Every tenant gets the same 8 roles, seeded automatically. Roles and their permissions are shared definitions across the whole platform (not duplicated per tenant) — what's tenant-specific is which of your users hold which role.
| Role | Can do |
|---|---|
| Owner | Everything. Every tenant has exactly one at all times — you can't remove the last Owner from Settings → Team. |
| Admin | Everything, same as Owner. The distinction exists so a tenant can have more than one full-access user without literally sharing the "Owner" label — assign it to a co-founder, an operations lead, etc. |
| Sales Manager | Parties (customers/vendors), full CRM (leads, deals) and Sales-to-Cash (quotes, invoices, tax rates), can view item/stock info. |
| Sales Rep | Same as Sales Manager for parties/CRM/sales, except only sees leads/deals assigned to them — not the whole tenant's pipeline — and can't create tax rates. |
| Accountant | Views parties and invoices, records payments, manages tax rates, full chart of accounts and journal entries (create/post/reverse). |
| Inventory Clerk | Parties (for vendors), full items, warehouses, stock adjustments, and purchase orders. No CRM/Sales/Accounting access. |
| HR Manager | Full employees, leave (including approving requests), attendance, and payroll. Only visible/usable once HR is enabled for the tenant (see HR). |
| Viewer | Read-only access across every module — parties, CRM, Sales, Inventory, Accounting, HR. No create/edit/delete anywhere. Useful for a bookkeeper, auditor, or stakeholder who needs visibility without the ability to change anything. |
Assigning users to roles
Settings → Team (visible if you're an Owner or Admin) lists everyone in your tenant and lets you add a new teammate with a name, email, password, and role in one step, or remove someone. There's no email-invite flow — you set the password directly when adding them, and share it with them yourself. A user always has exactly one role.
Two things this is not
- Not a per-record permission system. Sales Rep's "only my own leads/deals" restriction is the one ownership-based rule in the app — every other permission is all-or-nothing for the whole tenant (e.g.
Accountantsees every invoice, not just ones they created). - Not the same as the landlord. None of these 8 roles have anything to do with the separate landlord panel login, which only exists in SaaS mode and manages tenants/plans, not records within a tenant.
← All Coravo – AI CRM & ERP Software for Growing Businesses documentation