What is this page about: How to invite team members to Light, choose the right access role for each person, manage and disable users, organise people into groups, and where entity access and SSO fit in.
On this page
- Bringing your team into Light
- Invite a team member
- Not sure which role to pick?
- Roles reference
- Managing team members in Light
- Groups
- Roles tab
- Entity access
- SSO and authentication
- Quick reference
- Related articles
Bringing your team into Light
Adding your team takes a couple of minutes, and roles make sure everyone lands with exactly the access they need. You invite people, pick their role, and Light sends them a welcome email to get started. You stay in control the whole way.
Invite a team member
-
Go to Business partners → Users
-
Click Create user
-
Fill in the team member's details:
- First name and Last name
- Access role: select one or more roles (see "Not sure which role to pick?" below)
- Entity: which company entity they belong to
- Manager: their direct manager in Light
- Address
- Country: required
- State, City, Zip / postcode: optional
- Phone number: optional
-
Click Create
Light then sends the new member a welcome email with links to the Light web and mobile apps, so they can jump straight in. You can control this with the Send welcome email toggle when creating the user, or set an organisation-wide default in Organization settings. See Creating your account for what they see next.
Not sure which role to pick?
You can assign one or more roles to each person, so it's easy to match their real job. Here's the plain-language version of what each group does:
- Run everything: Admin (full access) and Controller (journal entries, GL review, financial reports).
- Handle bills and payments (AP): AP preparation and AP clerk process and pay bills, Invoice approver approves bills routed to them, and Purchase requester submits purchase requests.
- Handle customer invoicing (AR): AR clerk manages invoices, customers, and revenue.
- Manage vendors: Vendor management handles vendor records and onboarding.
- Spend and get reimbursed: Cardholder uses a company card and submits card transactions, and Reimbursement submits expenses and requests reimbursements.
- View only: Report viewer (read-only reports) and Auditor (read-only financial data for audits).
The full permission breakdown for every role is below, and you can always see it live in Business partners → Users → Roles tab. See User roles and permissions overview for how permissions map to each role.
Roles reference
Light comes with predefined system roles. Each role grants a specific set of permissions:
| Role | Description |
|---|---|
| Admin | Full access to all features, settings, and data |
| Controller | Create journal entries, review GL accounts, and prepare financial reports |
| Invoice approver | Approve bills routed to them for approval |
| AP preparation | Prepare and process bills |
| AP clerk | Handle bill processing, approval submission, and payments |
| AR clerk | Manage invoices, customers, and revenue |
| Vendor management | Manage vendor records and onboarding |
| Purchase requester | Submit purchase requests (a role under AP clerk, used for purchase orders) |
| Cardholder | Use a company card and submit card transactions |
| Reimbursement | Submit expenses and request reimbursements |
| Report viewer | Read-only access to reports |
| Auditor | Read-only access to financial data for audit purposes |
Managing team members in Light
View the team
Go to Business partners → Users to see all users. By default the list shows full name, status, email, city, roles, and groups. Click any row to open the user's details.
Edit a user
- Click on a user in the Users list. This opens their details directly in an editable dialog, so there is no separate Edit button
- Update their details, roles, entity, or manager
- Click Save
Disable a user
- Click on the user in the Users list
- Turn off the Active toggle
- Confirm
Their status changes to Disabled. Disabled users cannot log in but remain in historical records, so your audit trail stays intact. They are no longer included in approval flows.
Groups
Groups let you organise users into named teams with a hierarchy level. Groups can be named as approvers in an approval workflow, so any member of the group can act.
Create a group
-
Go to Business partners → Users
-
Open the Groups tab
-
Click + Create group
-
Fill in:
- Name (required, max 50 characters)
- Description (optional)
- Level (numeric, 1-99, used for approval hierarchy)
-
Click Next
-
Search and select users to add to the group
-
Click Create
Manage group members
Open any group from the Groups tab to see its members. Use Add users to add members or the remove button on any row to remove them. Groups can also be archived from this tab.
Roles tab
Go to Business partners → Users and open the Roles tab to see a permission matrix: the 12 assignable roles mapped against every available permission. This view is read-only.
Entity access
Each user is assigned to a specific company entity. To change which entity a user belongs to, open the user's details and update the Entity field.
SSO and authentication
Light supports single sign-on (SSO) for organisations that need it. Contact Light support to check current provider support and get SSO enabled for your organisation. For password and two-factor settings, see Two-Factor Authentication and Security.
Quick reference
| Task | Where to go |
|---|---|
| Invite a team member | Business partners → Users → Create user |
| View all roles and permissions | Business partners → Users → Roles tab |
| Edit a user | Click the user in the Users list |
| Disable a user | Click the user → turn off the Active toggle |
| Create a group | Business partners → Users → Groups tab → Create group |
| Change a user's entity | Open the user's details → Entity field |
| Enable SSO | Contact Light support |