Team Management
Team Management lets Admins control who has access to your VaultAP organization and what they can do. VaultAP uses a role-based access control model with three roles: Admin, Reviewer, and Viewer.
Inviting Users
Open Team Management
Navigate to Settings > Team Management and click Invite User.
Enter email address
Type the email address of the person you want to invite. They do not need an existing VaultAP account — one will be created when they accept the invitation.
Assign a role
Select a role from the dropdown: Admin, Reviewer, or Viewer. You can change this later.
Send invitation
Click Send Invite. The user receives an email with a link to set up their account and join your organization.
Invitations expire after 7 days. If an invitation expires, you can resend it from the Team Management page.
Roles
| Role | Description |
|---|---|
| Admin | Full access to all features, settings, and user management. Can approve, reject, and escalate invoices. |
| Reviewer | Can view invoices, vendors, and reports. Can approve, reject, and escalate invoices in the review queue. Cannot modify settings or manage users. |
| Viewer | Read-only access to dashboards, reports, and the audit trail. Cannot take action on invoices or change any settings. |
For a complete breakdown of permissions by role, see Security > Roles & Permissions.
Changing Roles
To change a user's role:
- Find the user in the Team Management list.
- Click the role badge next to their name.
- Select the new role from the dropdown.
- Confirm the change.
Role changes take effect immediately. The user does not need to log out and back in.
You cannot change your own role. Another Admin must do it. This prevents accidental lockout.
Deactivating Users
Deactivating a user immediately revokes their access to VaultAP. Their account is not deleted — all audit trail entries referencing the user remain intact for compliance purposes.
To deactivate a user:
- Find the user in the Team Management list.
- Click the more options menu (three dots) next to their name.
- Select Deactivate.
- Confirm the action.
Deactivated users can be reactivated at any time by an Admin, restoring their previous role and access.
Separation of Duties
VaultAP enforces separation of duties to prevent conflicts of interest in the review process.
A reviewer cannot approve or reject an invoice that they themselves escalated. A different reviewer or an Admin must make the final decision on escalated invoices. This rule is enforced at the system level and cannot be overridden.
This ensures that no single person can both flag an invoice for review and then clear it, reducing the risk of internal fraud or collusion.