Roles decide what a user can do. Approval policies decide when someone else has to check. Set the roles up well and the policies stay simple.
The five roles
- Owner. The registered user and Xace's main contact for the account. Full admin. No approval needed on their own payments. There is one Owner, and changing it is a formal process with a signed authorisation.
- Supervisor. The same rights as Owner without being the primary contact. Suits a CFO or finance director. No approval needed on their own payments.
- Standard. Creates and approves payments, but their own payments follow a four-eyes flow: someone else must approve. Good default for most of the finance team.
- Creator. Creates payments, cannot approve. For AP clerks and anyone who raises payments but should not sign them off.
- Approver. Approves payments, cannot create. For directors and anyone who signs off but never raises.
Limits on top
Every role carries two customisable limits:
- Payment limit: the most a user can create in one payment.
- Approval limit: the most a user can approve.
Limits let you keep the role count low. Two Standard users can have very different limits without needing different roles.
A setup for a team of five
- CFO: Supervisor. Approval limit unlimited. Signs off the top tier.
- Financial controller: Standard. Payment limit £100,000, approval limit £100,000.
- Two AP staff: Creator. Payment limit £25,000 each, no approval rights.
- Treasury analyst: Standard. Payment limit £250,000 for intercompany and FX, approval limit £25,000.
- A director outside finance: Approver. Approval limit £250,000, for the alternative approval path when the CFO is away.
Then write the approval policies against amounts, not people: one approver below £10,000, two between £10,000 and £100,000, two in order with the CFO last above that. Roles and limits stop anyone raising or approving beyond their remit; policies make sure the right number of people looked.
Across several entities
In a group, a user has one login and a role per company. The controller can be Standard in the operating entities and Viewer in the holding company. Access changes with the entity switch, and every action is logged with the entity it was taken in.
Three habits
- Give people the smallest role that lets them do their job. Widen it when they need it, not before.
- Review roles and limits when someone changes job, not at the annual audit.
- Never share a login to get around a limit. Add a user with the right role instead. The audit trail is only useful if it names the right person.



