Roles and Permissions
Understand firm roles, membership types, staff client access, assignments, and client portal access.
Wesley uses several access layers. A title such as Staff or an assignment to a client does not, by itself, describe everything a person can do.
Access model
Work through these questions in order:
- Is the person a firm member or a client portal user?
- For a firm member, are they Internal or Extended?
- What firm role do they have: Owner, Manager, or Staff?
- If they are Staff, what is their effective access to this client: Write, Read-only, or No access?
- Are they assigned to the client for workflow ownership?
Firm roles
| Role | Firm and client access | Team management |
|---|---|---|
| Owner | Full access to all clients | Can invite owners and managers, change roles (including lowering another Owner), manage staff, and remove non-owner members. |
| Manager | Full access to all clients | Can invite Managers or Staff and manage existing Staff. Cannot change roles or manage an Owner or existing Manager. |
| Staff | Controlled by default and per-client access settings | Cannot manage firm members from the Members page. |
An Owner cannot edit or remove their own membership from the member-management page. Only an internal Owner can change another Owner’s role; lower that Owner to Manager or Staff before removing them.
For Book Close, any firm member with effective client write access can start a close, manage its linked client tasks, submit it, or move a submitted close back to in progress. Only an Owner or Manager can request changes, approve, undo approval, or apply the final journal-period lock. Reopening also requires Manager or Owner control access and a written reason.
Membership types
- Internal is for the accounting firm’s team members.
- Extended is for external contractors, outsourced teams, or seasonal staff.
Extended members are Staff. They cannot hold Owner or Manager role, grant Internal membership, or manage client assignments.
Membership type is not client portal access. An external accountant who works inside the books may be an Extended firm member; a client contact who responds in the portal should be invited through Client Access instead.
Staff client access
Staff members receive one Default client access value:
- Write: can view and edit all clients covered by the default.
- Read-only: can view those clients without normal editing rights.
- No access: cannot access client data by default.
After the invitation is accepted, an owner or manager can open Members, select Manage for the Staff member, and set an individual client to Default, Write, Read-only, or No access. Default inherits the member’s current default; the other values are explicit overrides.
The member detail shows the Effective value for each client. Use that value when diagnosing why a user can edit, only view, or cannot open a client.
Assignments do not grant access
Assignments identify who is responsible for a client and drive portfolio views and workflow. They are managed from the portfolio’s Assign action or Client Settings → Assignments.
Only members who already have client access can be assigned. If a person is missing from the assignment choices, fix their effective client access first. Internal owners and managers manage assignments; Extended members can view applicable assignment information but cannot change assignments.
Client portal access is separate
Use Client Settings → Client Access to manage client-facing access:
- Review the portal URL and the All, Active, and Pending lists.
- Select Invite, enter the client contact’s email, and select Send Invite.
- For an active portal user, turn document request emails on or off or choose Revoke access.
- For a pending user, choose Cancel invitation if it should no longer be accepted.
Portal access applies to that client portal. It does not add the person to Members, assign them to the client, or grant access to the firm-side accounting workspace.
Permission checklist
Before changing access, confirm:
- the correct firm and person;
- whether they need the firm workspace or only the client portal;
- whether they are part of the firm team or an external contributor;
- whether they should edit, view, or have no access to each client;
- whether an assignment is also needed for responsibility tracking.
Use the least access that supports the person’s work. After saving, verify the member’s Access summary and the client’s Effective access rather than relying only on the invitation settings.