Skip to content
Members & roles

Members, Roles and permissions

Updated Sep 13, 2026Web

Pippin ships Owner, Staff and CPA, and you can write your own — a bookkeeper who enters Bills but never touches the Chart of Accounts.

Before you start

A Role is a named set of permissions, and an Org can write as many as it likes. Roles are not a hierarchy — CPA is not “more than” Staff. It can write the adjusting entries at close, which Staff cannot; Staff can raise an Invoice, which CPA cannot.

Three Roles ship with every Org:

Role What it grants
Owner Everything, including people and Roles. Cannot be renamed, edited or deleted.
Staff Day-to-day work — Clients, Invoices, Payments, Bills, Expenses, Time, Services, Banking, Journal Entries, sales tax.
CPA Read the books, and write the adjusting entries at close. Nothing else.

Permissions are deliberately coarse — one per area of work, not one per button. Deciding whether the bookkeeper can touch Bills is one decision, and nine checkboxes for it would be a worse question rather than a more precise one.

Reading the books is itself a permission. An Org may want Staff raising Invoices without seeing the profit and loss, so neither Reports nor the Ledger is granted until you grant it.

Steps

Screenshot · this article

Good to know

An email address cannot sign in until an Owner has invited it. A stranger who finds your Pippin address and types their own email is turned away rather than quietly given an Org of their own.

Granting Export hands somebody a complete copy of the business, in files, somewhere Pippin cannot see. It is worth keeping to Owners.

Granting Audit is worth considering for an outside accountant — it shows who did what, without making them an Owner.

Didn't solve it?
Beta support answers within one business day.