Roles and permissions
What the owner can do, what an agent can do, and the complete permission catalogue.
Prestafolio has two roles, and only two:
- Owner. You, the business owner. Can do everything, no exceptions, and is the only one who manages agents and billing.
- Agent (collector). Has no fixed bundle of permissions: they have the ones you grant, one by one. Two collectors in the same business can have completely different permissions.
Granting and revoking permissions
When you invite a collector you tick their initial permissions. Afterwards, in Agents โ row menu โ Edit permissions, you can change them whenever you like.
Important: editing permissions replaces the whole set, it does not add to it. Whatever stays ticked is exactly what they will have. If you untick everything, they end up with no permissions (they can sign in, but do nothing). And the change is immediate: if the agent is working right then, their session refreshes to apply the new permissions.
Two rules the system always enforces, no matter what you tick on screen:
- An agent can never manage agents. Agent-management permissions cannot be delegated to anyone: that is the protection against a collector escalating their own privileges or inviting people on their own.
- You cannot grant permissions from a module your plan does not include. If you try, you will see Some of those permissions are not available on your plan.
What an agent sees with no permissions at all
Even if you grant nothing, an agent who has accepted can sign in and see their own dashboard: what they collected today and this month, their assigned portfolio, their services and their cash shift. These are their figures, never the whole business's. See Collector performance.
Everything else must be granted, reading included. Without loans:read they don't see the Loans section; without clients:read, Clients; without legal:read, Legal.
Viewing is the gateway: grant reading first
Every section has a view permission (loans:read, clients:read, legal:read, services:read, cash:read, accounting:read, reports:read) and it governs the rest of that same section.
If you grantloans:createbut notloans:read, the agent doesn't see the Loans section, so there is nowhere to create one from. The permission is granted but useless.
So that this doesn't happen, ticking any permission of a section ticks its view permission too. And if you untick the view one, the rest of that section goes with it: leaving them would make no sense.
Careful: that applies within each section. Across sections nobody decides for you, and there is one combination worth knowing about ๐
Combinations that don't work (and why)
Permissions really are independent, so they can be combined in ways that don't let anyone work. These are the ones you'll run into:
You grant | What happens |
|---|---|
| They won't be able to create loans. Creating one means picking a client, and searching clients requires being able to see them. The app won't offer to create, and will tell them the client-viewing permission is missing. Same with |
Any action without its section's | The permission is useless: there is no screen to exercise it from. The picker prevents it by ticking the view one for you. |
| They can collect from the Payments section, but won't get into the loan record. A valid combination if that's what you want. |
Rule of thumb: start with what the person needs to see and then add what they need to do. If a notice says a permission is missing, take it literally: grant the one it names and the action shows up.
How much of what they see
Granting loans:read or clients:read does not open up the whole business. A collector only reaches:
- The loans assigned to them (and their payments, arrears and documents).
- The clients who have a loan of theirs.
- The services assigned to them.
In other words: the permission decides whether they see anything; the portfolio assignment decides how much. An agent with loans:read and no assigned loans will see an empty section, and that is correct.
Legal persons (attorneys and witnesses) are the exception: they belong to the business, not to a portfolio, so anyone with legal:read sees them all. Grant it only to those who really need it.
Complete permission catalogue
These are the system's real permissions, grouped by module. The Permission column is the technical identifier you will see in the app and in error messages.
Clients
Permission | What it allows |
|---|---|
| View clients (those with a loan assigned to them). It is the gateway to the section. |
| Create clients. |
| Edit clients (including uploading and deleting their files). |
| Delete clients. |
| Export the client list to CSV. |
Loans
Permission | What it allows |
|---|---|
| View the loan portfolio (the ones assigned to them). It is the gateway to the section. |
| Create loans. |
| Edit loans. |
| Delete loans. |
| Change the loan's arrears. |
| Renew a loan. |
| Archive a loan. |
| Reschedule the collection date. |
| Mark the loan as uncollectible. |
| Export the loan portfolio to CSV. |
Payments
Permission | What it allows |
|---|---|
| Record a payment. |
| Record payments in bulk. |
| Change a payment's interest. |
| Change a payment's arrears. |
| Reverse a full payment or a single payout. |
| Export the payment history to CSV. |
How the two "modify" permissions work when collecting. They do not open or close a field: they are only required when the value you send differs from the one the system calculated. Collecting the installment with its scheduled interest and the arrears the system proposes requires neither, and that is the normal path. Only if you change those figures by hand is the permission needed, and without it the collection is rejected. Two nuances: arrears are only checked if you send the field, and on an open promissory note the interest permission is never required, because there is no calculated interest to depart from (see Loan types).
Arrears
Permission | What it allows |
|---|---|
| Record the collection of an overdue amount. |
| Record arrears in bulk. |
| Change arrears interest. |
| Change arrears days or rate. |
| Mark an overdue item as uncollectible. |
Recurring services
Permission | What it allows |
|---|---|
| View services and their charges. |
| Create and edit service contracts. |
| Record the collection of a charge. |
| Reverse the collection of a charge. |
| Pause, reactivate or cancel a service. |
| Waive the arrears on a charge when collecting it. |
| Accept a partial (incomplete) payment on a charge. |
The last two are exception permissions: they let the collector take less than what is owed. Grant them only to someone you genuinely trust with that call.
Cash
Permission | What it allows |
|---|---|
| View the cash drawer. |
| View whole-business cash statistics (lent/collected), not just the shift. |
| Open the cash shift. |
| Close the shift (count). |
Accounting
Permission | What it allows |
|---|---|
| View the accounting summary (the ledger). |
| Create, post and reverse manual journal entries. |
| Close a fiscal period. |
| Set the allowance target for uncollectibles. |
| Create, edit and deactivate chart-of-accounts accounts (Premium). |
Reports, documents and others
Permission | What it allows |
|---|---|
| View the business reports (Gold and Premium). |
| View legal persons and documents. It is the gateway to the section: without it, the three below cannot be exercised. |
| Create legal persons and documents (promissory note). |
| Edit legal persons and documents. |
| Delete legal persons. |
| Access the calculator. |
Never delegable
Permission | Why it never shows up in the picker |
|---|---|
| Managing collectors is owner-only. No agent can receive them. |
| The Prestafolio subscription and payment are managed by the owner alone. |
Your plan matters too
Even if a permission exists in the catalogue, you can only grant it if your plan includes that module. For example, reports:read requires Gold or Premium; the agents module itself already requires it. Permissions your plan does not enable simply do not appear in the picker. See Plans and billing.
Common errors
Message | What happened |
|---|---|
Some of those permissions are not available on your plan | A permission from a module your plan lacks was included. None of the batch is applied: fix it and retry. |
You do not have permission to perform this action | The agent tried something you did not grant. If they should be able to, tick it in Edit permissions. |
Owner only | An agent tried to open the Agents section. It is not grantable: it belongs to the owner, period. |