Roles and permissions
Every user has one role. The role decides which pages they reach and which actions they can take.
On this page
The roles
VendOrca has five staff roles for people inside your company and two external roles for workers and suppliers.
| Role | Who it's for | What it can do |
|---|---|---|
| Program Admin | The people who run the program | Everything the other staff roles can do. Also: draft and apply changes to the program rules, invite people, change roles, deactivate and reactivate users, create and move org units, import data, manage billing, approve and reject timesheets, turn AI assistant access on or off, and use the emergency stop that pauses all of it at once. |
| Hiring Manager | Managers who approve worker time | Staff consoles: Home, Onboarding, Assignments, Timesheets, Invoices, Reports and Agent access, plus read-only Users, Org units and Config. Approve and reject timesheets. |
| Finance / AP | Finance and accounts payable | Staff consoles: Home, Onboarding, Assignments, Timesheets, Invoices, Reports and Agent access, plus read-only Users, Org units and Config. Can't be granted by invitation (see below). |
| HR / Compliance | HR and compliance teams | Staff consoles: Home, Onboarding, Assignments, Timesheets, Invoices, Reports and Agent access, plus read-only Users, Org units and Config. |
| Executive | Leaders who need visibility | Staff consoles: Home, Onboarding, Assignments, Timesheets, Invoices, Reports and Agent access, plus read-only Users, Org units and Config. |
| Worker | An outside worker in your program | Their own Profile, Onboarding checklist and Time. Can't reach the admin console. |
| Billing Entity | A supplier or agency | The supplier portal, showing only its own invoices. Can't reach the admin console. |
Staff roles can start onboarding, create assignments, and generate and export invoices. Program Admins and Hiring Managers approve or reject timesheets, and the other staff roles can read the queue. Billing and Import are for Program Admins only.
Available to every role
- The Ask VendOrca bar answers questions within what the user can already see. Workers and suppliers get answers about their own records only. See Reports and Ask VendOrca.
- Agent access lets a user create a read-only access key in their own name, so an AI assistant can read program data for them. A Program Admin turns this on for the workspace first. An access key never reads more than its owner can, reads only the kinds of data picked when it's created, and leaves out personal data unless Personal data is picked. See Access keys for AI assistants.
Roles and plans
Every role is available on every plan. The only capability that depends on your plan is agent access for AI assistants, which is included on the Team and Business plans. See Billing and plans.
Granting and changing roles
Only a Program Admin manages roles, from Users.
- Invite. Paste email addresses and pick a default role. You can set a different role for one address by adding it after the address on the same line.
- Change role. Pick the new role on the person's row and select Apply role. The change takes effect from their next action in VendOrca.
- Deactivate. The person loses access from their next action in VendOrca, and any AI assistant access keys they created stop working too. Their history is kept. To reactivate, pick the role first: the picker starts at Hiring Manager.
Two safeguards apply: you can't remove the last Program Admin, and you can't deactivate yourself.
Finance / AP
The Finance / AP role isn't offered in the invitation form. Invite the person with another role. Once they've accepted, a Program Admin grants Finance / AP with Change role on their row.
Workers and suppliers
A Worker or Billing Entity sign-in shows data once it's linked to the matching record, which a Program Admin arranges with VendOrca support. See Worker and supplier sign-ins.