---
id: KB-ET-002
url: https://app.codecontract.io/help/your-workspace/users-roles-and-permissions
idioma: en
categoria: espacio-de-trabajo
subcategoria: usuarios
audiencia: administrador
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-ET-001, KB-ET-003, KB-TL-003, KB-ET-021]
citadoPor: [KB-ET-001, KB-ET-003, KB-AD-001, KB-GL-001, KB-AD-003, KB-ET-004, KB-ET-005]
enLaApp: https://app.codecontract.io/settings/members
---

# Users, roles and permissions

_Who is a user, who is an external participant, and what each role can do._

**Responde a:** invite a colleague to the platform · difference between a user and an external participant · what permissions each role has · remove access for someone leaving the company · create user groups

The most common confusion when starting out is thinking you have to create accounts for your suppliers. You do not: suppliers, clients and signers are external participants and have no account. Users are only people inside your organisation.

**En corto**

- User = someone in your company, with an account and a password. Uses a licence.
- External participant = someone outside. Opens a link, has no account, uses no licence.
- Four internal roles, most to least: owner, administrator, editor and reader.
- Groups save assigning permissions person by person.

**Who is who** — The four internal roles have accounts; external participants do not, and that is the distinction most often confused at the start.

## What each role can do

| Role | Can | Cannot |
| --- | --- | --- |
| Owner | Everything, including billing and closing the account | — |
| Administrator | Configure the organisation, invite and remove people, see everything | Touch billing |
| Editor | Create processes, request documents, send for signature, certify | Change configuration or manage users |
| Reader | View and download what they are assigned | Create or modify anything |

_When in doubt, editor: that is the role of whoever does the day-to-day work._

## Inviting someone

1. **Settings → Members → Invite** — Only their email is needed. They receive an invitation to set up their access.
2. **Pick the role** — It can be changed later, so there is no need to get it right first time.
3. **Add them to a group if you have several teams** — Groups are how someone sees their department's work rather than the whole company's.

## When someone leaves

Removing access is immediate, but what they did does not vanish: the documents they uploaded, the processes they launched and the signatures they managed stay in place under their name. That is deliberate — if it disappeared, the history would stop being traceable.

> [!WARNING]
> Before removing access, check whether that person has running processes assigned to them. They can be reassigned; if you do not, they sit waiting for somebody who no longer logs in.

## Frequently asked questions

**Does a supplier count as a user?**

No. They are an external participant: they open a link, upload their part and have no account. No licence consumed.

**Can I have someone who only views, without touching anything?**

Yes, that is the reader role.

**Do groups limit what is visible?**

They organise access by team or department, so each one works with their own material.

**Can there be more than one owner?**

It is worth having at least two people able to administer, so you do not depend on a single account the day that person is away.

## Ejemplos

**A 30-person company wants each department to see only its own work, while management sees everything.**

- Creates one group per department
- Gives editor to those doing the work and reader to those who only consult
- Leaves management as administrators

→ Each team logs in and sees their own work without the rest of the noise, and management keeps the full picture.

**Everyone has administrator rights.**

- Gives each person what their job needs

→ Access stops being general by default.

**Somebody cannot do something and is made an administrator.**

- Checks which specific permission is needed

→ The minimum is granted.

**Somebody changes role and keeps their permissions.**

- Reviews permissions on role changes

→ Access follows the role.

**Nobody knows who can see what.**

- Checks permissions per person

→ The access picture exists.

**An external party needs to see one file only.**

- Grants access to that file and nothing else

→ They see theirs without reaching the rest.
