Permissions & Access¶
Kipper gives workspace admins precise control over who can see what. Access is enforced at query time — no matter how a question is phrased or which interface is used, users only ever see the data they're permitted to see.
How permissions work¶
- An admin sets each member's permission level per data source when they invite them (or later, from the member's profile)
- When a user asks a question, Kipper checks their permission level before running the query
- If the query would touch data outside the user's permission level, Kipper refuses to answer rather than returning partial results
Permission levels¶
Each member is assigned one of three permission levels per data source:
| Level | What the user can query |
|---|---|
| Full Access (Read only) | Unrestricted access to all financial data, reports, and analytics |
| Accounts Receivable (Read only) | Customers, invoices, payments, credit memos, and refunds |
| Accounts Payable (Read only) | Vendors, bills, bill payments, and vendor credits |
Every level is read-only — Kipper cannot write, edit, or delete records in your finance system regardless of a member's permission level. A member can hold different levels across different sources — for example, Full Access (Read only) on QuickBooks and Accounts Payable (Read only) on Xero. Members with no assignment for a given source cannot query it at all.
Where to manage this¶
- User Access — how to invite members and set their permission level
- Permission Sets — the three access tiers as they appear on each data source