Skip to main content

Types of Users and Their Roles

A reference guide to Docupath's user roles - Admin, Manager, Reviewer, Validator, Reviewer & Validator and Custom users

Every Docupath user holds exactly one role, and that role decides which modules they see and which actions they can take. Roles are managed under Settings → Manage Users & Roles, which has two tabs: Users, where accounts are added and assigned a role, and Roles, where the roles themselves live.

Docupath ships with five system roles that cover the common ways people work with documents. Where none of them is the right fit, an admin builds a custom role on the Roles tab, choosing read and write access module by module. A custom role is named, reusable and assigned to as many users as you like.


How It Works

System Roles

System roles are built-in templates. They are read-only: you can assign them to users and duplicate them as the starting point for a custom role, but you cannot edit what they grant.

Admin

Full access to every module and setting. Admin is the only role that can manage roles, meaning the Roles tab and the role builder, and the only role that can open Billing & Payments or edit Country and Global configuration. Reserve it for platform owners and the people accountable for the tenant as a whole.

Manager

A Manager can do everything an Admin can do, apart from three things: managing roles, Billing & Payments, and the Country and Global tabs of the four per-tab configuration modules.

Those four modules are Instruction Builds, Transformations, Rejections and Customize Captured Fields. A Manager works in all four, but only on the Organization and Trading Party tabs. The Country and Global tabs are not available to a Manager.

Managers can also manage users, so the Users tab is open to them even though the Roles tab is not.

Reviewer

Works documents. A Reviewer sees the document queue, reviews documents and approves or rejects them, and can reprocess and download documents. A Reviewer cannot delete documents, cannot open the settings modules, and cannot manage users or roles.

Validator

The same shape as a Reviewer, except that a Validator validates documents rather than approving or rejecting them. Validators can reprocess and download documents, and cannot delete them.

Reviewer and Validator

Combines both: this role reviews and validates, and can reprocess and download documents. It cannot delete documents.

Custom Roles

When the five system roles do not match a job, an admin creates a custom role on the Roles tab. A custom role has a name, an optional description, and a grid of read and write checkboxes grouped by module. One custom role can be assigned to many users, so a whole team shares a single definition.

Two rules shape what a custom role can hold:

  • Country and Global configuration can only be changed by an admin. A custom role can be granted view access to the Country and Global tabs, but never write access to them.

  • Billing & Payments cannot be granted to a custom role at all. It stays with the Admin role.

Custom roles are covered in full in Creating and Managing Custom Roles.

What a Role Changes on Screen

Navigation follows read access. A user sees a module in the menu only when their role gives them at least view access to it, so the menu is already narrowed to the work they can do.

Inside a module the behavior is different: actions the role does not allow are greyed out rather than hidden, with the tooltip "You don't have permission to perform this action". A user with read-only access still sees the full picture of what the module does and what exists in it, and simply cannot act on it. That makes it obvious when someone needs wider access, instead of leaving them to wonder whether a feature exists.

A document row where the delete icon is greyed out, showing the tooltip "You don't have permission to perform this action" while the view, download and reprocess icons stay available

Two specific settings sit behind their own access:

  • Marking an organization's documents urgent requires the Priority Queue permission.

  • The Data Processing Pro setting on an organization is a billing tier rather than an access control. It grants and restricts nothing. Admins can change it and Managers can view it.


Supported Configurations and Options

Document Actions by System Role

Action

Admin

Manager

Reviewer

Validator

Reviewer and Validator

See the document queue

Yes

Yes

Yes

Yes

Yes

Approve or reject

Yes

Yes

Yes

No

Yes

Validate

Yes

Yes

No

Yes

Yes

Reprocess

Yes

Yes

Yes

Yes

Yes

Download

Yes

Yes

Yes

Yes

Yes

Delete

Yes

Yes

No

No

No

Settings Access by System Role

Area

Admin

Manager

Review roles

Users tab (Manage Users & Roles)

Yes

Yes

No

Roles tab and the role builder

Yes

No

No

Billing & Payments

Yes

No

No

Instruction Builds, Transformations, Rejections, Customize Captured Fields - Organization and Trading Party tabs

Yes

Yes

No

Instruction Builds, Transformations, Rejections, Customize Captured Fields - Country and Global tabs

Yes

No

No

All other settings modules

Yes

Yes

No

Role Types

Role type

Editable

Assignable to many users

Where it lives

System role

No, read-only template

Yes

Built in, listed on the Roles tab

Custom role

Yes, by an admin

Yes

Created on the Roles tab


Other Technical Specifications

Aspect

Details

Roles per user

One role per user

Users per role

A role can be assigned to any number of users

Role management

The Roles tab and the role builder are available to admins only

User management

The Users tab is available to anyone who can manage users, which is admins and managers

Organization scope

Document-centric roles can be mapped to specific organizations, which narrows the documents they see

Self-Service Access

When enabled on an organization, users mapped to it see only documents they uploaded or documents assigned to their organization

User invitation and status

New users receive an email invitation and show as Pending Invite until they accept

Unavailable actions

Greyed out with the tooltip "You don't have permission to perform this action", never hidden


Role Assignment Best Practices

Principle of Least Privilege

Start people on the narrowest role that lets them do their job, usually Reviewer or Validator, and widen only when the work needs it. Reserve Admin for the few people who genuinely need to manage roles, billing and Country and Global configuration.

Where a job sits between two system roles, build a custom role for it rather than moving someone up to Manager for a single module. Duplicating the closest system role gives you a starting grid to trim.

Role Assignment Workflow

  1. Add the user. Go to Settings → Manage Users & Roles, open the Users tab, click Add users, and enter their Name, Email and Role. Optionally assign one or more Organizations if their work is specific to those entities.

  2. Match the role to the job. An accounts payable clerk who approves documents fits Reviewer; someone who checks work without dispositioning it fits Validator; a business lead who configures organization-level rules fits Manager; a platform owner fits Admin.

  3. Scope document access. For document-centric roles, set the organization and Self-Service Access so people see only the documents they should.

  4. Send the invitation. The user shows as Pending Invite until they accept. Use corporate email addresses so the audit record stays clean.

Role Change Management

  • To change someone's role, edit their account on the Users tab.

  • If a user reports that a button is greyed out, read the tooltip with them and check the role's grants on the Roles tab before widening anything.

  • If a user cannot see a module at all, their role has no read access to it.

  • If a user cannot see documents, check their organization assignment and the Self-Service Access setting on that organization.

  • If a user is stuck in Pending Invite, resend the invitation or confirm it was not caught in a spam or junk folder.

  • Review role assignments quarterly, and avoid shared accounts so actions stay attributable to a person.


Notes

  • A user holds one role at a time. To give someone a combination of access that no single system role covers, build a custom role rather than trying to stack roles.

  • Managers have the four configuration modules but only their Organization and Trading Party tabs. Country and Global configuration stays with admins.

  • Billing & Payments is available to the Admin role only and cannot be granted to a custom role.

  • Deleting documents is available to admins and managers only. Users with the Reviewer, Validator or Reviewer and Validator role can reprocess and download, but not delete.

  • System roles cannot be edited. Duplicate one to use its grants as the starting point for a custom role.

  • Self-Service Access controls document visibility for document-centric roles, which makes it useful for onboarding external partners, vendors or distributed regional teams.

  • Use corporate email addresses for traceability, and avoid shared accounts so each action is attributable.

Related Articles

  • User Management - the Users and Roles tabs under Settings → Manage Users & Roles

  • Creating and Managing Custom Roles - building a reusable role on the Roles tab

  • Legacy Custom Roles - what happened to per-user custom permissions set up before roles were named

  • Filtering Users by Organization and Role - narrowing the Users tab

Did this answer your question?