Understand roles and permissions in SamBooks: who can do what
6 min read
The company roles in SamBooks — Manager, Administrative, Viewer — and what each one can see or write in every area of the platform, not just the team.
What it's for
Everyone who accesses your company in SamBooks has a role, and the role decides what they can see and change in every area of the product: invoicing, accounting, bank and F24 tax forms, warehouse and shipping, company settings. This guide explains what each of the roles assignable today — Manager, Administrative, Viewer — can actually do, across the whole platform, not just on the Team page. There's also a fourth role in the permission system, Logistics, that isn't assignable yet: covered separately below.
For the practical steps — how to invite a colleague or your accountant, how to change their role, how to remove them — there's already a dedicated guide, Invite your team and accountant in SamBooks, linked at the bottom: this one focuses on "who can do what," not "how to invite."
Before you start
- Only the Manager can invite, change the role of, or remove a team member: managing the team is itself an operation reserved to that role, as you'll see below.
- The roles assignable today, in short: Manager (full access), Administrative (all operational data, not company settings), Viewer (read-only everywhere).
- Reading company data is open to every role with access to the company: the difference between roles is mostly about what you can write.
The roles, area by area
SamBooks organizes write permissions into five functional areas. This table sums up who writes where, for the roles you can assign today; the detail for each role follows.
| Area | Manager | Administrative | Viewer |
|---|---|---|---|
| Invoicing (sales/purchase invoices, quotes, pro-forma, credit/debit notes) | Writes | Writes | Reads |
| Accounting (journal, VAT settlements, tax filings, balance sheet, registers) | Writes | Writes | Reads |
| Finance and treasury (bank, reconciliation, due items, F24) | Writes | Writes | Reads |
| Warehouse and logistics (catalog, warehouse, delivery notes, orders, shipping, returns) | Writes | Writes | Reads |
| Company settings (tax profile, team, integrations, archive, data) | Writes | Reads | Reads |
Manager
Full access: reads and writes across all five areas, including company settings — the one area reserved only for this role. It's the only role that can change the tax regime, connect or disconnect external integrations (Stripe, ClickUp, Shopify, ShippyPro), upload or remove the company logo, and manage the team.
Administrative
Writes on everything else: invoicing, accounting, finance and treasury, warehouse and logistics — the day-to-day operational work of the company. Company settings stay outside its write scope: it can view them (the tax profile, who's on the team, which integrations are connected) but not change them. In the menu, those items stay visible but appear greyed out and unclickable.
Viewer
Read-only in every area: can view invoices, journal entries, bank transactions, warehouse data, tax filings and company settings, but cannot create, edit or delete anything, in any of the five areas. If it still tries a write action — from a form or by asking Sam — it gets a permission error; the message the system returns is, verbatim: "This action is not allowed for your current role (VISUALIZZATORE): you need a role with write permissions (Manager or Administrative)."
A fourth role: Logistics, not assignable yet
The permission system also defines a fourth role, Logistics, built for people who only work in the warehouse and shipping. It doesn't show up in the table above because it isn't assignable to anyone yet: neither the Team page nor Sam offer it as an option — both stay limited to Manager, Administrative and Viewer.
How you recognize a denied permission: greyed out, not hidden
When your role can't access a section, that item doesn't disappear from the menu: it stays in place but appears faded and unclickable, with a tooltip that says "Not available for your role." It's the same behavior for an Administrative or a Viewer looking at Company settings: you can see the section exists, understand why you can't get in, and know a Manager is needed if you really need access.
If instead you try to reach the page with a direct address rather than from the menu, you don't get a technical error: you get a panel that explains why, as with the Team page ("Only the company Manager can manage the team. Ask the Manager to promote you if you need access to this section.").
The accountant isn't a role of its own
There's no separate "Accountant" role in the table above: whoever you invite as your accountant still receives one of the existing roles — typically Administrative, so they can work on the books without touching company settings, or Viewer if they only need to consult. The flag that marks them as an accountant (an "Accountant" badge next to their name in the team table) opens up access to their own Studio portal on their account: it doesn't change in any way the permissions they have on your company, which stay whatever the chosen role grants.
Ask Sam
You can ask Sam who's on the team and with what role — reading is open to everyone. Actions that change the team (inviting, changing a role, removing someone) stay reserved to the Manager even in chat: if your role doesn't allow it, Sam replies with the same permission error you'd see in the form, it doesn't perform the action "on your behalf." The same goes for a write attempt outside your own area — for example a Viewer asking Sam to register an invoice — it returns the same permission error you'd get from the form: the checks are the same, chat or page.
If something goes wrong
- A menu item is greyed out and unclickable — your role doesn't have write permission on that area: the "Not available for your role" tooltip confirms it. It's not an error: it's the permission working as intended.
- I get "This action is not allowed for your current role" while trying to save — you have a role without write permission on that area (typically Viewer). You need a role with write permission on that specific area.
- I don't find "Logistics" among the assignable roles on the Team page — it's not yet an option in either the invite form or the role-change menu: only Manager, Administrative and Viewer are assignable.
- I can't manage the team even though I'm Administrative — that's correct: managing the team is reserved to the Manager, it's not part of what the Administrative role can do.
Frequently asked questions
What's the practical difference between Administrative and Manager? Administrative writes on all the day-to-day operational work (invoices, journal, bank, F24, warehouse…) but can't touch company settings: the tax profile, integrations and team management stay with the Manager only.
Can a Viewer see amounts and sensitive data, just not edit them? Yes: read-only access in SamBooks is full read access to whatever the role can reach, not a reduced version. The limit is strictly on writing.
Can I assign the Logistics role to a colleague today? No, not yet: both the Team page and Sam only offer Manager, Administrative and Viewer as assignable roles. The Logistics role exists in the permission system but isn't assignable to anyone today.
If my role isn't enough for an action, can I work around it by asking Sam? No: Sam applies exactly the same permission checks as the form. An action denied by your role on the page is denied in chat too.
Does my accountant, with the Administrative role, have different permissions from a regular Administrative colleague? No: they have exactly the same write permissions as any other Administrative user. The "accountant" flag only opens their own Studio portal.