Skip to main content

Types of Users and Their Roles

A reference guide to Docupath's user roles - Admin, Manager, Reviewer, Validator, Reviewer & Validator and Custom users

Docupath uses role-based access control (RBAC) to manage what each user can see and do. There are six roles: Administrator, Manager, Reviewer, Validator, Reviewer & Validator, and Custom.

Document-centric roles (Reviewer, Validator, Reviewer & Validator, and Custom) can be mapped to specific organizations for multi-tenant deployments. Assign roles using the principle of least privilege - give users only the access they need for their function.

How It Works

Understanding the Role Hierarchy

Roles range from broadest to narrowest access:

  • Administrator - full access to all system settings, documents, user management, and integrations

  • Manager - broad visibility and monitoring across the platform; no access to Instruction Builds

  • Reviewer, Validator, Reviewer & Validator, and Custom - document-centric roles, scoped to the organizations they are assigned to

Administrator Role

Full access to all system settings, documents, user management, and integrations. Reserved for platform owners and IT/compliance leadership. Because it carries complete control, grant this role only where it is genuinely required.

Manager Role

Broad visibility across the platform, including monitoring workflows and usage insights. A Manager does not have access to Instruction Builds. Typically assigned to business leads who oversee operations without configuring the system.

Reviewer Role

Reviews documents, makes edits, and decides whether to approve or reject them. A common fit for staff who process documents day to day, such as an external accounts payable clerk.

Validator Role

Can edit and validate documents but cannot approve or reject them. Useful when you want to separate validation from approval to create a multi-step review.

Reviewer & Validator Role

Combines the capabilities of both Reviewer and Validator, allowing full document handling - edit, validate, and approve or reject.

Custom Role

A configurable user role. You choose whether the user acts as a Reviewer, a Validator, or both, and you control which Docupath features they can access - for example, Manage organizations, Instruction builds, and Supporting files. Use Custom when none of the predefined roles matches a user's exact responsibilities.

Supported Configurations and Options

Role

Capabilities

Administrator

Full access to all system settings, documents, user management, and integrations

Manager

Broad visibility and monitoring across the platform; no access to Instruction Builds

Reviewer

Review, edit, and approve or reject documents

Validator

Edit and validate documents; cannot approve or reject

Reviewer & Validator

Full document handling (Reviewer + Validator capabilities)

Custom

Configurable as Reviewer, Validator, or both, with selectable access to specific features (e.g., Manage organizations, Instruction builds, Supporting files)

Other Technical Specifications

Aspect

Details

Access control model

Role-based access control (RBAC)

Organization scope

Document-centric roles (Reviewer, Validator, Reviewer & Validator, Custom) can be mapped to specific organizations

Self-Service Access

When enabled, document-centric users see only documents they uploaded or that are assigned to their organization; available for Reviewer, Validator, Reviewer & Validator, and Custom roles. When disabled, users follow standard visibility rules based on their role.

User invitation & status

New users receive an email invitation and show as "Pending Invite" until they accept

Audit trails

Role management is designed to support complete, transparent audit trails

Role Assignment Best Practices

Principle of Least Privilege

Start users with the lowest role that lets them do their job - Reviewer or Validator - and only escalate to Manager or Admin if required. Reserve Administrator for users who genuinely need full control.

Role Assignment Workflow

  1. Add the user: Go to Settings → Manage Users, click Add User, and enter their Name, Email, and Role. Optionally assign an Organization if their work involves documents specific to that entity.

  2. Match the role to the user's function, for example:

    • External AP clerk → Reviewer or Reviewer & Validator

    • Business lead → Manager

    • Platform owner → Admin

  3. Scope document access: For document-centric roles, set the organization and Self-Service Access so users see only the documents they should.

  4. Send the invitation: The user shows as "Pending Invite" until they accept. Use corporate email addresses for clean audit records.

Role Change Management

  • To change a user's role, edit their account under Settings → Manage Users.

  • If a user has too much access, scale them back to Reviewer or Validator.

  • If a user can't approve documents, assign Reviewer or Reviewer & Validator.

  • If a user can't see documents, check their organization assignment and Self-Service settings.

  • If a user is stuck in "Pending Invite," resend the invitation or confirm it wasn't caught in spam/junk.

  • Review role assignments quarterly to maintain compliance, and avoid shared accounts so actions remain accountable.

Notes

  • Manager has no Instruction Builds: The Manager role cannot access Instruction Builds.

  • Custom role: Lets you set Reviewer/Validator capabilities and grant access to specific features such as Manage organizations, Instruction builds, and Supporting files.

  • Self-Service Access: Controls document visibility for document-centric roles and is useful for onboarding external partners, vendors, or distributed regional teams.

  • Account hygiene: Use corporate email addresses for traceability, and avoid shared accounts for accountability.

Did this answer your question?