Light provides role-based access controls, entity-level scoping, and approval guardrails to protect your financial data. Single Sign-On (SSO) is available through Light's Auth0-based authentication la...
Last updated Feb 18, 2026 · 5 min read
User management lives under Business partners > Users in the main sidebar navigation. This page has three tabs: Users, Groups, and Access roles.
The Users tab lists all users in your organization, showing their full name, email, roles, groups, and city. You can search and filter the list, customize which columns are shown via the Columns button, and create new users with + Create user.
Clicking on a user opens their detail form, where an admin can view or edit:
Users can be archived from this form using the Archive button.
Each user is assigned one or more access roles that determine what they can see and do across the platform. Light includes the following predefined roles:
To assign roles, open a user's detail form from Business partners > Users, then select the desired role(s) from the Access role dropdown.
You can also view your own assigned roles in Settings > Profile > Organization details.
The Access roles tab on the Users page displays a full permissions matrix. Each row represents a specific permission (grouped by category), and each column represents a role. A checkmark indicates the role has that permission.
Permission categories include:
This matrix is read-only and reflects the system-defined permissions for each role.
The Groups tab lets you organize users into groups. Each group has a name, an optional description, and a member count. Groups can be used to scope access, route approvals, or organize teams.
You can create new groups using the + Create group button at the top of the Users page.
Light supports multi-entity organizations. Each user is assigned to an entity (legal company) via the Entity dropdown on their user detail form.
Available entities are configured under Settings > Entities, where each entity has a code, name, base currency, and VAT number.
Light uses Guardrails to enforce approval requirements on financial transactions. Guardrail settings are found under Settings > Guardrails > Payables.
Under the Bills tab, you can view the approval rules that apply to bill payments. For example, a guardrail might require approval from a minimum number of approvers before a bill can be processed.
Under the Reimbursements tab, similar approval rules apply to expense reimbursements — such as requiring approval from at least two approvers before a reimbursement is paid out.
Note: Guardrail configurations are managed by Light. If you need to update your approval rules, contact your Light representative — you'll see a Contact Light for update prompt on the guardrails page.
Light includes a visual Workflow builder for automating processes that involve approvals and other actions. Workflows are accessed from Settings > Workflows.
Each workflow is triggered by an event and can include approval steps, conditional logic, and automated actions. Pre-built workflows include:
Workflows are configured using a drag-and-drop node editor with Action and Condition blocks. Each workflow can be published, and the Workflows page shows the trigger, publication date, publisher, and version number.
Under Settings > Guardrails > Policies, you can create and manage spend policies that are scoped to specific entities. Policies can be uploaded or created from scratch using the + Create policy and Upload buttons. Each policy is associated with one or more entities and tracks the last edit date and editor.
Light supports Single Sign-On so that employees can log in using their company's identity provider rather than managing a separate username and password. Light's SSO is powered by Auth0.
SSO is configured at the organization level in coordination with Light's team — there is no self-service SSO setup screen in the Light app. To enable SSO, contact your Light representative and provide:
Light's team will configure the connection on the Auth0 backend and test it with you before going live.
When setting up SAML-based SSO, you'll need to configure a new SAML application in your identity provider (e.g., Okta, Azure AD, OneLogin). Use the following callback URL:
https://light-inc-prod.eu.auth0.com/login/callbackThis callback URL is the same for all identity providers. Share your SAML metadata (Entity ID, SSO URL, and signing certificate) with your Light representative, and they will complete the configuration on Light's side.
Important: When sharing your SAML certificate, use a secure method such as a 1Password shared link, an encrypted email, or another trusted secret-sharing tool. Do not send certificates as plain-text email attachments.
Was this article helpful?