Skip to main content
Roles control what each person can open and change. Getting them right is how you keep salaries, bank details and identification numbers seen only by the people who need them.

The roles

What each role can do

Everything. Uniquely can:
  • Change the subscription plan
  • Manage billing and payment methods
  • Remove other Owners
  • Close the organisation
Have at least two Owners. A single Owner who is unreachable leaves nobody able to change the plan or manage billing.
Everything an Owner can, except billing, plan changes and removing Owners.
  • All compliance work, including requesting submissions
  • All invoicing
  • All payroll, including sensitive employee data
  • All inventory
  • Invite and manage team members
  • Change organisation settings
  • Full invoicing: invoices, quotes, payments, customers, vendors
  • File statutory returns
  • View salaries and payslips
  • View employee bank details
  • Cannot see NRC, passport or TPIN
  • Cannot run a pay run
  • View all reports
  • Full employee records, including NRC, passport, TPIN and bank details
  • Run and approve pay runs
  • Manage loans, allowances and deductions
  • Generate and distribute payslips
  • Cannot file statutory returns
The separation from Finance is deliberate: the person who runs the pay run is not the person who files the returns.
  • View employees in their own department only
  • View payslips for their own department
  • Submit monthly inputs for their team
  • Cannot see NRC, passport, TPIN or bank details
  • Cannot export data
  • Cannot run payroll
  • View their own payslips
  • View and update their own contact details
  • Nothing about anyone else
Read-only across what they are granted. Cannot create, edit, approve or submit anything.Right for auditors, board members and advisers who need visibility without the ability to change anything.

Sensitive data — the reference table

Check this before assigning any role:

Choosing a role

Ask two questions:
  1. What do they need to do this month? Not what they might one day need.
  2. What should they not see? Salaries and identification are the ones that matter.
When in doubt, choose the narrower role. Widening access takes ten seconds when someone asks. Narrowing it after they have seen something is not possible.

Location assignments

If you operate from more than one location, assign staff to the ones they work at. Inventory figures and dashboards then show only their locations. An unassigned user in a multi-location business may see nothing at all in inventory — which is usually the intended behaviour, not a fault.

Changing a role

1

Open Settings, then Team

Find the person.
2

Choose Change role

Effective immediately.
3

Tell them

Bumara does not notify people about role changes. Someone who suddenly cannot see a page they used yesterday will report it as a fault.

Removing someone

Remove leavers the same day. Their work is not deleted — invoices they raised, payroll they ran, documents they uploaded all remain, and the timeline still records that they did it. Your audit trail must survive staff turnover.
Removing someone from your team does not revoke their authorisation to act for you with a regulator. If they were your authorised representative, replace that separately. See Authorised representative.

Separation of duties

For a business of any size, keep these apart: In a very small business one person often does everything. If so, the compensating control is that the owner reviews — the audit trail is what makes that review possible.

Reviewing access

Last modified on August 4, 2026