the quickest route. If they don’t - crew who sign in with a username - or the email never arrives, send the link yourself: Settings → Company → Team & roles, then the key icon next to their name. LawnLedger emails it to a real address, texts it if there’s a phone on file, and otherwise hands you the link to pass on however you like. It works for one hour. Owners and Admins only - and you can’t send one to yourself.

Checking what happened

Settings → Activity → Audit log records significant actions with who, what and when. Filter by user, action type or date. It’s the answer to “who changed this price?” - and the reason to give people their own login rather than sharing one.

It is Owner-only. Admins can manage the team but can’t read the log of it.

Tips

  • One login per person. Shared logins make the audit log useless and make removing someone impossible.
  • Review roles when someone changes job. The promoted crew lead usually keeps field access they no longer need.
  • Require two-factor for anyone with money permissions. See Security & two-factor.
Last updated on