Give everyone exactly the access they need
Finance software tends to offer two roles: admin and everyone else. Clyr gives you custom roles with fine-grained permissions, so the bookkeeper, the field manager, and the owner each see exactly their slice, and nothing else.
Access that fits the job, not the software
Granular by area
Permissions are set per area of the product: transactions, bills, reimbursements, vendors, reports, settings, and more. No all-or-nothing switch.
Scoped to entities
Roles follow the org chart. A role can cover one entity, several, or all of them.
Safe by default
New users start as members. Elevation is a decision someone makes, not a default someone forgets.
Access control for finance tools, done properly
Finance software tends to offer two roles: admin and everyone else. Real companies need more shades than that.
The bookkeeper
Needs to see and code everything, but has no business in company settings. In Clyr, that is one custom role.
Full books, no keysThe field manager
Needs their own region’s transactions and approvals, and should not be browsing another region’s spend. Scope the role to their slice.
Their region, their approvalsThe owner
Wants to see everything and edit nothing. Read-all, touch-nothing is a role, not a compromise.
Read all, touch nothingBuild the role once, assign it to as many people as it fits.
Who can view, code, approve, and pay
Every permission in Clyr comes down to four verbs, set separately, per area of the product.
Who can open an area at all, and what falls inside their scope.
Who can put a job, property, GL account, or custom field on what lands there.
Who signs off, on their slice only, before anything moves forward.
Who can release money, kept separate from who approved it.
That is how the bookkeeper codes without paying, the field manager approves without seeing other regions, and the owner sees everything without a single edit right. For how money movement gets approved before it gets paid, see Approval Workflows →
Roles that follow the org chart
Running multiple companies or portfolios? Roles are entity-aware. Your property accountant sees their portfolio, your regional manager sees their region, and leadership sees everything. One login each, correctly bounded.
Member by default, admin by decision
Onboarding
New users start with member access; elevation is deliberate. Nobody becomes an admin because a default said so.
Offboarding
When someone leaves, removing their access is one change, not an archaeology project, and their historical activity stays on the record for audit purposes.
The record
What people did in Clyr is tracked by user, time, and action, so the record survives the departure.
Frequently asked questions
Can I build fully custom roles?
Yes. Start from the permission areas, set view, code, approve, and pay per area, and assign the role to anyone it fits.
Can someone have access to just one entity?
Yes. Roles are entity-scoped: one entity, a subset, or all of them.
What happens when an employee leaves?
Remove their access in one change. Their historical activity stays on the record for audit purposes.
Can my bookkeeper work in Clyr without becoming an admin?
Yes. A bookkeeper role typically covers viewing and coding everything, with settings kept off. Full books, no keys.
Who can approve and pay bills?
Approval and payment are separate permissions, set per role, and payments flow through your approval rules first. See Approval Workflows for how routing works.
Is activity tracked?
Yes. Actions are recorded by user, time, and action, and the history survives personnel changes.
See it on your own spend
Book a 20-minute demo. Tell us who is on your team; we will build their roles live and show you exactly what each person would and would not see.
