New KPMG Agentic ERP, now available with KPMG in 140+ countries Read the announcement

Adding team members and roles

Guide
Admin guides
Reading
5 min read
On this page
  1. 01On this page
  2. 02Bringing your team into Light
  3. 03Invite a team member
  4. 04Not sure which role to pick?
  5. 05Roles reference
  6. 06Managing team members in Light
  7. 07Groups
  8. 08Roles tab
  9. 09Entity access
  10. 10SSO and authentication
  11. 11Quick reference
  12. 12Related articles

What is this page about: How to invite team members to Light, choose the right access role for each person, manage and disable users, organise people into groups, and where entity access and SSO fit in.

On this page

  • Bringing your team into Light
  • Invite a team member
  • Not sure which role to pick?
  • Roles reference
  • Managing team members in Light
  • Groups
  • Roles tab
  • Entity access
  • SSO and authentication
  • Quick reference
  • Related articles

Bringing your team into Light

Adding your team takes a couple of minutes, and roles make sure everyone lands with exactly the access they need. You invite people, pick their role, and Light sends them a welcome email to get started. You stay in control the whole way.

Invite a team member

  1. Go to Business partners → Users

  2. Click Create user

  3. Fill in the team member's details:

    • First name and Last name
    • Email
    • Access role: select one or more roles (see "Not sure which role to pick?" below)
    • Entity: which company entity they belong to
    • Manager: their direct manager in Light
    • Address
    • Country: required
    • State, City, Zip / postcode: optional
    • Phone number: optional
  4. Click Create

Light then sends the new member a welcome email with links to the Light web and mobile apps, so they can jump straight in. You can control this with the Send welcome email toggle when creating the user, or set an organisation-wide default in Organization settings. See Creating your account for what they see next.

Not sure which role to pick?

You can assign one or more roles to each person, so it's easy to match their real job. Here's the plain-language version of what each group does:

  • Run everything: Admin (full access) and Controller (journal entries, GL review, financial reports).
  • Handle bills and payments (AP): AP preparation and AP clerk process and pay bills, Invoice approver approves bills routed to them, and Purchase requester submits purchase requests.
  • Handle customer invoicing (AR): AR clerk manages invoices, customers, and revenue.
  • Manage vendors: Vendor management handles vendor records and onboarding.
  • Spend and get reimbursed: Cardholder uses a company card and submits card transactions, and Reimbursement submits expenses and requests reimbursements.
  • View only: Report viewer (read-only reports) and Auditor (read-only financial data for audits).

The full permission breakdown for every role is below, and you can always see it live in Business partners → Users → Roles tab. See User roles and permissions overview for how permissions map to each role.

Roles reference

Light comes with predefined system roles. Each role grants a specific set of permissions:

Role Description
Admin Full access to all features, settings, and data
Controller Create journal entries, review GL accounts, and prepare financial reports
Invoice approver Approve bills routed to them for approval
AP preparation Prepare and process bills
AP clerk Handle bill processing, approval submission, and payments
AR clerk Manage invoices, customers, and revenue
Vendor management Manage vendor records and onboarding
Purchase requester Submit purchase requests (a role under AP clerk, used for purchase orders)
Cardholder Use a company card and submit card transactions
Reimbursement Submit expenses and request reimbursements
Report viewer Read-only access to reports
Auditor Read-only access to financial data for audit purposes

Managing team members in Light

View the team

Go to Business partners → Users to see all users. By default the list shows full name, status, email, city, roles, and groups. Click any row to open the user's details.

Edit a user

  1. Click on a user in the Users list. This opens their details directly in an editable dialog, so there is no separate Edit button
  2. Update their details, roles, entity, or manager
  3. Click Save

Disable a user

  1. Click on the user in the Users list
  2. Turn off the Active toggle
  3. Confirm

Their status changes to Disabled. Disabled users cannot log in but remain in historical records, so your audit trail stays intact. They are no longer included in approval flows.

Groups

Groups let you organise users into named teams with a hierarchy level. Groups can be named as approvers in an approval workflow, so any member of the group can act.

Create a group

  1. Go to Business partners → Users

  2. Open the Groups tab

  3. Click + Create group

  4. Fill in:

    • Name (required, max 50 characters)
    • Description (optional)
    • Level (numeric, 1-99, used for approval hierarchy)
  5. Click Next

  6. Search and select users to add to the group

  7. Click Create

Manage group members

Open any group from the Groups tab to see its members. Use Add users to add members or the remove button on any row to remove them. Groups can also be archived from this tab.

Roles tab

Go to Business partners → Users and open the Roles tab to see a permission matrix: the 12 assignable roles mapped against every available permission. This view is read-only.

Entity access

Each user is assigned to a specific company entity. To change which entity a user belongs to, open the user's details and update the Entity field.

SSO and authentication

Light supports single sign-on (SSO) for organisations that need it. Contact Light support to check current provider support and get SSO enabled for your organisation. For password and two-factor settings, see Two-Factor Authentication and Security.

Quick reference

Task Where to go
Invite a team member Business partners → Users → Create user
View all roles and permissions Business partners → Users → Roles tab
Edit a user Click the user in the Users list
Disable a user Click the user → turn off the Active toggle
Create a group Business partners → Users → Groups tab → Create group
Change a user's entity Open the user's details → Entity field
Enable SSO Contact Light support

Was this article helpful?