User Management
Gäld uses role-based access control (RBAC) within each organisation. You can invite colleagues, accountants, and read-only stakeholders — each with the exact level of access they need.
Roles
| Role | Who it's for | Key permissions |
|---|---|---|
| Owner | The person who created the organisation | All permissions, including deleting the organisation |
| Admin | Finance manager, accountant, trusted deputy | All permissions except deleting the organisation |
| Member | Bookkeeper, staff who create expenses or invoices | Create, edit, approve, finalize, import, reconcile — no delete, no user management |
| Viewer | Board member, investor, read-only accountant | View all data, download PDFs and exports — cannot create or modify anything |
Ownership can be transferred but there is always exactly one Owner. The Owner role cannot be removed or downgraded by other Admins.
Detailed permission matrix
| Action | Owner | Admin | Member | Viewer |
|---|---|---|---|---|
| View all data | ✅ | ✅ | ✅ | ✅ |
| Create / edit invoices, expenses | ✅ | ✅ | ✅ | ❌ |
| Finalize invoices | ✅ | ✅ | ✅ | ❌ |
| Delete invoices / expenses | ✅ | ✅ | ❌ | ❌ |
| Post journal entries | ✅ | ✅ | ✅ | ❌ |
| Import bank statements | ✅ | ✅ | ✅ | ❌ |
| Reconcile bank transactions | ✅ | ✅ | ✅ | ❌ |
| Run payroll | ✅ | ✅ | ✅ | ❌ |
| Manage users (invite / revoke) | ✅ | ✅ | ❌ | ❌ |
| Change organisation settings | ✅ | ✅ | ❌ | ❌ |
| Year-end closing | ✅ | ✅ | ❌ | ❌ |
| Delete organisation | ✅ | ❌ | ❌ | ❌ |
Inviting a new user
- Go to Settings → Users
- Click Invite User
- Enter the person's email address
- Select their role (Admin / Member / Viewer)
- Click Send Invitation
The person receives an invitation email with a link valid for 48 hours. If they already have a Gäld account, the organisation is added to their account automatically. If not, they are prompted to create one.
Invite your accountant with the Admin role so they can run reports, post year-end adjustments, and generate the fiduciary export — without being able to delete your organisation.
Resending or cancelling an invitation
If the invitation expires or the person did not receive it:
- Go to Settings → Users → Pending Invitations
- Find the pending invitation
- Click Resend to generate a new link, or Cancel to remove it
Changing a user's role
- Go to Settings → Users
- Find the user in the Active Members list
- Click Edit next to their name
- Select the new role
- Click Save
Downgrading a user from Admin to Member removes their ability to manage users and change settings, effective immediately.
Removing a user
- Go to Settings → Users
- Find the user
- Click Remove
- Confirm
The user loses access immediately. Their actions (journal entries, invoices they created) remain in the system — they are not deleted.
Two-factor authentication (2FA)
Gäld supports two 2FA methods:
TOTP (Google Authenticator / Authy)
- Go to Settings → Security → Two-Factor Authentication
- Click Enable
- Scan the QR code with your authenticator app
- Enter the 6-digit code to confirm
- Save your recovery codes in a secure location
Passkeys (WebAuthn)
- Go to Settings → Security → Passkeys
- Click Add Passkey
- Follow your browser or device prompt (Touch ID, Face ID, Windows Hello, or a hardware key)
- Name the passkey and save
Passkeys are phishing-resistant and require no app or code — they are the recommended method.
If you lose your 2FA device and have no recovery codes, you must contact your organisation Owner or the Gäld administrator to regain access. Store recovery codes offline in a safe place.
Organisation settings
Beyond user management, Settings → Organisation lets you configure:
| Setting | Description |
|---|---|
| Organisation name | Appears on invoices and reports |
| Logo | Uploaded logo shown on PDF invoices |
| Fiscal year start | Month when your fiscal year begins (default January) |
| Default language | Used for new invoices and email templates |
| Default VAT rate | Pre-filled on new invoice lines |
| IBAN | Used for QR-Bill generation |
| Address | Appears on invoices |
Frequently asked questions
Can a Member invite other users? No. Only Owner and Admin roles can manage users.
Can I have the same email address in multiple organisations? Yes. One Gäld account can be a member of multiple organisations with different roles in each.
What happens to the organisation if the Owner leaves? Transfer ownership first: Settings → Users → [owner name] → Transfer Ownership. If the Owner account is inaccessible, contact Gäld support.