Users and permissions
A company's users are managed under Company Settings > Company Users. Inviting someone is the easy part; deciding what they may do is the part worth understanding, because permissions here are granular rather than a handful of named roles.
Two special permissions
Administrator covers everything within the company: settings, users, registrations, invoices, integrations. Every company needs at least one, and in practice it should have two — an account with a single administrator is locked out the day that person is unavailable.
Super Administrator is a platform-level permission held by Melasoft, not something granted inside your company. If you were told to "ask an admin", that means your company's administrator, not this.
Everything else is a specific permission
Rather than roles like "accountant" or "clerk", each action is its own permission. They fall into areas, and most areas separate seeing from changing:
| Area | What the permissions cover |
|---|---|
| Sent invoices | View the PDF or XML, filter and search, add and edit notes, update or delete a sent invoice, send it again by Peppol or e-mail, send it to the authorised institution |
| Incoming invoices | View the PDF or XML, filter and search, notes, update or delete an incoming invoice, upload one by hand, create an invoice from a PDF, use the AI assistant |
| Invoice creation | Easy Invoice, creation from a document, creation from an Excel spreadsheet |
| Drafts and templates | View drafts, save, update and delete templates |
| Company | View company settings, update company info, edit or delete the logo, add and remove users, edit users, add and remove sub-companies, list sub-companies |
| Partners | View, search, add, update and delete partner records |
| Invoice settings | Invoice numbering, currency, notes, the XSLT template |
| View e-mail settings, SMTP settings, e-mail creation settings | |
| ERP and API | View ERP management, create, renew, activate and delete API keys, SFTP management, DATEV management |
| Certificates | Certificate management, delete a certificate |
| Dashboard | Incoming and outgoing statistics, package purchase view, view company users |
A user without a permission does not see a disabled button — the screen or action is simply absent. This is the usual explanation for "the option is not there for me but you have it": compare permissions before looking for a fault.
Patterns that work
An external accountant normally needs to read, not write: view incoming and sent invoices with PDF and XML, filter and search, view partners, and nothing under Company or ERP. They do not need administrator to do a month-end.
An accounts-payable clerk needs the incoming side in full — upload, update, notes — plus drafts, and no company settings.
Someone who only issues invoices needs the creation permissions, drafts and templates, partners, and the sent-invoice side.
A read-only reviewer gets the view permissions across both invoice sides and nothing else. This is the safest way to give a colleague or an auditor access without risking a change.
Granting administrator because it is quicker is what produces accidental deletions later — a deleted company or a removed registration is not undone by restoring the permission.
Inviting and removing
An invitation goes to the person's e-mail address, and they set their own password; you never type a password for someone else. If the address was already invited, the platform offers to resend the invitation rather than creating a second account.
Removing a user removes their access to that company. It does not delete the invoices they created, the notes they wrote or the audit trail of what they did — those belong to the company.
A user can belong to several companies. Removing them from one company leaves their access to the others untouched, and their own account continues to exist.
Sub-companies
A sub-company is a separate company under the same subscription, with its own SIREN, its own PPF directory lines and its own Peppol registrations. Adding one needs the Add Sub-Company permission, and it counts against the companies allowance on your plan.
Access to a sub-company is not inherited. Whoever creates it becomes its administrator automatically, but the other users of the parent company gain nothing — they have to be added to the sub-company, and its users are managed on that company rather than on the parent.
One consequence is worth planning for: if a single person creates every sub-company, they are the only administrator of each one. Add a second administrator per company as you go.