Every Docupath user holds exactly one role, and that role decides which modules they see and which actions they can take. Roles are managed under Settings → Manage Users & Roles, which has two tabs: Users, where accounts are added and assigned a role, and Roles, where the roles themselves live.
Docupath ships with five system roles that cover the common ways people work with documents. Where none of them is the right fit, an admin builds a custom role on the Roles tab, choosing read and write access module by module. A custom role is named, reusable and assigned to as many users as you like.
How It Works
System Roles
System roles are built-in templates. They are read-only: you can assign them to users and duplicate them as the starting point for a custom role, but you cannot edit what they grant.
Admin
Full access to every module and setting. Admin is the only role that can manage roles, meaning the Roles tab and the role builder, and the only role that can open Billing & Payments or edit Country and Global configuration. Reserve it for platform owners and the people accountable for the tenant as a whole.
Manager
A Manager can do everything an Admin can do, apart from three things: managing roles, Billing & Payments, and the Country and Global tabs of the four per-tab configuration modules.
Those four modules are Instruction Builds, Transformations, Rejections and Customize Captured Fields. A Manager works in all four, but only on the Organization and Trading Party tabs. The Country and Global tabs are not available to a Manager.
Managers can also manage users, so the Users tab is open to them even though the Roles tab is not.
Reviewer
Works documents. A Reviewer sees the document queue, reviews documents and approves or rejects them, and can reprocess and download documents. A Reviewer cannot delete documents, cannot open the settings modules, and cannot manage users or roles.
Validator
The same shape as a Reviewer, except that a Validator validates documents rather than approving or rejecting them. Validators can reprocess and download documents, and cannot delete them.
Reviewer and Validator
Combines both: this role reviews and validates, and can reprocess and download documents. It cannot delete documents.
Custom Roles
When the five system roles do not match a job, an admin creates a custom role on the Roles tab. A custom role has a name, an optional description, and a grid of read and write checkboxes grouped by module. One custom role can be assigned to many users, so a whole team shares a single definition.
Two rules shape what a custom role can hold:
Country and Global configuration can only be changed by an admin. A custom role can be granted view access to the Country and Global tabs, but never write access to them.
Billing & Payments cannot be granted to a custom role at all. It stays with the Admin role.
Custom roles are covered in full in Creating and Managing Custom Roles.
What a Role Changes on Screen
Navigation follows read access. A user sees a module in the menu only when their role gives them at least view access to it, so the menu is already narrowed to the work they can do.
Inside a module the behavior is different: actions the role does not allow are greyed out rather than hidden, with the tooltip "You don't have permission to perform this action". A user with read-only access still sees the full picture of what the module does and what exists in it, and simply cannot act on it. That makes it obvious when someone needs wider access, instead of leaving them to wonder whether a feature exists.
Two specific settings sit behind their own access:
Marking an organization's documents urgent requires the Priority Queue permission.
The Data Processing Pro setting on an organization is a billing tier rather than an access control. It grants and restricts nothing. Admins can change it and Managers can view it.
Supported Configurations and Options
Document Actions by System Role
Action | Admin | Manager | Reviewer | Validator | Reviewer and Validator |
See the document queue | Yes | Yes | Yes | Yes | Yes |
Approve or reject | Yes | Yes | Yes | No | Yes |
Validate | Yes | Yes | No | Yes | Yes |
Reprocess | Yes | Yes | Yes | Yes | Yes |
Download | Yes | Yes | Yes | Yes | Yes |
Delete | Yes | Yes | No | No | No |
Settings Access by System Role
Area | Admin | Manager | Review roles |
Users tab (Manage Users & Roles) | Yes | Yes | No |
Roles tab and the role builder | Yes | No | No |
Billing & Payments | Yes | No | No |
Instruction Builds, Transformations, Rejections, Customize Captured Fields - Organization and Trading Party tabs | Yes | Yes | No |
Instruction Builds, Transformations, Rejections, Customize Captured Fields - Country and Global tabs | Yes | No | No |
All other settings modules | Yes | Yes | No |
Role Types
Role type | Editable | Assignable to many users | Where it lives |
System role | No, read-only template | Yes | Built in, listed on the Roles tab |
Custom role | Yes, by an admin | Yes | Created on the Roles tab |
Other Technical Specifications
Aspect | Details |
Roles per user | One role per user |
Users per role | A role can be assigned to any number of users |
Role management | The Roles tab and the role builder are available to admins only |
User management | The Users tab is available to anyone who can manage users, which is admins and managers |
Organization scope | Document-centric roles can be mapped to specific organizations, which narrows the documents they see |
Self-Service Access | When enabled on an organization, users mapped to it see only documents they uploaded or documents assigned to their organization |
User invitation and status | New users receive an email invitation and show as Pending Invite until they accept |
Unavailable actions | Greyed out with the tooltip "You don't have permission to perform this action", never hidden |
Role Assignment Best Practices
Principle of Least Privilege
Start people on the narrowest role that lets them do their job, usually Reviewer or Validator, and widen only when the work needs it. Reserve Admin for the few people who genuinely need to manage roles, billing and Country and Global configuration.
Where a job sits between two system roles, build a custom role for it rather than moving someone up to Manager for a single module. Duplicating the closest system role gives you a starting grid to trim.
Role Assignment Workflow
Add the user. Go to Settings → Manage Users & Roles, open the Users tab, click Add users, and enter their Name, Email and Role. Optionally assign one or more Organizations if their work is specific to those entities.
Match the role to the job. An accounts payable clerk who approves documents fits Reviewer; someone who checks work without dispositioning it fits Validator; a business lead who configures organization-level rules fits Manager; a platform owner fits Admin.
Scope document access. For document-centric roles, set the organization and Self-Service Access so people see only the documents they should.
Send the invitation. The user shows as Pending Invite until they accept. Use corporate email addresses so the audit record stays clean.
Role Change Management
To change someone's role, edit their account on the Users tab.
If a user reports that a button is greyed out, read the tooltip with them and check the role's grants on the Roles tab before widening anything.
If a user cannot see a module at all, their role has no read access to it.
If a user cannot see documents, check their organization assignment and the Self-Service Access setting on that organization.
If a user is stuck in Pending Invite, resend the invitation or confirm it was not caught in a spam or junk folder.
Review role assignments quarterly, and avoid shared accounts so actions stay attributable to a person.
Notes
A user holds one role at a time. To give someone a combination of access that no single system role covers, build a custom role rather than trying to stack roles.
Managers have the four configuration modules but only their Organization and Trading Party tabs. Country and Global configuration stays with admins.
Billing & Payments is available to the Admin role only and cannot be granted to a custom role.
Deleting documents is available to admins and managers only. Users with the Reviewer, Validator or Reviewer and Validator role can reprocess and download, but not delete.
System roles cannot be edited. Duplicate one to use its grants as the starting point for a custom role.
Self-Service Access controls document visibility for document-centric roles, which makes it useful for onboarding external partners, vendors or distributed regional teams.
Use corporate email addresses for traceability, and avoid shared accounts so each action is attributable.
Related Articles
User Management - the Users and Roles tabs under Settings → Manage Users & Roles
Creating and Managing Custom Roles - building a reusable role on the Roles tab
Legacy Custom Roles - what happened to per-user custom permissions set up before roles were named
Filtering Users by Organization and Role - narrowing the Users tab

