Firm and team
Firm and team management is where you control who's on your firm and what each person (or AI agent) can do. It covers the member roster, role assignment, fine-grained permission overrides, invitations, and narrow grants of access to specific clients, books, or projects.
Every firm needs exactly one owner and at least one person who can manage it, and most firms will only ever touch roles rather than individual permissions. But the fine-grained system is there for the firm that wants precise control, like giving someone the whole Emails app but only read access to the books.
Where to find it
Two doors, same surface:
- Settings › Firm, the gear tile at the tail of the dock.
- The account dashboard behind your avatar: Firms, then the firm you want to manage.
If you operate in more than one firm, a picker at the top lets you switch which firm's roster you're looking at.
Key concepts
- Member: anyone with access to the firm's workspace: a human teammate or an AI agent. Agents are members like anyone else, with their own role and permissions.
- Role: a named bundle of permissions (Owner, Admin, Partner, Manager, Staff, Limited, or Custom) you assign to a member. Picking a role fills in its default permission set; changing any single permission by hand switches that member to Custom.
- Permission: a specific capability, grouped into categories that mirror the app sections (Clients, Bookkeeping, Projects, Emails, and so on).
- Resource grant: a narrower kind of access than a role: scoping one member to only certain clients, books, or projects rather than everything of that kind.
- Sharing: a separate system from firm permissions. Firm permissions decide which apps a member can use at all; sharing decides which specific items inside those apps they can see.
Roles
Every firm ships with six built-in roles plus Custom:
| Role | Who it's for |
|---|---|
| Owner | Full control over the firm account. A firm has exactly one owner at a time. |
| Admin | Full access to every feature and to firm management. |
| Partner | Full access to client work and bookkeeping, but can't manage the firm's team or settings. |
| Manager | Manages client work day to day. Can't delete records, and can't manage the team or settings. |
| Staff | Day-to-day client work: view and edit the things staff typically touch, without administrative or destructive actions. |
| Limited | View-only access. Suitable for interns or temporary staff. |
| Custom | Whatever set of permissions you assign by hand. |
Assigning a role fills in that role's default permissions. Toggle any single permission afterward and the member's assignment becomes Custom, without losing any of the permissions you didn't touch.
Permissions by category
Permissions are grouped into categories that mirror the app sections: Clients and CRM, AI tools, Agents, Bookkeeping, Projects, Emails, Calendar and meetings, Phone, Messages, the connected messaging bridges (Slack, Signal, Telegram), Asana, Files and documents, Signatures, Forms, Recordings, Meetings, Fireflies, Taxes, Feedback, and Administration. A category only shows in the permission grid if your firm has the corresponding app turned on, so the list you see may be shorter than this.
The table below shows what each built-in role grants, category by category. Full means every permission in that category; Manage means create and edit but not delete; View means read-only; None means no access.
| Category | Owner / Admin | Partner | Manager | Staff | Limited |
|---|---|---|---|---|---|
| Clients & CRM | Full | Full | Manage | View + manage contacts | View |
| AI tools (chat, web search, code, database, plans) | Full | Full | Full | Full | None |
| Agents | Full | Full | Full | View | None |
| Bookkeeping | Full | Full | Manage | View + categorize | None |
| Projects | Full | Full | Manage | Manage (no delete) | View |
| Emails | Full | Full | Full | Full | View |
| Calendar & meetings (scheduling) | Full | Full | Full | View + edit events | View |
| Phone | Full | Full | Full | Full | View |
| Messages (native team chat) | Full | Full | Full | View + send | View |
| Slack / Signal / Telegram | Full | Full | Full | View + send | None |
| Asana | Full | Full | Full | Full | View |
| Files & documents | Full | Full | Manage | View + manage | View |
| Signatures | Full | Full | Manage | View + manage | View |
| Forms | Full | Full | Manage | View + manage | View |
| Recordings | Full | Full | Full | Full | View |
| Meetings (call capture, transcripts) | Full | Full | Full | Full | View |
| Fireflies | Full | Full | Full | View | View |
| Taxes | Full | Full | Full | Full | View |
| Feedback | Full | Full | Full | Full | Full |
| Administration (firm settings, team management) | Full | View firm only | View firm only | View firm only | View firm only |
Custom starts from whatever role you picked, or empty if you build one from scratch on invite, and lets you flip any individual permission from that baseline.
Invite a member
- On Settings › Firm, choose the firm you're inviting into (if you operate in more than one).
- Click Invite.
- Enter the person's email address, pick a starting role, and adjust individual permissions if you want something other than the role's defaults.
- Send the invite.
What happens next depends on whether the email belongs to an existing Bitment account:
- If the address already belongs to someone with a Bitment account, they're added to the firm immediately and notified.
- If it's a new address, they receive an email with a link to accept and set up their account. The invitation sits pending until they do.
From a pending invitation you can Resend the invite email or Revoke it to cancel.
Open a member's profile
Click any member in the roster to open their detail view: profile, the full permission grid with any overrides, resource grants, and lifecycle actions.
- Deactivate suspends a member's access without deleting their history; Reactivate restores it.
- Transfer ownership hands the Owner role to another member. A firm keeps exactly one owner at all times, so transferring ownership demotes you to Admin at the same moment.
- Toggling any individual permission on this screen switches that member from their assigned role to Custom, without touching the permissions you didn't change.
Grant access to specific resources
Beyond role-based permissions, you can scope a member to only certain resources of a given kind: specific clients, specific books, or specific projects.
A member with no resource grants of a kind has unrestricted access to everything of that kind their role allows. Once you add even one grant of that kind, that member is scoped to only the resources you've explicitly granted, at either view or edit level. Grant access from the member's detail view under Resource Access, or from the resource's own share control, which reaches the same grant.
Sharing vs. permissions
Most individual items in Bitment, a project, a file, a form, a signature request, a meeting, a conversation, carry their own share control, separate from firm-wide permissions. Sharing grants a specific person, or a firm's whole team, view or edit access to that one thing.
The two systems compose: firm permissions decide which apps a member can use at all, and sharing decides which specific items inside those apps they can see. Someone with Emails permission still only sees the email threads shared with them or that they own; someone without Emails permission can't open the app regardless of what's shared with them.
Firm color and branding
Each firm you operate in can carry its own workspace color, set from the account dashboard, so the shell reads differently depending on which firm's context you're working in.
Tips
- Give a role a try before reaching for Custom. Most firms never need anything more granular than the six built-in roles.
- Resource grants are for the exception, not the rule: a contractor who should only see one client, or a bookkeeper scoped to a handful of books. Leave most members ungranted so they inherit their role's full reach.
- Deactivating a member is reversible and keeps their history intact; it's the right choice for someone on leave. Removing their invite before it's accepted is the right choice for a typo'd email.