Roles and permissions for Expense
Who can do what in Expense, which standard role holds Expense permissions today, and how to build custom roles for employees, approvers, finance staff and administrators.
In one minute
Winlium decides who can do what in Expense with permissions. Permissions are grouped into roles, and an administrator gives each person a role. Roles and permissions explains the idea. This page lists every Expense permission, says what it allows, and gives recipes for four roles you will probably want.
How access works, in order
A person reaches an Expense screen only when every one of these is true:
- Expense is part of your company's licence.
- An administrator has switched Expense on for the company in Administration > Modules.
- The person is not restricted from Expense (see "Restrict one person from Expense" below).
- The person's role holds the permission for what they are trying to do.
- For creating a claim only: the departments on the claim lines are ones the person may use (see "Department limits on new claims").
If a person holds no Expense permission at all, the Expense menu does not appear for them. If they hold at least one, they see every Expense menu item, and a screen they lack permission for opens empty or shows a permission message.
Every Expense permission
The action wording below is what each permission allows. Only the Owner role holds them today.
Employee tasks
| What you want to do | Owner |
|---|---|
| Load the Expense Settings that apply to your companyadmin:expense-settings-me:read | |
| Submit an advance request for approvalexpense:advances-submit:create | |
| Create an advance requestexpense:advances:create | |
| Open an advance; list advancesexpense:advances:read | |
| Edit an advance requestexpense:advances:update | |
| See expense categoriesexpense:categories:read | |
| See the My Expenses listexpense:expenses-my-expenses:readShows only your own expenses. | |
| Answer an approver's request for clarificationexpense:expenses-provide-clarification:create | |
| Recall an expense you submittedexpense:expenses-recall:create | |
| Submit an expense for approvalexpense:expenses-submit:createSubmit is a POST action, so it needs the create permission. | |
| See where an expense is in its approvalexpense:expenses-workflow-status:read | |
| Create an expense draftexpense:expenses:create | |
| Delete an expense that is Draftexpense:expenses:delete | |
| Open an expense; load the Expense Report and other lists of all expensesexpense:expenses:read | |
| Edit an expense that is Draft or Rejectedexpense:expenses:update | |
| See the policy that applies to youexpense:policies-my-policy:read |
Finance tasks
| What you want to do | Owner |
|---|---|
| See the advance ageing summaryexpense:advances-ageing-summary:read | |
| Disburse an approved advanceexpense:advances-disburse:createPosts to the ledger. | |
| Return unspent advance cashexpense:advances-return-cash:createNo screen for this action was found in the web app. | |
| See the Process Expenses queue (approved expenses waiting for payment)expense:expenses-pending-processing:read | |
| Process a reimbursement (pay an approved claim)expense:expenses-process-reimbursement:createPosts stage 2 of the ledger entries. | |
| Correct a petty cash fund balanceexpense:petty-cash-funds-adjust-balance:createNeeds a reason. Posts to the ledger. | |
| See a petty cash fund's ledgerexpense:petty-cash-funds-ledger:readNo screen for this was found in the web app. | |
| Replenish a petty cash fundexpense:petty-cash-funds-replenish:createPosts to the ledger. | |
| See petty cash fundsexpense:petty-cash-funds:read |
Configuration
| What you want to do | Owner |
|---|---|
| Create an expense categoryexpense:categories:create | |
| Delete an expense categoryexpense:categories:deleteA category already in use is only deactivated. | |
| Edit an expense categoryexpense:categories:update | |
| Add an external payeeexpense:external-payees:create | |
| See external payeesexpense:external-payees:read | |
| Edit an external payeeexpense:external-payees:update | |
| Create a petty cash fundexpense:petty-cash-funds:create | |
| Delete a petty cash fundexpense:petty-cash-funds:deleteA fund with history is only deactivated. | |
| Edit a petty cash fundexpense:petty-cash-funds:update | |
| Create an expense policyexpense:policies:create | |
| Delete an expense policyexpense:policies:delete | |
| See expense policiesexpense:policies:read | |
| Edit an expense policyexpense:policies:update |
Public submissions
| What you want to do | Owner |
|---|---|
| Attach an external payee to a public submissionexpense:public-submissions-attach-external-payee:create | |
| Convert a public submission into an expenseexpense:public-submissions-convert:create | |
| Search employees to match a public submissionexpense:public-submissions-employee-search:read | |
| Match a public submission to an employeeexpense:public-submissions-match-employee:create | |
| Reject a public submissionexpense:public-submissions-reject:create | |
| See public submissionsexpense:public-submissions:read |
Expense Settings (Administration)
Expense Settings lives in Administration, so its permissions begin with admin and not expense. Winlium treats it as part of Administration for module access.
| What you want to do | Owner |
|---|---|
| Turn off the public submission linkadmin:expense-settings-public-submission-deactivate:create | |
| See the public submission linkadmin:expense-settings-public-submission-link:read | |
| Replace the public submission link with a new oneadmin:expense-settings-public-submission-rotate-token:create | |
| Create Expense Settingsadmin:expense-settings:create | |
| Delete Expense Settingsadmin:expense-settings:delete | |
| See Expense Settingsadmin:expense-settings:read | |
| Change Expense Settingsadmin:expense-settings:update |
Approving needs no Expense permission
Approvers act in My Approvals, in the Approvals area. Every signed-in person can open My Approvals and Winlium decides by whether the task was assigned to them. So an approver needs no Expense permission to approve, reject or ask a question. An approver who also wants to open the claim in full needs the permissions to open a claim (see the Approver recipe). See Approvals.
One permission covers each button
Winlium has no separate "post" or "void" permission in Expense. Every button that sends something to the server needs the create permission for that action. In particular:
- Submit for Approval needs "Submit an expense for approval" (and a person who submits an advance needs "Submit an advance request for approval").
- Process Reimbursement needs "Process a reimbursement (pay an approved claim)".
- Disbursing an advance, replenishing a petty cash fund, correcting a fund balance, converting a public submission and rejecting a public submission each have their own permission, and each needs the person to hold it.
- Posting to the ledger is a result of approving, paying, disbursing, replenishing or correcting. There is no way to grant "can post" on its own. Give the paying permissions only to people you trust to move money.
Department limits on new claims
Creating a claim is the only Expense action that Winlium also checks against Org Unit access. If a person has been given access to certain departments, they can only save a claim whose lines use those departments. A line with no department is not checked. A person with no department access set at all is not limited, and neither is a person who has branch access only. Owner and platform administrators are never limited. Nothing else in Expense (advances, petty cash, payments, reports) is checked by department or branch. See Org Unit access scoping.
Restrict one person from Expense
An administrator can switch Expense off for one person without changing their role. In Administration > User Management, open the user and find Module Access. Turn the Expense switch off. A red badge Restricted appears next to it. From the next request on, that person is blocked from every Expense screen and the Expense permissions on their role stop working. You cannot change your own access, and the company Owner and platform administrators cannot be restricted. The switch only appears when Expense is turned on for the company.
Recipes for custom roles
An administrator with the Owner role builds each role in Administration > Roles. The steps are the same for every role below:
Open Roles
In the menu choose Administration, then Roles. Start a new role. The page is called Create Role.Name the role
Type the name in Role Name, for example Expense Employee.Choose the permissions
In Permissions tick the permissions listed in the recipe. They are grouped by module. You can search across every module.Save
Select Save.Give the role to people
In Administration > User Management, give the new role to each person who needs it.
Expense Employee
For anyone who files claims and advance requests.
- expense:expenses:create
- expense:expenses:read
- expense:expenses:update
- expense:expenses:delete
- expense:expenses-my-expenses:read
- expense:expenses-submit:create
- expense:expenses-recall:create
- expense:expenses-provide-clarification:create
- expense:expenses-workflow-status:read
- expense:advances:create
- expense:advances:read
- expense:advances:update
- expense:advances-submit:create
- expense:categories:read
- expense:policies-my-policy:read
- admin:expense-settings-me:read
The forms also load lists from other modules: currencies, departments, branches, cost centres, taxes and the file upload. If a list on the form comes up empty or shows a permission error, add the matching read permission from that module to the role. The permission expense:expenses:read also allows the person to open any claim by its link and to load the Expense Report data, so give it with that in mind.
Expense Approver
An approver needs no Expense permission to approve (see above). To let the approver open the claim or advance behind a task, add:
- expense:expenses:read
- expense:expenses-workflow-status:read
- expense:advances:read
Being named as an approver is done in the approval template, under Administration, not in the role. Winlium never lets a person approve what they submitted themselves.
Finance Officer
For the person who pays claims, disburses advances and tops up petty cash.
- expense:expenses-pending-processing:read
- expense:expenses-process-reimbursement:create
- expense:expenses:read
- expense:advances:read
- expense:advances-disburse:create
- expense:advances-ageing-summary:read
- expense:petty-cash-funds:read
- expense:petty-cash-funds-replenish:create
- expense:petty-cash-funds-adjust-balance:create
- expense:public-submissions:read
- expense:public-submissions-employee-search:read
- expense:public-submissions-match-employee:create
- expense:public-submissions-attach-external-payee:create
- expense:public-submissions-convert:create
- expense:public-submissions-reject:create
- expense:external-payees:read
The payment, disbursement and replenishment windows list your bank and cash accounts. The person also needs permission to read the Chart of Accounts in Accounting, or those lists come up empty. Leave the last seven out if Finance does not review public submissions.
Expense Administrator
For the person who sets Expense up.
- expense:categories:read, expense:categories:create, expense:categories:update, expense:categories:delete
- expense:policies:read, expense:policies:create, expense:policies:update, expense:policies:delete
- expense:petty-cash-funds:read, expense:petty-cash-funds:create, expense:petty-cash-funds:update, expense:petty-cash-funds:delete
- expense:external-payees:read, expense:external-payees:create, expense:external-payees:update
- admin:expense-settings:read, admin:expense-settings:create, admin:expense-settings:update, admin:expense-settings:delete
- admin:expense-settings-me:read
- admin:expense-settings-public-submission-link:read, admin:expense-settings-public-submission-rotate-token:create, admin:expense-settings-public-submission-deactivate:create
A category needs an expense account, so the person also needs permission to read the Chart of Accounts. Approval templates are managed under Administration, with their own permissions.
Two screens have no menu item behind them
Two permissions allow actions with no Expense screen today. Do not rely on them: "Return unspent advance cash" and "See a petty cash fund's ledger".