VaultAP Docs

Team Management

Team Management lets Admins control who has access to your VaultAP organization and what they can do. VaultAP uses a role-based access control model with three roles: Admin, Reviewer, and Viewer.

Manage team membersAdmin ✗Reviewer ✗Viewer ✗

Inviting Users

Open Team Management

Navigate to Settings > Team Management and click Invite User.

Enter email address

Type the email address of the person you want to invite. They do not need an existing VaultAP account — one will be created when they accept the invitation.

Assign a role

Select a role from the dropdown: Admin, Reviewer, or Viewer. You can change this later.

Send invitation

Click Send Invite. The user receives an email with a link to set up their account and join your organization.

Invitations expire after 7 days. If an invitation expires, you can resend it from the Team Management page.

Roles

RoleDescription
AdminFull access to all features, settings, and user management. Can approve, reject, and escalate invoices.
ReviewerCan view invoices, vendors, and reports. Can approve, reject, and escalate invoices in the review queue. Cannot modify settings or manage users.
ViewerRead-only access to dashboards, reports, and the audit trail. Cannot take action on invoices or change any settings.

For a complete breakdown of permissions by role, see Security > Roles & Permissions.

Changing Roles

To change a user's role:

  1. Find the user in the Team Management list.
  2. Click the role badge next to their name.
  3. Select the new role from the dropdown.
  4. Confirm the change.

Role changes take effect immediately. The user does not need to log out and back in.

You cannot change your own role. Another Admin must do it. This prevents accidental lockout.

Deactivating Users

Deactivating a user immediately revokes their access to VaultAP. Their account is not deleted — all audit trail entries referencing the user remain intact for compliance purposes.

To deactivate a user:

  1. Find the user in the Team Management list.
  2. Click the more options menu (three dots) next to their name.
  3. Select Deactivate.
  4. Confirm the action.

Deactivated users can be reactivated at any time by an Admin, restoring their previous role and access.

Separation of Duties

VaultAP enforces separation of duties to prevent conflicts of interest in the review process.

A reviewer cannot approve or reject an invoice that they themselves escalated. A different reviewer or an Admin must make the final decision on escalated invoices. This rule is enforced at the system level and cannot be overridden.

This ensures that no single person can both flag an invoice for review and then clear it, reducing the risk of internal fraud or collusion.