> ## Documentation Index
> Fetch the complete documentation index at: https://docs.investsync.co.nz/llms.txt
> Use this file to discover all available pages before exploring further.

# Members and permissions

> Control who can access organisation settings and approval workflows

## Overview

Members and permissions helps owners and authorised team members control what each person can do in an organisation.

Use it when you need to invite colleagues, review existing users, or adjust access for tasks such as approvals, billing, email automation, and report history.

## Open members and permissions

Go to **Settings**, then choose **Organisation Settings**. Open the **Members** tab and select a member from the table.

Each member has a full page showing their details, permissions, and recent activity when you have access to view it. Owners always keep full access.

## Member details

The member page shows the person’s name, email address, organisation role, and the date they joined.

If you are reviewing your own record, InvestSync marks it as **You**.

## Permission types

Each permission controls a clear area of work:

* **Approve investments**: approve or reject investment updates.
* **Manage members**: invite or remove people from the organisation.
* **Manage subscriptions**: update subscription and billing details.
* **Manage permissions**: change another user’s permissions.
* **Manage inbound email addresses**: add or update email addresses used for automated email intake.
* **Manage email automation**: choose how much InvestSync can automate from inbound emails.
* **Approve email automation**: review email items before they update investments.
* **View full report history**: see all sent report deliveries for the organisation.
* **Bulk delete transactions**: select and permanently delete multiple transactions at once.

## Update a user’s permissions

<Steps>
  <Step title="Open the member">
    Go to the Members tab in Organisation Settings and select the person you want to review from the table.
  </Step>

  <Step title="Toggle access">
    Turn a permission on to allow that person to perform the task, or off to remove that access.
  </Step>

  <Step title="Check the result">
    InvestSync shows a confirmation after the change is saved.
  </Step>
</Steps>

## Accepting an invitation

When you invite someone, they receive an email with a **View invitation** link. Opening it shows who invited them and which organisation they are joining.

Invitation links stay available for seven days. If the person does not accept in that time, send them a new invitation from the Members tab.

InvestSync checks the email address the invitation was sent to and guides the person to the right next step:

* **Already have an account**: they are taken to sign in, with their email already filled in. They just enter their password (or use a passkey or sign-in link) to accept.
* **New to InvestSync**: they are taken to a create-account form. Their email is already filled in and locked to the invited address, so they only need to add their name and a password. They then confirm their email and set up two-factor authentication to secure the account.

Once they are signed in, InvestSync accepts the invitation for them automatically, switches them into the invited organisation, and takes them to its dashboard — there is no need to confirm it a second time.

## Activity

The member page can show recent activity, such as joining the organisation, permission changes, role changes, sign-ins, and audit history.

Activity is only shown to people with the right access. If you cannot view activity, the page explains that the section is restricted.

## Good practice

Give each person only the access they need for their role. Review permissions when someone changes responsibilities, leaves the organisation, or starts helping with approvals or automation.
