User Management
Gäld uses role-based access control (RBAC) within each organisation. You can invite colleagues, accountants, employees, and read-only stakeholders — each with a defined level of access.
Roles
| Role | Who it's for | Key permissions |
|---|---|---|
| Owner | Organisation owner | All permissions, including deleting the organisation |
| Admin | Finance manager or trusted deputy | All permissions except deleting the organisation |
| Accountant | External or internal accountant | Full accounting and reporting access, including year-end closing; no user management or organisation deletion |
| Member | Staff who create invoices, expenses, or entries | Create and edit operational records, approve expenses, finalize invoices, import, and reconcile; no delete or user management |
| Employee | Employee using self-service features | View and create their own expenses and view their own salary slips |
| Viewer | Board member or read-only stakeholder | View organisation data and payroll information; cannot create or modify records |
There is one Owner for each organisation. The last Owner cannot leave or be removed, and an organisation member cannot remove themselves through the member-removal action.
Detailed permission matrix
| Action | Owner | Admin | Accountant | Member | Employee | Viewer |
|---|---|---|---|---|---|---|
| View organisation data | ✅ | ✅ | ✅ | ✅ | Limited | ✅ |
| Create / edit invoices and expenses | ✅ | ✅ | ✅ | ✅ | Own expenses | ❌ |
| Finalize invoices | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ |
| Delete invoices / expenses | ✅ | ✅ | ✅ | ❌ | ❌ | ❌ |
| Post journal entries | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ |
| Import and reconcile bank statements | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ |
| Run payroll | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ |
| Manage users and invitations | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ |
| Change organisation settings | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ |
| Close a fiscal year | ✅ | ✅ | ✅ | ❌ | ❌ | ❌ |
| Delete organisation | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ |
Inviting a new user
- Go to Organisations and open the organisation
- Scroll to Members and click Invite Member
- Enter the person's email address
- Select their role (Admin / Accountant / Member / Employee / Viewer)
- Click Send Invitation
The person receives an invitation email with a link valid for 7 days. If they already have a Gäld account, the organisation is added to their account automatically. If not, they are prompted to create one.
Invite your accountant with the Accountant role so they can run reports, post year-end adjustments, and generate the fiduciary export without being able to manage users or delete your organisation.
Resending or cancelling an invitation
If the invitation expires or the person did not receive it:
- Open the organisation from Organisations
- Go to the Pending Invitations section
- Find the pending invitation
- Click Resend to generate a new link, or Cancel to remove it
Changing a user's role
- Open the organisation from Organisations
- Find the user in the Members list
- Select a new role in the role control next to their name
Changing a member to Employee also requires selecting the associated employee record.
Downgrading a user from Admin to Member removes their ability to manage users and change settings, effective immediately.
Removing a user
- Open the organisation from Organisations
- Find the user in the Members list
- Click Remove and confirm
The user loses access immediately. Their actions (journal entries, invoices they created) remain in the system — they are not deleted.
Two-factor authentication (2FA)
Gäld supports two 2FA methods:
TOTP (Google Authenticator / Authy)
- Go to Profile
- Click Enable
- Scan the QR code with your authenticator app
- Enter the 6-digit code to confirm
- Save your recovery codes in a secure location
Passkeys (WebAuthn)
- Go to Profile
- Click Add Passkey
- Follow your browser or device prompt (Touch ID, Face ID, Windows Hello, or a hardware key)
- Name the passkey and save
Passkeys are phishing-resistant and require no app or code — they are the recommended method.
If you lose your 2FA device and have no recovery codes, you must contact your organisation Owner or the Gäld administrator to regain access. Store recovery codes offline in a safe place.
Notification preferences
Gäld sends in-app notifications for key events — OCR scan results, approval requests, payment reminders, and system messages. You can control which notifications you receive.
- Go to Profile
- Scroll to Notification Preferences
- Toggle individual notification types on or off
Notifications appear in the bell icon in the top bar. Unread notifications show a badge count.
Notification preferences are per-user. Each team member can configure their own settings independently.
Organisation settings
Beyond user management, Settings → Organisation lets you configure:
| Setting | Description |
|---|---|
| Organisation name | Appears on invoices and reports |
| Logo | Uploaded logo shown on PDF invoices |
| Fiscal year start | Month when your fiscal year begins (default January) |
| Default language | Used for new invoices and email templates |
| Default VAT rate | Pre-filled on new invoice lines |
| IBAN | Used for QR-Bill generation |
| Address | Appears on invoices |
Frequently asked questions
Can a Member invite other users? No. Only Owner and Admin roles can manage users.
Can I have the same email address in multiple organisations? Yes. One Gäld account can be a member of multiple organisations with different roles in each.
What happens if the Owner wants to leave? The last Owner cannot leave. Add another owner or contact the Gäld administrator before changing the organisation membership.