Understand User Roles and Access Controls
Last updated on Sep 19, 2026
Every user in Maxio holds a role per application, set under Access Controls when you create or edit that user. The tables further down describe what each role can do, so you can give someone the least access that still lets them do their job.
How roles are assigned
Maxio Access and Expenses Access are set per entity and per instance, so one user can hold a different role in each instance your account contains. Advanced Billing Access is the exception: it is account-wide, and changing it on one instance applies it everywhere.
Two of the three columns only appear when they apply to you.
- Advanced Billing Access appears only if an Advanced Billing role applies to your account.
- Expenses Access appears only if Expenses is enabled for your account.
The Admin checkbox above the table overrides all three. Checking it creates an admin-level user in every Maxio application within the entity and any sub-entities, so use it only when someone genuinely needs full control everywhere.
Important: Choosing Admin User under Maxio Access also sets Expenses to Bookkeeping User and disables the Expenses dropdown. There is no Admin role for Expenses. The two are not independent.
A user needs a Maxio Access role before they can hold an Expenses role. Setting Maxio Access to No Access forces Expenses to No Access as well.
Maxio Access roles
Maxio Access governs Maxio Core itself. Each role builds on the one before it, so a Bookkeeping User can do everything a Report User can, plus the record work listed below.
Roles controlling access to Maxio Core
| Role | Description |
|---|---|
| No Access | Does not have access to Maxio. |
| Admin User | Has complete control over the configuration of your Maxio account. This includes:
|
| Bookkeeping User | Has the ability to add:
|
| Report User | Can create and run their own reports, as well as run any reports created by other users. Report Users cannot add or modify any configuration or transaction information; they can simply run reports against existing information. User examples: CEO, Business Analyst |
Advanced Billing Access roles
This column appears only when Advanced Billing is enabled for your account. Unlike the other two, the role you pick applies across every instance rather than per instance.
Roles controlling access to Advanced Billing
| Role | Description |
|---|---|
| No Access | Does not have access to Advanced Billing. |
| Team Member | A user on the account without admin privileges. |
| Admin User | Has full access to all sites. |
Expenses Access roles
This column appears only when Expenses is enabled. A user needs a Maxio Access role before they can hold an Expenses role, and there is no Admin level here.
Roles controlling access to Expenses
| Role | Description |
|---|---|
| No Access | Does not have access to Expenses. |
| Bookkeeping User | Has the ability to add:
|
| Report User | Can create and run their own reports, as well as run any reports created by other users. Report Users cannot add or modify any configuration or transaction information; they can simply run reports against existing information. User examples: CEO, Business Analyst |
Related information
To create, edit, and deactivate the users these roles apply to, see Manage Users.
Still need help?
Reach out and our support team will take it from here.
