Settings → Manage Users & Roles is where you decide who can use your Docupath tenant and what each person can do in it. It has two tabs:
Users lists the accounts in your tenant. This is where you invite people, assign a role, map them to organizations and remove accounts. It is available to anyone who can manage users, which is admins and managers.
Roles lists the roles themselves, both the five built-in system roles and any custom roles your tenant has. This is where custom roles are created and edited. It is available to admins only.
Every user holds exactly one role, and that role decides which modules appear in their menu and which actions they can take once inside. Where none of the system roles fits a job, an admin builds a named custom role from a read and write grid and assigns it to as many users as needed.
The Filters button at the top right of the Users tab narrows the list by organization and by user role. See Filtering Users by Organization and Role.
How It Works
Adding Users
New users are added from the Users tab under Settings → Manage Users & Roles:
Click Add users
Provide the user's Name, Email and Role. The role list holds the five system roles and every custom role in your tenant
Optionally assign one or more Organizations, which narrows the documents the user sees
Save. Docupath sends an email invitation to the user
Until the user accepts the invitation, their status shows as Pending Invite. If the invitation does not arrive, resend it or ask the user to check spam and junk folders.
Note: Adding and editing users requires the ability to manage users, which admins and managers have. Creating or changing the roles themselves requires the Admin role.
Editing Users
On the Users tab, click the edit (pencil) icon on the user's row in the Actions column. The Edit user dialog opens.
Update the user's Name or Role as needed. The Email field cannot be changed.
Click Save to apply your changes, or Cancel to discard them.
Changing someone's role takes effect immediately, though the user may need to refresh their session before the change shows up on screen.
Deleting Users
On the Users tab, click the delete (trash) icon on the user's row in the Actions column.
Confirm the deletion when prompted.
You cannot delete your own account. The delete icon is disabled on the row marked YOU.
System Roles
Docupath ships with five system roles. They are read-only templates: assign them or duplicate them as the starting point for a custom role, but you cannot edit what they grant.
Role | Capabilities |
Admin | Full access to every module and setting. The only role that can manage roles, open Billing & Payments, or edit Country and Global configuration |
Manager | Everything an Admin can do apart from managing roles, Billing & Payments, and the Country and Global tabs of the four per-tab configuration modules |
Reviewer | Works documents: sees the queue, reviews and approves or rejects, and can reprocess and download. Cannot delete documents or open settings modules |
Validator | The same as Reviewer, except validating rather than approving or rejecting. Can reprocess and download, cannot delete |
Reviewer and Validator | Both reviews and validates, and can reprocess and download. Cannot delete |
Deleting documents is available to admins and managers only.
The four per-tab configuration modules are Instruction Builds, Transformations, Rejections and Customize Captured Fields. Managers have all four, but only their Organization and Trading Party tabs. Country and Global configuration stays with admins.
For the full breakdown, see Types of Users and Their Roles.
Custom Roles
On the Roles tab, an admin builds a custom role from a read and write grid grouped by module, gives it a name and an optional description, and assigns it to as many users as needed. Write implies read: turning on write auto-checks read and locks it.
The four configuration modules expand into four rows each, Organization, Trading Party, Country and Global, with independent read and write on every row. Two limits apply: Country and Global can be granted view access but never write, because only admins change that configuration, and Billing & Payments cannot be granted to a custom role at all.
A role that is assigned to users cannot be deleted. See Creating and Managing Custom Roles.
Tenants that previously set custom permissions on individual accounts have those carried over as named legacy custom roles with the same effective access. See Legacy Custom Roles.
What a Role Changes on Screen
Navigation follows read access: a user sees a module only when their role gives them at least view access to it. Inside a module, actions the role does not allow are greyed out, not hidden, so a read-only user still sees the whole module and simply cannot act on it.
Organization Assignment
Users can be mapped to specific organizations, which narrows the documents they see:
With Self-Service Access enabled: Users see only documents they uploaded or those assigned to their mapped organization
With Self-Service Access disabled: Users follow standard visibility rules based on their role
Unmapped non-admin users: See all non-self-service organizations
Admin users: See everything, including self-service organizations
Least-Privilege Principle
Start users on the most restrictive role that lets them do the job, usually Reviewer or Validator, and widen only when the work needs it. Where someone sits between two system roles, build a custom role for that job rather than promoting them to Manager for a single module.
This keeps security risk low and separation of duties clear.
Supported Configurations and Options
Configuration | Detail |
Tabs | Users (admins and managers) and Roles (admins only) |
System roles | Admin, Manager, Reviewer, Validator and Reviewer and Validator |
Custom roles | Named, reusable, built from a read and write grid grouped by module |
Roles per user | One |
Users per role | Any number |
User fields | Name, Email, Role, Organization Assignment (optional) |
Invitation workflow | Email-based invitation with Pending Invite status tracking |
Self-service interaction | Organization assignment plus Self-Service Access equals scoped document visibility |
Organization mapping | Optional; determines document visibility |
Other Technical Specifications
Parameter | Detail |
Invitation delivery | Email-based; pending until accepted |
Role editing | System roles are read-only. Custom roles are editable by admins |
Role deletion | A role assigned to at least one user cannot be deleted |
Billing & Payments | Admin role only; cannot be granted to a custom role |
Country and Global configuration | Editable by admins only; a custom role can be granted view access |
Unavailable actions | Greyed out with a tooltip, never hidden |
Notes
Users stuck in Pending Invite status may need the invitation resent or delivery confirmed (check spam and junk folders)
Shared accounts should be avoided for audit accountability, so each person should have their own credentials
Organization assignment is optional; unassigned non-admin users default to broad visibility across all non-self-service organizations
Role changes take effect immediately but may require the user to refresh their session
There is no bulk user import, so users are added individually through the UI
Managers can manage users but not roles, so a manager can move someone onto an existing role but cannot change what that role grants
Related Articles
Types of Users and Their Roles - the five system roles and what each one covers
Creating and Managing Custom Roles - building a reusable role on the Roles tab
Legacy Custom Roles - per-user custom permissions carried over as named roles
Filtering Users by Organization and Role - narrowing the Users tab


