> ## Documentation Index
> Fetch the complete documentation index at: https://www.presolve.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Manage staff roles and permissions

> Separate job labels, application permissions, and case relationships.

Open [Settings → Organization](https://attorney.dearlegal.com/dashboard/settings?tab=organization) and find **Roles & Permissions**. Access roles determine what staff can do in Presolve. Your firm's role names are configurable, so a title such as Attorney or Accounting does not establish a universal set of permissions.

## Create an access role

1. Select **New Role**.
2. Enter the required **Role Name**, optional description, and color.
3. Review **Admin Role**. This grants full access to features and settings; use it only when that broad access is intended.
4. Review **Default Role**, which automatically assigns the role to new members when they join.
5. Select the permissions needed for the work. Read the descriptions and dependencies rather than selecting every item by category.
6. Select **Create Role** and review the saved role before assigning it to members.

<Frame caption="Creating an access role includes separate administrator and default-role settings.">
  <img src="https://mintcdn.com/grand-charter/zQHBSF8DN2vYm8-f/images/help/access-role-setup.jpg?fit=max&auto=format&n=zQHBSF8DN2vYm8-f&q=85&s=8b99688fd22cbec43330aaaa21b84c32" alt="Create Role dialog with name, description, color, and administrator-role switch." width="1280" height="720" data-path="images/help/access-role-setup.jpg" />
</Frame>

## Match permissions to the task

Permission groups distinguish viewing, creating, editing, approving, exporting, and executing work. Examples include:

| Work | Permissions to review together |
| - | - |
| Case access | View Cases, View All Cases, case assignment, and any practice restriction. |
| Accounting review | Viewing invoices/expenses, approving expenses, and Process Payments where the staff member chooses funding or records payments. |
| E-sign work | Viewing templates/documents, using templates, sending for signature, voiding, and downloading signed documents. |
| Approval review | View Approvals and Review Approvals; Manage All Approvals has broader organization scope. |
| Automation administration | View, Run, Edit, Publish, Manage Automation Access, and View All Automation Runs. Running a workflow does not expand case or action access. |
| Reports | Viewing, creating, exporting, and the separate Manage Report API permission. |
| Custom intake | Viewing, creating, editing, publishing, archiving, and managing section templates. |
| Calendar work | Viewing the calendar and the separate permissions to view, open, or manage other members' items. |

Some practice permissions explicitly require other permissions. For example, NSA workspace viewing also requires case-viewing access, and managing negotiations has additional case and negotiation requirements. Follow the descriptions shown in the role editor.

## Assign roles to members

In **Members**, find the intended person and check their identity. Use the **+** role control to assign an existing role. The role's name and its configured permissions are separate from the person's profile name or professional title.

The **Referral Network** toggle controls network visibility; it is separate from role assignment. **Invite Member** starts onboarding for another person, so review the destination and role before sending an invitation.

After changing access, have the member confirm they can open the intended page and perform the required task. Review case assignment and organization context if a record is still missing. Avoid treating an administrator's successful walkthrough as proof that every staff role has the same access.

For roles such as witness or referring attorney on an individual case, use [case-contact roles](/docs/help/admin/contact-roles).

## Roles used by reporting integrations

An integration key's API scopes and its acting attorney's organization roles are separate. A key with `reports:read` can call reporting endpoints, but an HQ rollup also checks the acting attorney's current report viewing/export, HQ visibility, and underlying data permissions. Managing the key requires Manage Integrations; that permission alone does not grant access to case or accounting data.

For shared child reports, authorized HQ editors need Create Reports and Manage Shared Resources to save the original. Organization-managed reports additionally require Manage Organization Reports, and managed templates stay protected. Copying a report creates a different ID, so existing integrations continue using the original until deliberately changed.

Use the [HQ reporting checklist](/docs/authorization#hq-saved-report-permissions) and [key management guide](/docs/service-accounts) when reviewing an integration's access. Application Accounting and Lead Overview permissions remain separate from a credential's report hierarchy toggle.
