Application

Users and roles

People are invited to an entity, not to your account. Someone can be an Admin on one company and a Viewer on another, which is what lets a finance team, an external accountant and a manager who only signs off work on the same books without sharing a login.

The four roles

RoleWhat it is
AdminThe person who created the entity, and anyone they make an Admin. Full access to everything on it, and the only role that can delete the entity or change another Admin's access.
EditorEverything an Admin does day to day — the connection, the mapping, tax codes, invoices, people — except deleting the entity and anything that touches an Admin.
ApproverInvoice approval only. Sees the entity and its invoices, and approves, rejects or comments on the ones waiting for a decision. Changes nothing else.
ViewerRead-only. Sees the entity, its invoices, its mapping and its settings, and can change none of it. The role for an auditor, an external bookkeeper, or anyone who only needs to look.

Anyone with a TaxStar account can create an entity, and creating one makes you its Admin. The other three roles only ever arrive by invitation from someone who already has access.

What each role can do

Action on the entityAdminEditorApproverViewer
See invoices, reports, mapping and settingsYesYesYesYes
Edit entity details and TRNYesYesNoNo
Connect or disconnect the ERPYesYesNoNo
Complete and change PINT MappingYesYesNoNo
Configure tax codesYesYesNoNo
Fill in a staged invoice and submit itYesYesNoNo
Email an invoice, or upload a batchYesYesNoNo
Approve, reject or comment on an invoiceYesYesYesNo
Invite an Editor, Approver or ViewerYesYesNoNo
Change someone's role, or remove themYesYesNoNo
Make, change or remove an AdminYesNoNoNo
Delete the entityYesNoNoNo

The two rows that matter most are the last two. Everything else an Editor does is what an Admin does — inviting people and removing them included — but an Editor can never make someone an Admin, change an Admin's role, remove an Admin, or delete the entity. That is what stops control of an entity being handed on, or taken away, by someone who was merely given access to it.

These rules are applied to every request, not only to the buttons. Where your role does not allow something, the screen still shows it — switched off, with a note naming the role that can — so you can see the feature exists and know who to ask rather than wondering where it went.

Admin

The first Admin is whoever created the entity. There is no separate step to become one — creating the company makes you its Admin, and with it comes full access to entity details, the ERP connection, PINT Mapping, tax codes, invoices and people.

Anything involving another Admin is the Admin's alone: only an Admin can promote someone to Admin, change an Admin's role, or remove one. Deleting the entity is Admin-only for the same reason. An Admin also inherits every action the other roles have, so nothing on the entity is ever blocked on someone else being available.

Editor

An entity can have as many Editors as it needs. An Editor works on the entity exactly as the Admin does — connecting the ERP, completing the mapping, configuring tax codes, filling in staged invoices, approving, and inviting or removing people — with one boundary: an Editor cannot make, change or remove an Admin, and cannot delete the entity. When an Editor invites someone, the roles offered are Editor, Approver and Viewer.

An Editor must already have an account on TaxStar. Invite them by email, they receive an invitation link, and they have access to the entity once they accept it — not before.

Approver

Where your finance process needs a second pair of eyes, the entity can require invoices to be approved before they go to the Peppol network. Approvers are the people who give that approval, and an entity can have several of them. They are invited by an Admin or an Editor through the same email invitation, and the same acceptance step applies.

What an Approver can doWhy
Invoices to ApproveThe one tab an Approver works in. It lists the invoices waiting on a decision.
View invoice detailsThe full invoice as it will be filed, so the decision is made on what actually goes.
Comment on an invoiceWhat tells the person who raised it why it came back.
Reject an invoiceA human decision, not a rule failure. The invoice stops and the comment explains it.
Approve an invoiceReleases it. From here it continues to the Peppol network.

That list is deliberately the whole of it. An Approver can read the entity but change nothing else about it — not the TRN, not the connection, not the mapping, not the tax codes — and cannot send, email or upload an invoice either. The role is to decide, not to operate, which is what makes it safe to give to someone outside the finance team whose only job is to say yes or no.

Viewer

A Viewer sees what an Admin sees and changes none of it: the invoice list and each invoice's detail, the reports, the connection, the mapping, the tax codes, and who has access. Every control that would change something is switched off for them.

It is the right role for an auditor, an external bookkeeper, or a colleague who needs to answer questions about what was filed without being able to alter it. A Viewer cannot approve invoices — if the person is meant to sign off, they need Approver.

How an invitation works

The flow is the same for every role, and it always ends with the invited person agreeing to it:

  1. An Admin or an Editor invites someone by email and picks their role — Editor, Approver or Viewer.
  2. The invited person needs an account on TaxStar — the invitation is tied to their email.
  3. They receive an invitation link.
  4. They accept it. Until they do, they appear as invited and can see nothing of the entity.
  5. On acceptance they get exactly the access their role carries, on that entity only.

A role can be changed later, and access can be taken away, from the same place it was granted. Both take effect immediately.

Approval is one of the two points where a person steps into an otherwise automatic flow; the other is a staged invoice. Both are on Sending invoices. The entity itself, and the details it is created with, are on Set up your account.