A role answers three questions about a person: what they can do, what they can spend, and what they can sign. Access tiers keep their defaults; roles add to them.

assign on Team page
Roles0 defined

No custom roles yet

The defaults (owner, approver, operator, viewer) work out of the box — roles add granularity.

Create a role
blank = no cap
Approval chainswho signs, in what order

An approval travels its chain in order — only the current stage's role is asked, and only its holders can sign. Unconfigured kinds use the default gate: one approver (go-live: two). In-flight approvals keep the chain they were born with.

Chain for: Payroll and salary changes

No stages — uses the default gate