BookTrove user guide · Chapter 3

3. Users, roles and approvals

Steps in this chapter (11)

11 steps, each with a screenshot · Chapter 3 of 20

Each person has their own login and a role in each company. The role decides what they see and what they may do, area by area. Approvals add a second pair of eyes to purchase orders and payments.

In the illustration, Aisha Bello adds Chukwudi Okeke as administrator; Chukwudi then adds the team at head office, the factory and the buying centres, and invites the company's external accountant, Nkechi Okafor of Okafor Bello & Co.

3.1 Add a person

Screenshot: Users & roles → Add a person
Figure 3.1 — Users & roles → Add a person

Why

People are added by an owner or administrator; there is no self-registration. The role can be changed later. Each active or invited person who is not an external accountant takes one user seat of the subscription (chapter 15).

Who

Owner or administrator.

What to do

  1. Open Users & roles and click Add a person. Type the email address (1) and the name.
  2. Choose the role (2) — see the next steps and Appendix A — and click Add.

Back to top ↑

3.2 Give the temporary password privately

Screenshot: BookTrove creates a one-time temporary password
Figure 3.2 — BookTrove creates a one-time temporary password

Why

A new person gets a temporary password (1). Give it to them in person, by phone or in a separate message — never in the same email as the sign-in address. At first sign-in they set up two-factor and choose their own password.

Who

The owner or administrator who added the person.

What to do

  1. Note the temporary password and pass it on privately. Close the window.

Back to top ↑

3.3 The new person's first sign-in

Screenshot: After setting up two-factor, the person chooses their own password
Figure 3.3 — After setting up two-factor, the person chooses their own password

Why

The first sign-in goes through the two-factor set-up (chapter 1) and then asks for a new password (1). The temporary password stops working.

Who

The new person.

What to do

  1. Type the temporary password, then the new password twice, and click Save password.

Back to top ↑

3.4 Roles and permissions

Screenshot: Users & roles → Roles and permissions
Figure 3.4 — Users & roles → Roles and permissions

Why

BookTrove has ready-made roles — Owner, Administrator, Accountant (1), External accountant, Bookkeeper, Sales, Purchasing, Inventory manager, Production manager, Auditor, Reports only and Employee — and custom roles (2) (3). Each role has one of five levels in each of fifteen areas: None, View, Prepare (create drafts and submit), Approve (post, including other people's work) and Full (also void and change the area's settings). Roles marked ⚿ may post into soft-locked periods.

Who

Owner or administrator.

What to do

  1. Read across a row to see what a role allows. Appendix A lists every ready-made role.
  2. Click New custom role to make your own, or click a custom role to change it.

Back to top ↑

3.5 A custom role for buying officers

Screenshot: New custom role: Buying officer
Figure 3.5 — New custom role: Buying officer

Why

Savannah Harvest's buying officers raise requisitions and purchase orders, receive produce into their centre's store and claim expenses, but do not pay suppliers or see the accounts. None of the ready-made roles fits, so Chukwudi made one. A second custom role, Payroll & HR officer, lets Blessing Etim approve staff expense claims and view the payroll accounts.

Who

Owner or administrator.

What to do

  1. Name the role (1) and describe it.
  2. Choose the level for each area: Prepare for purchases (2), Approve for inventory so that goods received can be posted (3), Prepare for expense claims (4), and None elsewhere.
  3. Click Save. You cannot give a role more access than your own.

Back to top ↑

3.6 What a buying officer sees

Screenshot: Musa Lawal's menu after his first sign-in
Figure 3.6 — Musa Lawal's menu after his first sign-in

Why

The menu (1) shows only the areas Musa's role allows: purchases, contacts, approvals, expense claims, requisitions, price lists and inventory. The dashboard shows only what he owes suppliers.

Who

Musa Lawal, buying officer at Lafia.

What to do

  1. Check with each new person that they see what they need, and nothing more.

Back to top ↑

3.7 Invite the external accountant

Screenshot: An existing BookTrove login is invited, not created
Figure 3.7 — An existing BookTrove login is invited, not created

Why

Nkechi Okafor already uses BookTrove for her own firm. Adding her email address therefore sends an invitation to her existing login (1); she gets access only when she accepts, with her own password and authenticator. The External accountant role has the same accounting powers as the Accountant role and does not take a user seat.

Who

Owner or administrator.

What to do

  1. Add the person with the role External accountant.
  2. Before they accept, confirm with them by phone that the login is theirs.

Back to top ↑

3.8 Accept an invitation

Screenshot: Companies → Invitations, as Nkechi sees it
Figure 3.8 — Companies → Invitations, as Nkechi sees it

Why

Invitations appear under Companies (and as a notice on the dashboard). Accept only invitations you expected.

Who

The person invited.

What to do

  1. Click Accept (1) to join the company, or Decline (2).
  2. Switch to the company with the Company box.

Back to top ↑

3.9 The people list

Screenshot: Users & roles → People
Figure 3.9 — Users & roles → People

Why

The list shows each person's role, whether their access is active, invited (1) or switched off, whether two-factor is set up, and their last sign-in (2).

Who

Owner or administrator.

What to do

  1. Click Change to give someone another role or switch their access off. A new role takes effect at once.
  2. Click Reset 2FA only when someone has lost both their phone and their recovery codes, after checking their identity in person or by video call. You will need your own current code.

Back to top ↑

3.10 Access review

Screenshot: Users & roles → Access review
Figure 3.10 — Users & roles → Access review

Why

A list of every person with their role, permissions and two-factor status (1), for a periodic review of who can do what — and for the auditors.

Who

Owner, administrator or auditor.

What to do

  1. Review it at least every quarter and remove access that is no longer needed. Export it from Reports → User access review.

Back to top ↑

3.11 The approvals inbox

Screenshot: Approvals: items waiting for a second person
Figure 3.11 — Approvals: items waiting for a second person

Why

With approvals switched on (chapter 2), a purchase order or payment prepared by one person waits here until someone else with approval rights posts it (1). The preparer cannot approve their own item while another approver exists. Drafts not yet submitted are listed below.

Who

Anyone with Approve level in the area.

What to do

  1. Click Open to review the item, then Approve. Or approve straight from the list.

Back to top ↑