> ## Documentation Index
> Fetch the complete documentation index at: https://zenofirm.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Give your team the right access

> Invite colleagues, assign preparation and approval roles, and limit access to client companies.

Zeno is invite-only. An owner adds an address under **Settings → Team**,
and that row *is* the authorization — there is no code to share, and
forwarding an invite grants nothing, because the gate is the address rather
than the link. People then sign in with Google, Microsoft, or Intuit on the
address you listed.

Somebody who cannot use any of those — an auditor, a reviewer, anyone whose
work account will not sign in to outside apps — can choose **Email me a
sign-in link** on the sign-in page instead. Zeno emails a link to the
address, and it works once, for 15 minutes. Links only go to addresses on a
firm's team, and someone you remove from the team stops receiving them.

Revoking someone before their first sign-in is a delete, with nothing left
behind to clean up.

## Roles

| Role | What it is for |
| - | - |
| **Owner** | Runs the firm. Everything below, plus the team and the subscription. |
| **Operator** | Does the books and signs off on what gets posted. |
| **Member** | Does the books. Does not approve what gets posted — the reviewer's counterpart, not a lesser operator. |
| **Cardholder** | Carries a company card. Sees their own charges and nothing else. |
| **Business viewer** | A client's owner. Reads their own company's books and leaves questions for the team. Changes nothing. |

What each may do:

| | Owner | Operator | Member | Cardholder | Business viewer |
| - | :-: | :-: | :-: | :-: | :-: |
| See the console | ✔ | ✔ | ✔ | | |
| Work the queue, import statements, work the inbox, teach rules through the assistant | ✔ | ✔ | ✔ | | |
| Approve a plan or an expense claim | ✔ | ✔ | | | |
| Connect banks, map feed accounts, configure expense cards | ✔ | ✔ | | | |
| Manage the team | ✔ | | | | |
| Manage billing | ✔ | | | | |
| Submit their own card charges and attach receipts | ✔ | ✔ | ✔ | ✔ | |
| Read their own company's books | ✔ | ✔ | ✔ | | ✔ |
| Ask the team a question, or answer one | ✔ | ✔ | ✔ | | ✔ |

These are enforced by the server on every request. The console mirrors them by
hiding what a person cannot use, but the check that matters is the server's.

<img src="https://mintcdn.com/zenofirm/VfRuieValpxF_E2q/images/illustrations/cloud/role-capability-card.svg?fit=max&auto=format&n=VfRuieValpxF_E2q&q=85&s=766ae22d7d9d4ac1891b43ba41a96da9" alt="Role Capability Card" width="600" height="420" data-path="images/illustrations/cloud/role-capability-card.svg" />

<Note>
  A cardholder does not get the console at all. Handing someone whose whole
  business here is the card in their pocket the full firm console would expose
  work they cannot act on. They get a page for their own charges instead, and
  cannot connect an AI client. See
  [expense claims](/docs/cloud/expenses#what-the-cardholder-sees).
</Note>

<img src="https://mintcdn.com/zenofirm/VfRuieValpxF_E2q/images/illustrations/cloud/cardholder-restricted-view.svg?fit=max&auto=format&n=VfRuieValpxF_E2q&q=85&s=5dead1dc52f1703c73b3edf380d150db" alt="Cardholder Restricted View" width="600" height="420" data-path="images/illustrations/cloud/cardholder-restricted-view.svg" />

## Client access

An owner can limit an invite to named client companies. Leave the selection
empty for an owner, operator, or member who should see the whole firm. A scoped
person sees only the selected companies wherever the console or MCP tools list
client work.

A cardholder must be scoped to at least one company. With no company selected,
the cardholder sees no claims.

## Business viewers

A business viewer is the owner of one of your clients, given a way to see their
own books without being able to change them. "Owner" in the table above is
whoever runs your Zeno workspace; a business viewer never is, and making
someone one takes nothing away from anyone else.

* **Their companies, and only those.** Pick at least one company when you
  invite a business viewer or move someone to the role. With none picked they
  would see nothing, so Zeno refuses the invite rather than guess. They can
  never be widened to the whole firm.
* **Their own page.** They do not get the console. They see their company's
  profit and loss for the year and its balance sheet, read from QuickBooks
  Online when the page opens, and its latest transactions, each saying how
  fresh it is. None of your firm's plans, notes or work is on it.
* **Questions for you.** Beside any transaction they can ask the team what it
  is. The question waits under **Owner questions** in your console and in your
  AI's next check for pending work; it is not a chat, and nobody has to be
  online. Your AI can draft the answer; a person on your team publishes it
  before the owner sees it. Answering or resolving a question never changes
  the books - a correction is a plan, approved the usual way.
* **Their own AI, read-only.** A business viewer can connect Claude or ChatGPT
  to Zeno. That connection reads only their companies' books and can leave
  questions, whatever they chose on the consent screen.

<Note>
  Anyone who could act can also connect an AI client for looking only: the
  consent screen offers **View and answer only** beside **Full access**. That
  choice is for that one connection. It changes nobody's role.
</Note>

## Nobody is a seat

Pricing follows client books and nothing else. Invite as many owners,
operators, members, cardholders and business viewers as the work needs; who may approve is a
permission you grant, not a purchase. The Team page says how many people can
approve a posting, which is a fact about the firm's review and not a count
against anything. Current pricing is on
[zenofirm.com/pricing](https://zenofirm.com/pricing).

## Removing someone

Removing a person ends their sessions immediately. Work they approved keeps
their name on it — a verdict is a record of what a specific person decided, and
it does not become anonymous because they left.

## Changing a role

Re-role someone in place from the same page. It takes effect on their next
request, not on their next sign-in.

To change an existing person's company scope, remove the address and invite it
again with the intended clients selected. Their recorded approvals keep their
name. A business viewer's companies are changed in place, from the
**companies** link on their row. Moving someone to business viewer asks for
their companies before anything changes.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.