How to Invite Users and Assign Roles in CrmLeaf
All editions. Core feature - no add-on required. The number of users you can add is limited by your plan's seat limit.
Availability: All editions. Core feature - no add-on required. The number of users you can add is limited by your plan's seat limit.
Overview
Every person who works in CrmLeaf is a user inside your Company, and every user carries a role. The role decides what kind of participant they are; the permission scope attached to that role decides which records they see. Getting the role right at invitation time avoids most later access problems.
This article covers the three roles that ship with every new account, how to bring users in, and how seats are limited by your plan.
How It Works
You invite a person, they receive an invitation, and they become a user in your Company with a role. Employees are users with an employee record attached. Clients are also real user accounts, which is what gives them a portal login.
Choose role → Invite → User accepts → Assign permission scope → Assign work
- Every new Company is created with three roles: admin with full access, employee with access to assigned work, and client with access to their own tasks and projects.
- Employees can be brought in three ways: an email or link invitation, a CSV import, or an interactive import grid that validates each row before it is accepted.
- An employee record is paired one-to-one with a user account and holds reporting manager, designation, department, bank details, nominees, skills, documents and visas.
- A client is a real user account, so clients can sign in to the client portal and see their invoices, estimates, proposals and contracts.
- Your plan's seat limit is enforced when you add users, so an invitation can be refused if the account is at its limit.
- Which modules a role can reach is driven by your package, and the ownership scope for each module is set per role.
Who Can Use This Feature?
Administrator
- Invite users and assign their role.
- Import employees in bulk and correct rows that fail validation.
- Set the ownership permission scope for each role and module.
- Monitor the account against its seat limit.
This functionality is available only to Administrators.
Prerequisites
- The company profile is complete.
- Designations and departments exist, if you are adding employees who need them.
- Seats are available under your plan's limit.
- You have decided the role and permission scope each person needs.
The Three Default Roles
| Role | What it is for | Typical access |
|---|---|---|
| admin | Runs the account | Full access, including settings, modules and permissions |
| employee | Internal staff | The work assigned to them, within the ownership scope set for each module |
| client | External customers | Their own tasks and projects, plus their documents through the client portal |
For Administrators
Step 1: Decide the role before you invite
What to do: Choose admin only for people who must configure the account. Choose employee for staff. Choose client for customers who need portal access. Keep the number of Administrators small - the role has full access to settings and permissions.
What to verify: Each person on your list has exactly one intended role.
Step 2: Invite an employee
What to do: Add the employee and complete the record, including reporting manager, designation and department. Invite the person by email or by invitation link so they can set their own password.
What to verify: The employee appears in the list, and the invitation reaches the address you entered.
Step 3: Import several employees at once
What to do: Use Import for a CSV file, or use the interactive import grid, which validates row by row so you can correct problems before the records are created.
What to verify: The import reports no failed rows, and the expected number of employees appears in the list.
Step 4: Add a client user
What to do: Create the client record with its company profile and contacts. Because a client is a real user account, the client can sign in to the portal to view invoices, estimates, proposals and contracts.
What to verify: The client can reach the portal, and sees only their own documents.
Step 5: Set the permission scope for each role
What to do: For each module, set the ownership scope the role should have -
none, owned, added, both or all. This is what
decides which records a user sees, not simply whether a page opens.
What to verify: Sign in as a test user in that role and confirm the record list contains what you expect and nothing more.
Step 6: Check your seat usage
What to do: Keep track of how many users your plan allows. The seat limit is enforced when you add users.
What to verify: You can still add the users you have planned. If not, review the plan before the rollout date.
Expected Result
Each person is a user in your Company with the correct role, employees have an employee record, clients can sign in to the client portal, and each role sees only the records its ownership scope allows.
Service Organisation Context
The three default roles map onto how service organisations are staffed. Consultants and delivery staff are employee users with an employee record attached, which is what allows their assigned work, time and leave to be tracked. A client is a real user account, so the client organisation an engagement is delivered for can sign in to the portal and see its own invoices, estimates, proposals and contracts without internal visibility. Keep admin to the few people who configure the account. Seat limits belong to the whole Company, so count client users into the plan before onboarding a delivery team. Any business with staff and customers uses the same three roles.
Important Notes
- Menu names and their position can differ between product editions and can be customised for your account, so your sidebar may not match these paths exactly. Use Search or your Quick Access items if you cannot find a screen.
- The same email address can be a user in several Companies. Inviting someone who already uses CrmLeaf elsewhere adds them to your account; they switch between accounts with the workspace picker.
- Roles are set per Company. A person who is an Administrator in one account is not automatically an Administrator in yours.
- Which modules a role can reach comes from your package. If a module is missing for a role, check the package before changing permissions.
- Users work inside the Organization they have selected. Brief new users on the workspace picker.
Common Scenarios
Example: onboarding a sales team. The Administrator imports 12
representatives with the import grid, assigns them the employee role, and sets the Leads scope to
owned so each representative works only their own leads. The sales manager keeps the same role but a
scope of all.
Example: giving a customer visibility. A client asks to follow project progress. The Administrator creates the client record, which is a real user account, so the client signs in to the portal and sees their own projects and documents without access to internal data.
Troubleshooting
| Issue | Possible Cause | Resolution |
|---|---|---|
| You cannot add another user | The account has reached the seat limit set by its plan | Review the plan, or remove users who no longer need access. |
| An imported row was rejected | Mandatory data was missing or invalid in that row | Use the import grid, correct the flagged row and import again. |
| A user can open a module but sees no records | Their role's scope for that module is owned or added and nothing is assigned to them | Assign records to them, or widen the scope to both or all. |
| A user cannot see a module at all | The module is not available to that role under the account's package, or the add-on is not enabled | Check module availability for the account, then check the role's permission. |
| A client cannot sign in to the portal | The client user account was not completed | Re-check the client record and re-send the invitation. |
Frequently Asked Questions
What is the difference between the employee and client roles?
An employee is internal staff who work on assigned records. A client is an external customer who sees their own tasks and projects and their own documents through the portal.
Can I have more than one Administrator?
Yes. The admin role has full access, so grant it only to people who must configure the account.
Do clients count towards my seat limit?
Seat limits are enforced against the account's user count under its plan.
How do I stop a representative from seeing other people's leads?
Set the Leads permission scope for their role to owned. See the article on ownership-based
permissions.
Related Articles
Our support team answers on business days. Reference PLT-05 so we can jump straight in.