Skip to content

Administration

Roles and permissions

Every tenant gets the same 8 roles, seeded automatically. Roles and their permissions are shared definitions across the whole platform (not duplicated per tenant) — what's tenant-specific is which of…

Last updated Aug 19, 2026 · 2 min read

Every tenant gets the same 8 roles, seeded automatically. Roles and their permissions are shared definitions across the whole platform (not duplicated per tenant) — what's tenant-specific is which of your users hold which role.

Role Can do
Owner Everything. Every tenant has exactly one at all times — you can't remove the last Owner from Settings → Team.
Admin Everything, same as Owner. The distinction exists so a tenant can have more than one full-access user without literally sharing the "Owner" label — assign it to a co-founder, an operations lead, etc.
Sales Manager Parties (customers/vendors), full CRM (leads, deals) and Sales-to-Cash (quotes, invoices, tax rates), can view item/stock info.
Sales Rep Same as Sales Manager for parties/CRM/sales, except only sees leads/deals assigned to them — not the whole tenant's pipeline — and can't create tax rates.
Accountant Views parties and invoices, records payments, manages tax rates, full chart of accounts and journal entries (create/post/reverse).
Inventory Clerk Parties (for vendors), full items, warehouses, stock adjustments, and purchase orders. No CRM/Sales/Accounting access.
HR Manager Full employees, leave (including approving requests), attendance, and payroll. Only visible/usable once HR is enabled for the tenant (see HR).
Viewer Read-only access across every module — parties, CRM, Sales, Inventory, Accounting, HR. No create/edit/delete anywhere. Useful for a bookkeeper, auditor, or stakeholder who needs visibility without the ability to change anything.

Assigning users to roles

Settings → Team (visible if you're an Owner or Admin) lists everyone in your tenant and lets you add a new teammate with a name, email, password, and role in one step, or remove someone. There's no email-invite flow — you set the password directly when adding them, and share it with them yourself. A user always has exactly one role.

Two things this is not

  • Not a per-record permission system. Sales Rep's "only my own leads/deals" restriction is the one ownership-based rule in the app — every other permission is all-or-nothing for the whole tenant (e.g. Accountant sees every invoice, not just ones they created).
  • Not the same as the landlord. None of these 8 roles have anything to do with the separate landlord panel login, which only exists in SaaS mode and manages tenants/plans, not records within a tenant.

← All Coravo – AI CRM & ERP Software for Growing Businesses documentation

We use cookies to understand how visitors use this site. Cookie Policy