Management access is granted through a scoped invitation, a role or available role template, explicit capabilities, and recorded organization hierarchy. A role name alone does not prove that a person can view or change every record in the organization, access personal financial information, or manage their own permissions.

Start from your authorized business scope

You need the relevant people-invitation capability for the organization, property, department, or service point you intend to manage. Use the current Business invitation controls to select only the role and scope available to you. The server enforces recipient binding, expiry, use limits, and the assignment; a client-entered value cannot expand that authority.

Do not promise a particular title, dashboard path, analytics view, financial access, or immediate email-delivery outcome from this guide. Share an invitation only with the intended person through an approved channel.

Confirm acceptance and actual capabilities

The recipient verifies an identity they control and accepts the invitation through the current onboarding flow when that option is shown. After the assignment is recorded, review the team record and the business controls that are actually available to the signed-in account. If a page is visible but an action is disabled, the role may have read access without the needed management capability.

Business access is separate from a person's profile, Wallet, payout account, and bank details. Do not use a management assignment to infer ownership of an employee Wallet or permission to view private financial information.

Change access deliberately

An operator can manage only people within their assigned scope and cannot use the team screen to manage their own role or assign a standard role at or above their own level. Use the currently available team and role-assignment workflow to correct an assignment. A used invitation is not a continuing access-control mechanism, and removal or deactivation behavior must be confirmed in the current product rather than promised here.

Get help safely

For an access issue, provide the authorized business scope, displayed role or capability, approximate time, and a non-sensitive error or reference. Do not send invitation codes, verification codes, passwords, payment details, bank details, or tokens.