Team Roles and Dashboard Access
Dots uses role-based access control to limit what team members can see and do in the Dots Dashboard. Each role has specific permissions that control visibility of sidebar sections and available actions.
Available Roles
When inviting team members or editing user access, you can assign one of the following roles:
Admin — Full access to all dashboard sections and actions. Admins can manage team members, configure settings, and perform all operations.
Payer — Can send and manage payouts across all available rails.
AP Approver — Can approve accounts payable requests and manage payment approvals.
AP Creator — Can create accounts payable requests for approval.
Viewer — Read-only access to dashboard data and reports.
Viewer + Clawbacks — Read-only access plus the ability to process clawbacks.
Customer Service — Access focused on user support and inquiry resolution.
Compliance — Access focused on compliance review and document management.
User Manager — Can manage user records and data.
How Access Control Works
The dashboard enforces role-based access through multiple mechanisms:
Sidebar visibility — Tabs and sections that a role cannot access are hidden from the navigation sidebar.
Route protection — Attempting to navigate directly to a restricted section redirects to the home page.
Action authorization — Backend permissions verify whether a role can perform specific actions, such as viewing API keys or modifying settings.
Admins have unrestricted access. All other roles are checked against a permission set that determines which tabs they can view and which actions they can perform.
Assigning Roles to Team Members
To change a team member's role:
Go to Advanced → Team Management in the dashboard sidebar.
Find the team member you want to update.
Click to open their user details.
Select the appropriate role from the dropdown.
Save your changes.
The updated permissions take effect immediately. The team member will see their sidebar update to reflect their new access level.
Inviting New Team Members
When inviting a new user to your organization:
Navigate to Advanced → Team Management.
Click Invite Team Member.
Enter their email address.
Select their role before sending the invitation.
Pending invitations show a status of created until accepted. You can cancel an invitation before it's accepted if needed.
Understanding Restricted Access
When a team member tries to access a section or perform an action outside their role's permissions:
Hidden sections do not appear in their sidebar navigation.
Direct navigation to restricted routes redirects them to the dashboard home.
Action buttons for restricted operations are not visible or are disabled.
This access model ensures team members only see and interact with the features relevant to their responsibilities.
Role Comparison
The following table summarizes access patterns by role:
Role | Dashboard Access | Payout Actions | Team Management | Settings |
|---|---|---|---|---|
Admin | All sections | Full | Full | Full |
Payer | Payout-focused sections | Send and manage | No | Limited |
AP Approver | AP-focused sections | Approve only | No | No |
AP Creator | AP-focused sections | Create requests | No | No |
Viewer | Read-only sections | None | No | No |
Viewer + Clawbacks | Read-only + clawbacks | Clawbacks only | No | No |
Customer Service | Support-focused sections | Limited | No | No |
Compliance | Compliance-focused sections | Limited | No | No |
User Manager | User management sections | Limited | No | No |
For detailed permission mapping, contact Dots support or refer to your organization's access policy.
Next Steps
Learn about Getting Started with the Dots Dashboard
Understand Sandbox vs Production Environments
Learn about overriding user addresses in compliance tooling when address validation fails
Learn about editing a user's date of birth in the dashboard