**Source:** https://heykiku.com/help/manage-team-permissions

# Manage Team Permissions

Beyond roles, heykiku gives you fine-grained control over what each team member can do with four permission toggles. Roles set the baseline tier each person can reach — see [how the four access tiers work](https://heykiku.com/help/access-control) — and these toggles refine what they can do within it.

## The Four Permissions

| Permission | What It Controls |
|------------|-----------------|
| **Upload** | Upload documents and record voice memos |
| **Approve** | Approve documents, edit approved extractions, replace files, access Insights |
| **Organize** | Create, edit, and delete folders; move documents between folders |
| **Billing** | View and manage billing, change plan, buy add-ons, update payment method |

Owners always have all four permissions. For everyone else, you can toggle Upload, Approve, and Organize individually. **Billing is special** — it can only be granted to Admins, and only the Owner can grant it.

## Where to Manage

1. Go to **Settings** → **Team**
2. The members table shows columns for Upload, Approve, Organize, and Billing
3. Toggle the switches for any member

Each toggle change saves immediately. You'll see a confirmation toast like "Upload permission enabled" or "Billing access granted."

## Role Defaults

When you invite someone or change their role, permissions reset to that role's defaults:

| Role | Upload | Approve | Organize | Billing |
|------|--------|---------|----------|---------|
| Owner | Always on | Always on | Always on | Always on |
| Admin | On | On | On | Off |
| Employee | On | Off | On | — |
| Freelancer | Off | Off | Off | — |

You can override Upload, Approve, and Organize per person. Billing only applies to Admins — Employees and Freelancers show an em dash because the grant doesn't apply to them.

## Billing Access

Billing actions are owner-only by default. If you want an Admin to handle invoices, plan changes, or add-on purchases on your behalf, toggle their Billing switch on.

- Only the **Owner** can grant or revoke Billing
- Only **Admins** are eligible — the toggle doesn't appear for Employees or Freelancers
- The grant survives role changes within Admin tier and is revoked automatically if you tier the member down

## Tier-Down Restriction

Admins can manage members at a strictly lower role tier than their own — they cannot mutate users at the same tier or above. In practice: admins can change employee and freelancer settings, but not other admins or the owner. Demoting an admin automatically revokes their Billing permission — you don't need to remove it manually first.

## Restrictions

- You can't change your own permissions (prevents locking yourself out)
- Owner permissions are always on and can't be toggled
- Changing someone's role resets their permissions to the new role's defaults
- Billing can't be set during invite — grant it after the member accepts

## Inviting with Custom Permissions

When [inviting a new member](https://heykiku.com/help/invite-team-members), the invite modal shows Upload, Approve, and Organize toggles pre-filled from the selected role's defaults. You can override them before sending the invite. Billing isn't in the invite flow — grant it from the team table after the invite is accepted.

## Related terms

- [Freelancer Access Control](https://heykiku.com/glossary/freelancer-access-control)
- [Team Onboarding](https://heykiku.com/glossary/team-onboarding)
- [Offboarding](https://heykiku.com/glossary/offboarding)
