Settings

System Roles

Trabalance has built-in system roles that define a baseline access hierarchy — from the unrestricted Super Administrator to self-service Staff. They cannot be modified but can be supplemented with custom roles.

Navigate to: Settings → Team → Team → Add New User → System role · Settings → Team → Roles

System roles are pre-defined permission sets built into the platform. Every user holds exactly one role — a system role or a custom role. System roles work out of the box, without any configuration required.

Choosing a system role when adding a user. Switch the role to see what each one receives.

The System Roles

RoleAccess LevelWhat They Can DoTypical Assignee
Super AdministratorUnrestrictedThe account that registered the business. Full access to every module, setting and record; the only role that sees Your plan, Modules and features, API keys and Partner configuration. Marked Protected Account on the Team page — it cannot be edited or deactivated there.Business owner or the primary account holder who registered the business
AdministratorFull operational accessEvery module, every permission and every center are granted automatically when the role is chosen. Can manage users, roles, and business settings.General manager, operations director, senior accountant managing the system
SupervisorConfigurableReceives exactly the modules, per-feature permissions (Create, Read, Update, Delete, Approve), access scopes and centers you tick when creating or editing the user.Department managers, senior accountants, team leads
StaffSelf-service onlySees only their own information in the People features they are granted — own payslips, own payment requests, own personnel record. Never Reporting, never other employees' data, never business settings beyond Personal.Employees using the self-service dashboard

Role Assignment

Roles are assigned per user in Settings → Team → Team. A user holds one role: a system role, or a custom role built in Settings → Team → Roles. A custom role replaces the system role for that user — it does not stack on top of one.

What System Roles Cannot Do

System roles cannot be:

  • Edited or modified — on the Roles page they carry a System badge and no actions menu
  • Deleted — they are always available
  • Named differently — the names are permanent

If you need a permission set that does not match a system role, create a Custom Role.

⚠️Staff never reach Reporting

Staff is a hard boundary, not a default. Even a custom role built with Staff authority cannot open any report. Staff users see the Dashboard plus the People features granted to them, and only their own records within those.

ℹ️The Super Administrator is always present

Every business has the account that registered it as Super Administrator. It cannot be downgraded or deactivated from the Team page; contact Trabalance support to transfer it.