This article explains how to invite team members to Light, assign roles, and manage users across your organisation.
Last updated Jul 22, 2026 · 2 min read
Light comes with predefined system roles. Each role grants a specific set of permissions:
| Role | Description |
|---|---|
| Company Admin | Full access to all features, settings, and data |
| Controller | Create journal entries, review GL accounts, and prepare financial reports |
| Invoice Approver | Approve bills routed to them for approval |
| AP Preparation | Prepare and process bills |
| AP Clerk | Handle bill processing, approval submission, and payments |
| AR Clerk | Manage invoices, customers, and revenue |
| Vendor Management | Manage vendor records and onboarding |
| Purchase Requester | Submit purchase requests |
| Cardholder | Use a company card and submit card transactions |
| Reimbursement | Submit expenses and request reimbursements |
| Report Viewer | Read-only access to reports |
| Auditor | Read-only access to financial data for audit purposes |
To see the full permission breakdown for each role, go to Business partners → Users and open the Roles tab.
Go to Business partners → Users
Click + Create user
Fill in the team member's details:
Click Create
Light sends the new member a welcome email with links to the Light web and mobile apps. You can control this with the Send welcome email toggle when creating the user, or set an organisation-wide default in Organization settings.
Go to Business partners → Users to see all users. The list shows full name, email, roles, phone, groups, country, city, and address. Click any row to open the user's details.
Archived users cannot log in but remain in historical records. They are no longer included in approval flows.
Groups let you organise users into named teams with a hierarchy level.
Open any group from the Groups tab to see its members. Use Add users to add members or the remove button on any row to remove them.
Go to Business partners → Users and open the Roles tab to see a full permission matrix — every role mapped against every available permission. This view is read-only.
Each user is assigned to a specific company entity. To change which entity a user belongs to, open the user's details and update the Entity field.
For organisations using single sign-on (SSO), Light integrates with Auth0, supporting:
Contact Light support to enable SSO for your organisation.
Was this article helpful?

