Companies and Data Access
Every company is a separate accounting tenant. Records, features, subscriptions and access decisions are evaluated in the active company's context.
The active company controls the workspace
A normal company user works in their own company. An approved accountant can switch into an accepted client. While switched, the navigation, available features and records are those of that client, and a persistent banner identifies the context.
Roles and capabilities
| Access | Meaning |
|---|---|
| Company administrator | Manages the company's settings, users and full operational workspace. |
| Standard user | Works only in the pages permitted by the role and available features. |
| Accountant capability | Adds consent-based client switching to an ordinary subscriber account; each client remains separate. |
| Platform operator | Uses a separate operator console and reaches tenant data only through explicit, audited impersonation. |
Accountant consent
The client invites an approved accountant, the accountant accepts, and either party can end access. Invitations, acceptance, switching and revocation are audit logged. The client chooses the access level on the invitation, either read-only, standard or full, and can change it later without disconnecting the accountant. The level is enforced on the server, not by hiding buttons.
What is recorded
Documents and journals belong to one company. Actions performed while acting as a client remain attributed to the accountant's user identity. Sequential document numbers are generated within the company, and tenant checks prevent a record from another company being selected as a customer, supplier or source document.