Skip to main content

Access control and user permissions in Catacloud

A comprehensive guide to roles, access groups and detailed permissions – and why users sometimes cannot perform actions even though they appear to have access.

Written by Florence C.L.H. Kröger-Smedmann

This guide covers how to manage who has access to what in Catacloud: roles, access groups, and detailed permissions down to individual functions. It also explains the most common reasons why users sometimes cannot perform an action even though they appear to have access.

How access works – in brief

Access in Catacloud is controlled at two levels:

  1. Role – the overarching level assigned to each user (Administrator, Accountant, or Member).

  2. Access groups – fine-grained control over exactly which modules and functions a user can reach. This is where you restrict access per task.

As an administrator you manage both yourself. You'll find everything under Administration → User access, which has two pages: Members and Permissions.

Inviting a user

  1. Go to Administration → User access → Members.

  2. Click Invite person at the top.

  3. Enter the email address and select a role.

New users appear with status Invited until they log in for the first time, then Active. If they haven't received or have lost the invitation, you can resend it from the member list.

On the Members page you can see all users with their name, status, role and when they were last active. You can filter by status and search the list.

The roles

  • Administrator – full access, including managing users, permissions and settings.

  • Accountant – access to all standard business modules (Invoicing, Accounting, Bank, Customers, Suppliers, Products, Files, Contacts) as well as Modules and integrations. Also has access to selected parts of Administration: User access, Company settings, Module settings, Payment and Data transfer. Cannot change other users' roles to Administrator.

  • Member – a member without an access group gets broad default access to the business modules (Invoicing, Accounting, Bank, Customers, Suppliers, Products, Budget, Files, Contacts, Approvals), but no access to Administration or Modules and integrations. If you place the member in an access group, the group defines exactly what they can see and do.

To give someone restricted access, assign them the role Member and add them to an access group with precisely the permissions they need.

Access groups

Access groups let you decide exactly which modules and functions one or more users can reach. You'll find them under Administration → User access → Permissions. The page is split in two: a list of Members at the top and Access groups below.

Creating a new access group

  1. Go to Administration → User access → Permissions.

  2. Click New access group.

  3. On the General tab, give the group a Name and optionally a Description. If the group should have everything, turn on the All permissions toggle.

  4. On the Permissions tab, select exactly what level of access the group should have (see next section).

  5. On the Members tab, tick the users who should be part of the group.

  6. Click Save changes.

You can also add a user to a group by dragging the member card from the member overview into the access group. The History tab shows changes made to the group.

Detailed permissions (the Permissions tab)

On the Permissions tab you see all modules – e.g. Overview, Modules and integrations, Administration, Approvals, Invoicing, Accounting, Bank, Customers, Suppliers, Products, Employees and Budget. Each module has a toggle and a status text:

  • No access – the user cannot reach the module.

  • Partial access – some, but not all, functions in the module are enabled.

  • Full access – all functions in the module are enabled.

Under each module there are sub-permissions. Click Show all sub-permissions to expand them and toggle individual functions on or off. For Customers, the sub-permissions include View and read customers, Create and update customers, Remove customers and View accounts receivable.

"I have full access but can't do X"

This is the most common access question, and the answer is almost always the sub-permissions. A module being turned on often only means Partial access – certain actions are individual sub-permissions that must be enabled separately.

Example: a user has access to Customers but cannot create a contact on a customer card. The solution is to open the sub-permissions for the module and enable the relevant function (e.g. edit/update contacts). Always check the sub-permissions before concluding something is broken.

A field is grey / locked during approval

If a user cannot change a field – for example dimension/department on an invoice awaiting approval – there is often no error message; the field is simply grey and cannot be edited. This is usually because the user lacks access to the relevant department/dimension, in addition to the approval permission itself.

Check that the user has both the correct sub-permission under Approvals and access to the department in question. If you still cannot resolve it, contact us – a screenshot and the relevant client and invoice will help us look into the setup.

Giving an auditor access

To give an auditor read-only access without full administrator rights:

  1. Invite the auditor as a Member via Invite person.

  2. Create an access group that only grants access to views (read access), without edit rights.

  3. Add the auditor to the group – via the Members tab or by dragging the user into the group.

The auditor can then see what they need without being able to make changes.

"Why did I lose access to a client?"

There are two common causes:

  • Unpaid Catacloud invoice. If the subscription is unpaid, the client may be locked until payment is registered. See the article about the Catacloud subscription for how to find the invoice and reopen the client.

  • Access was tied to a different/old user account. If you had access via an email address you no longer use, the access does not automatically carry over to the new one. Access must be granted again to the correct user, or the login email must be changed (see below).

Changing login email, phone or 2FA

Changing the email address (username), phone number and resetting two-factor authentication (2FA) is done by us, and for security reasons the request must come from the registered email address. See the separate article: Roles, auditor access and access groups for the procedure.

When should you contact us?

You manage roles and access groups yourself as an administrator. Contact us if:

  • A user cannot perform something even after you have checked both the role and sub-permissions.

  • A field is locked during approval and you cannot identify which permission is missing.

  • You need to change a login email/phone or reset 2FA.

Always provide the client, the user's name and email, and exactly what is happening (a screenshot is helpful), so we don't have to ask again.

Did this answer your question?