Users
What the Users tab is for
The Users tab is admin-only. Invite new users, track the invitations you have sent, change roles, scope access to specific companies or departments, remove users to free seats, and decide whether this organization requires a passkey. The full roles and permissions matrix lives on the Settings overview.
TL;DR
Click Invite user, set role and access — the person accepts the invitation themselves. Edit any row to change role or scope. Remove a user to revoke access and free their seat. Passkeys below the table sets whether a passkey is required.
Users elements
Invite a user
Open the Invite user modal and finish with Send invitation. The person is not added straight away — they receive an invitation and accept it themselves.
- Email — where the invitation goes. statycs checks it as you type and warns you about your own address, someone already a member or already invited, and a domain nobody in the organization uses yet.
- First / Last name — optional, used for display until the user updates them.
- Role — Admin, Editor, Viewer, or Guest.
- Companies — pick the companies this user can see. The chip on the row shows
All companies, a single name, orN of M. - Departments (with the Departments add-on on) — pick the departments this user can see. Same chip shape.
Admins always see every company and every department; the Companies and Departments chips on admin rows are locked.
Invitations
Invitations you have sent sit as rows above the members, with their email, role, companies and status — Invited, Declined or Expired. Withdraw cancels an open one and Resend sends it again. A pending invitation cannot be edited: withdraw it and invite again.
An open invitation for a paid role holds a seat, and the seat counter says how many, so a seat is never promised twice.
Edit / remove
The row’s Edit action opens the same modal pre-populated. Remove revokes access and frees the seat (paid roles); a confirmation is required.
Companies scope chip
The Companies column on each row carries a single chip:
- All companies — full access (default).
- Acme GmbH — single company.
- N of M — multiple companies out of the total.
Click the chip to open the popover and tick the companies. Non-admins must keep at least one company; the popover blocks unchecking the last selection.
Departments scope chip
When the Departments add-on is on, a second chip on each row scopes the user to specific departments. Same shape — All departments / single name / N of M. Empty selection means full access. Admins are locked.
What scoped users see
Company scope takes effect immediately: a user only sees their assigned companies everywhere in the app.
A non-admin user with a department scope (i.e. fewer than all departments selected) sees only Financials, Planning, and Settings → Profile in the sidebar. Dashboard, Analysis, Data, and the other Settings tabs are hidden. In Financials they see only the P&L (BS / CF hidden), and the scope pill is locked to their departments.
Passkeys
Below the user table, administrators decide whether this organization requires a passkey to sign in: Required for — Nobody, Administrators or Everyone — and a Deadline from which it applies. A counter shows how many people already hold one.
Note
Switching the requirement on needs an administrator who is signed in with a passkey.
The Passkey column shows one of four values: Active, Waiting for approval, Declined or None yet. Review approves or rejects a new passkey; do that while you are on the phone with the person, so you know it was really them. Remind sends a reminder to someone who has not set one up. Lower relaxes the requirement again, and every administrator is notified.
See Sign in & onboarding for what the person on the other end goes through.
Related
- Settings overview — full role permissions matrix
- Departments — adds the per-user department scope chip
- Sign in & onboarding — accepting an invitation, passkey sign-in, and recovery
- Profile — where each person manages their own passkeys