The problem
Most small-business software gives you a handful of fixed roles and hopes they fit, or an all-or-nothing owner/staff split that either over-grants access or forces everyone through the owner for routine work. Neither approach lets a business say "this bookkeeper can do everything except void a transaction" or "this manager can approve purchases up to $10,000 but no more."
How AccountDesq solves it
Every permission in the product is defined once in a single registry, and 13 system roles are built from it - each with a real permission count and a plain-language description of what it's actually for ("Runs one branch day to day", "Rings up sales at one or more registers - no register administration or discount-override authority"). On Growth, any system role can be customized: cloning it opens a drawer with permissions grouped by module (Customers, Locations, Inventory, Purchasing, Sales, Banking, Accounting, Reports, and more), each with its own tri-state select-all and a description plus the raw permission code for every checkbox - so nothing is a black box. Existing members can migrate to the new custom role automatically, and the system role itself is never touched. Independently, per-member dollar approval limits cap what someone can do regardless of their role - a maximum amount for issuing invoices, recording payments, issuing purchase orders or vendor bills, adjusting inventory, or changing tax settings - the classic maker-checker control, scoped to a person rather than a title. A workspace can never lose its last Owner, and every privileged action writes an audit log row.
How it works, step by step
Start from a real system role
13 system roles, each with an honest permission count and a plain-language description of what it's for.
Customize on Growth
Clone any system role into your own version - the original is never touched, and existing members can migrate over automatically.
Pick permissions by module
A module-grouped picker shows every permission's description and its raw code - select all, clear all, or check them one by one.
Cap what a person can do alone
Set a per-member dollar approval limit on invoices, payments, purchase orders, vendor bills, or inventory adjustments - independent of their role.
Connected to the rest of AccountDesq
Nothing here works in isolation - it posts through the same ledger as everything else.
In practice
A distributor's Accountant role includes vendor and customer edit rights but not delete - fine for day-to-day bookkeeping, but the business also wants one bookkeeper trusted with slightly more. They clone Accountant into a custom role, add delete rights for vendors only, and migrate that one person over - the original Accountant role, and everyone else still on it, is completely unaffected.
What this means for your business
- Access can match how the business actually works, not just the handful of roles a vendor thought to build in.
- A dollar approval limit caps what one person can do alone, independent of their role - the same maker-checker control most software only offers as an all-or-nothing toggle.
- Every permission is documented in plain language and by its exact code - nobody has to guess what a checkbox actually grants.
Frequently asked questions
How many roles does AccountDesq come with?
13 system roles - Owner, Admin, Finance Manager, Accountant, External Accountant, Sales Manager, Viewer, Branch Manager, Warehouse Manager, Warehouse Staff, POS Cashier, POS Waiter, and POS Manager - each with a real, visible permission count.
Can I create my own custom role?
Yes, on the Growth plan - clone any system role into your own version, adjust its permissions module by module, and optionally migrate existing members to it automatically. The original system role is never changed.
What's the difference between a role and an approval limit?
A role defines what actions someone can take at all. An approval limit is a separate, per-member dollar cap on specific actions (issuing an invoice, recording a payment, adjusting inventory, and more) - so two people with the same role can still have different spending authority.
Can a workspace end up with no Owner?
No - the last remaining Owner is protected and can't be removed or have their role changed away from Owner, so a workspace can never lock itself out.