Skip to content
WinliumDocs

Roles and permissions for Expense

Who can do what in Expense, which standard role holds Expense permissions today, and how to build custom roles for employees, approvers, finance staff and administrators.

Checked against the product 06 Oct 2026

In one minute

Winlium decides who can do what in Expense with permissions. Permissions are grouped into roles, and an administrator gives each person a role. Roles and permissions explains the idea. This page lists every Expense permission, says what it allows, and gives recipes for four roles you will probably want.

How access works, in order

A person reaches an Expense screen only when every one of these is true:

  1. Expense is part of your company's licence.
  2. An administrator has switched Expense on for the company in Administration > Modules.
  3. The person is not restricted from Expense (see "Restrict one person from Expense" below).
  4. The person's role holds the permission for what they are trying to do.
  5. For creating a claim only: the departments on the claim lines are ones the person may use (see "Department limits on new claims").

If a person holds no Expense permission at all, the Expense menu does not appear for them. If they hold at least one, they see every Expense menu item, and a screen they lack permission for opens empty or shows a permission message.

Every Expense permission

The action wording below is what each permission allows. Only the Owner role holds them today.

Employee tasks

Employee tasks in Expense and the Owner role
What you want to doOwner
Load the Expense Settings that apply to your companyadmin:expense-settings-me:read
Submit an advance request for approvalexpense:advances-submit:create
Create an advance requestexpense:advances:create
Open an advance; list advancesexpense:advances:read
Edit an advance requestexpense:advances:update
See expense categoriesexpense:categories:read
See the My Expenses listexpense:expenses-my-expenses:readShows only your own expenses.
Answer an approver's request for clarificationexpense:expenses-provide-clarification:create
Recall an expense you submittedexpense:expenses-recall:create
Submit an expense for approvalexpense:expenses-submit:createSubmit is a POST action, so it needs the create permission.
See where an expense is in its approvalexpense:expenses-workflow-status:read
Create an expense draftexpense:expenses:create
Delete an expense that is Draftexpense:expenses:delete
Open an expense; load the Expense Report and other lists of all expensesexpense:expenses:read
Edit an expense that is Draft or Rejectedexpense:expenses:update
See the policy that applies to youexpense:policies-my-policy:read

Finance tasks

Finance tasks in Expense and the Owner role
What you want to doOwner
See the advance ageing summaryexpense:advances-ageing-summary:read
Disburse an approved advanceexpense:advances-disburse:createPosts to the ledger.
Return unspent advance cashexpense:advances-return-cash:createNo screen for this action was found in the web app.
See the Process Expenses queue (approved expenses waiting for payment)expense:expenses-pending-processing:read
Process a reimbursement (pay an approved claim)expense:expenses-process-reimbursement:createPosts stage 2 of the ledger entries.
Correct a petty cash fund balanceexpense:petty-cash-funds-adjust-balance:createNeeds a reason. Posts to the ledger.
See a petty cash fund's ledgerexpense:petty-cash-funds-ledger:readNo screen for this was found in the web app.
Replenish a petty cash fundexpense:petty-cash-funds-replenish:createPosts to the ledger.
See petty cash fundsexpense:petty-cash-funds:read

Configuration

Configuration of categories, policies, petty cash funds and external payees, and the Owner role
What you want to doOwner
Create an expense categoryexpense:categories:create
Delete an expense categoryexpense:categories:deleteA category already in use is only deactivated.
Edit an expense categoryexpense:categories:update
Add an external payeeexpense:external-payees:create
See external payeesexpense:external-payees:read
Edit an external payeeexpense:external-payees:update
Create a petty cash fundexpense:petty-cash-funds:create
Delete a petty cash fundexpense:petty-cash-funds:deleteA fund with history is only deactivated.
Edit a petty cash fundexpense:petty-cash-funds:update
Create an expense policyexpense:policies:create
Delete an expense policyexpense:policies:delete
See expense policiesexpense:policies:read
Edit an expense policyexpense:policies:update

Public submissions

Reviewing public submissions and the Owner role
What you want to doOwner
Attach an external payee to a public submissionexpense:public-submissions-attach-external-payee:create
Convert a public submission into an expenseexpense:public-submissions-convert:create
Search employees to match a public submissionexpense:public-submissions-employee-search:read
Match a public submission to an employeeexpense:public-submissions-match-employee:create
Reject a public submissionexpense:public-submissions-reject:create
See public submissionsexpense:public-submissions:read

Expense Settings (Administration)

Expense Settings lives in Administration, so its permissions begin with admin and not expense. Winlium treats it as part of Administration for module access.

Expense Settings permissions and the Owner role
What you want to doOwner
Turn off the public submission linkadmin:expense-settings-public-submission-deactivate:create
See the public submission linkadmin:expense-settings-public-submission-link:read
Replace the public submission link with a new oneadmin:expense-settings-public-submission-rotate-token:create
Create Expense Settingsadmin:expense-settings:create
Delete Expense Settingsadmin:expense-settings:delete
See Expense Settingsadmin:expense-settings:read
Change Expense Settingsadmin:expense-settings:update

Approving needs no Expense permission

Approvers act in My Approvals, in the Approvals area. Every signed-in person can open My Approvals and Winlium decides by whether the task was assigned to them. So an approver needs no Expense permission to approve, reject or ask a question. An approver who also wants to open the claim in full needs the permissions to open a claim (see the Approver recipe). See Approvals.

One permission covers each button

Winlium has no separate "post" or "void" permission in Expense. Every button that sends something to the server needs the create permission for that action. In particular:

  • Submit for Approval needs "Submit an expense for approval" (and a person who submits an advance needs "Submit an advance request for approval").
  • Process Reimbursement needs "Process a reimbursement (pay an approved claim)".
  • Disbursing an advance, replenishing a petty cash fund, correcting a fund balance, converting a public submission and rejecting a public submission each have their own permission, and each needs the person to hold it.
  • Posting to the ledger is a result of approving, paying, disbursing, replenishing or correcting. There is no way to grant "can post" on its own. Give the paying permissions only to people you trust to move money.

Department limits on new claims

Creating a claim is the only Expense action that Winlium also checks against Org Unit access. If a person has been given access to certain departments, they can only save a claim whose lines use those departments. A line with no department is not checked. A person with no department access set at all is not limited, and neither is a person who has branch access only. Owner and platform administrators are never limited. Nothing else in Expense (advances, petty cash, payments, reports) is checked by department or branch. See Org Unit access scoping.

Restrict one person from Expense

An administrator can switch Expense off for one person without changing their role. In Administration > User Management, open the user and find Module Access. Turn the Expense switch off. A red badge Restricted appears next to it. From the next request on, that person is blocked from every Expense screen and the Expense permissions on their role stop working. You cannot change your own access, and the company Owner and platform administrators cannot be restricted. The switch only appears when Expense is turned on for the company.

Recipes for custom roles

An administrator with the Owner role builds each role in Administration > Roles. The steps are the same for every role below:

  1. Open Roles

    In the menu choose Administration, then Roles. Start a new role. The page is called Create Role.
  2. Name the role

    Type the name in Role Name, for example Expense Employee.
  3. Choose the permissions

    In Permissions tick the permissions listed in the recipe. They are grouped by module. You can search across every module.
  4. Save

    Select Save.
  5. Give the role to people

    In Administration > User Management, give the new role to each person who needs it.

Expense Employee

For anyone who files claims and advance requests.

  • expense:expenses:create
  • expense:expenses:read
  • expense:expenses:update
  • expense:expenses:delete
  • expense:expenses-my-expenses:read
  • expense:expenses-submit:create
  • expense:expenses-recall:create
  • expense:expenses-provide-clarification:create
  • expense:expenses-workflow-status:read
  • expense:advances:create
  • expense:advances:read
  • expense:advances:update
  • expense:advances-submit:create
  • expense:categories:read
  • expense:policies-my-policy:read
  • admin:expense-settings-me:read

The forms also load lists from other modules: currencies, departments, branches, cost centres, taxes and the file upload. If a list on the form comes up empty or shows a permission error, add the matching read permission from that module to the role. The permission expense:expenses:read also allows the person to open any claim by its link and to load the Expense Report data, so give it with that in mind.

Expense Approver

An approver needs no Expense permission to approve (see above). To let the approver open the claim or advance behind a task, add:

  • expense:expenses:read
  • expense:expenses-workflow-status:read
  • expense:advances:read

Being named as an approver is done in the approval template, under Administration, not in the role. Winlium never lets a person approve what they submitted themselves.

Finance Officer

For the person who pays claims, disburses advances and tops up petty cash.

  • expense:expenses-pending-processing:read
  • expense:expenses-process-reimbursement:create
  • expense:expenses:read
  • expense:advances:read
  • expense:advances-disburse:create
  • expense:advances-ageing-summary:read
  • expense:petty-cash-funds:read
  • expense:petty-cash-funds-replenish:create
  • expense:petty-cash-funds-adjust-balance:create
  • expense:public-submissions:read
  • expense:public-submissions-employee-search:read
  • expense:public-submissions-match-employee:create
  • expense:public-submissions-attach-external-payee:create
  • expense:public-submissions-convert:create
  • expense:public-submissions-reject:create
  • expense:external-payees:read

The payment, disbursement and replenishment windows list your bank and cash accounts. The person also needs permission to read the Chart of Accounts in Accounting, or those lists come up empty. Leave the last seven out if Finance does not review public submissions.

Expense Administrator

For the person who sets Expense up.

  • expense:categories:read, expense:categories:create, expense:categories:update, expense:categories:delete
  • expense:policies:read, expense:policies:create, expense:policies:update, expense:policies:delete
  • expense:petty-cash-funds:read, expense:petty-cash-funds:create, expense:petty-cash-funds:update, expense:petty-cash-funds:delete
  • expense:external-payees:read, expense:external-payees:create, expense:external-payees:update
  • admin:expense-settings:read, admin:expense-settings:create, admin:expense-settings:update, admin:expense-settings:delete
  • admin:expense-settings-me:read
  • admin:expense-settings-public-submission-link:read, admin:expense-settings-public-submission-rotate-token:create, admin:expense-settings-public-submission-deactivate:create

A category needs an expense account, so the person also needs permission to read the Chart of Accounts. Approval templates are managed under Administration, with their own permissions.

Two screens have no menu item behind them

Two permissions allow actions with no Expense screen today. Do not rely on them: "Return unspent advance cash" and "See a petty cash fund's ledger".