Invite people: How to manage roles and permissions for additional users

What's in it for you


Instead of maintaining a single "everyone can do everything" configuration, you build a clean multi-level permission model: per role, you define which contract categories are visible and at which access level (Read → Write → Full). All without an IT ticket, all traceable in the change log — important for GDPR, internal compliance and clean on- and offboarding.


How it works


1. Open the members overview


Go to Settings („Einstellungen").





In the left-hand sidebar under Organization („Organisation") you will find the dedicated menu item Members („Mitglieder"). You see the table of all active members with the columns First name, Last name, Email address, Organization Owner (green tick for owners), Role and Field Builder (green tick when access is enabled). If there are currently open invitations, they appear below under "Pending invitations (X)" („Ausstehende Einladungen (X)").





New since Aug 2026: Members, Roles and Change log are their own sidebar entries under Organization — previously they lived as cards inside the "Organization details" page.


2. Invite a new member


At the top right of the members page, click "+ Add new member" („+ Neues Mitglied hinzufügen").


The "Send invitation" („Einladung senden") dialog opens.


The blue info box states the core of the permission logic: Owners have full access to all contracts of a team; all other members get restricted access via roles, based on your role configuration.


Fill in:


  • Email address of the person to invite.
  • Language of the invitation email (default: German, alternative: English).
  • Optional: "Make this member an owner of the organization" („Machen Sie dieses Mitglied zum Eigentümer der Organisation") — toggle on if the person should get full admin rights. Multiple owners are allowed.
  • Select roles („Rollen auswählen") (mandatory) — at least one role from the list of roles configured in your account.





Click "Send invitation" („Einladung senden"). The person receives an email with an activation link and initially appears under "Pending invitations" („Ausstehende Einladungen").


3. Configure a role — the three access levels


Before you assign a role to a person, the role should have the right access level. In the sidebar under Organization → Roles („Organisation → Rollen") you create roles with one or more rules. Per rule, you choose conditions (e.g. Category = supplier contract) and one of three access levels:


  • Read access („Leserechte") — members with this role see the matching contracts but cannot edit them. Ideal for supervisory board, accounting, auditors, external consultants.
  • Write (read & edit, without delete) („Schreiben (lesen & bearbeiten, ohne Löschen)") — members can view and edit contracts, but not delete them. Delete actions are hidden for these users; the trash bin stays readable. Ideal for day-to-day work without the risk of accidental deletions. New since Aug 2026 — the middle ground between read-only and full access.
  • Full (read, write & delete) („Voll (lesen, schreiben & löschen)") — full access including delete. For roles that should fully manage a contract.


The access level works together with the rule's conditions: a person with the role "Legal Full Access" (Rule #2: Team = FAQs, Category = supplier contract, Full) may only fully edit that specific combination — everything else stays locked.





4. Change permissions of an existing member


Click a person's name in the members list. On the detail page you can adjust:


  • Owner role (on/off toggle)
  • Roles — add or remove. A person can carry several roles; the accesses combine as a union (with overlapping conditions the more generous level wins: Full > Write > Read).
  • Permission toggles for special features: Task automation, Field Builder, Contract templates — each individually unlockable. Owners get these permissions automatically.


Click "Save" („Speichern"). Changes take effect immediately.


5. Remove a member


Open the member's detail page and scroll to the bottom. The red button "Delete member" („Mitglied löschen") removes access.


Careful: deletion cannot be undone — all roles and settings assigned to the member are removed. Contracts and data stay in the system; only access is revoked.


Common questions


What is the difference between an owner and a regular member?


  • Owner: full access to all contracts, can invite members, assign roles, manage the organization. Multiple owners per account are possible — at least two are recommended to avoid a single point of failure.
  • Member with a role: sees only what the assigned role allows — typically restricted to specific contract categories and to a specific access level (Read, Write or Full). Special features like Task automation, Field Builder and Contract templates are unlocked separately per member.


When should I assign "Write" instead of "Full"?


"Write (read & edit, without delete)" is the right choice when you want to give a person editing rights — for example so they can maintain fields or upload documents — but prevent accidental or unaligned deletion of contracts, documents, contacts or tasks. Classic use cases: operational case handling, interns, temporary contract partners. Full stays for roles that genuinely own entire records (Legal, contract management).


How many members can I invite?


The limit depends on your plan. You see the current usage in the "Organization limits" („Organisationslimits") section on the "Organization details" page — e.g. "Team members 11 of 20". Once the limit is reached, the "+ Add new member" button is greyed out.


My invited member didn't receive the invitation — what now?


First, ask them to check the spam folder. If the email doesn't arrive: delete the pending user from "Pending invitations" and resend the invitation. Also check that the email address is correct and that your IT is not blocking emails from ContractHero (whitelisting helps).


The invitation is valid for 7 days. We recommend accepting it promptly after sending.


Can I temporarily deactivate a member instead of deleting them?


There is no pure deactivation at the moment. Alternatives:


  • Remove all roles — the member stays in the account but no longer sees any contracts.
  • Downgrade roles to Read access — if you only want to block write/delete rights.
  • Delete the member and re-invite them if needed.


Who changed what, when?


All changes to members, roles and permissions are logged in the change log under Organization → Change log — important for audits and compliance.


Can multiple roles be combined for one person?


Yes. The accesses of the assigned roles combine as a union. With overlapping conditions, the more generous access level wins: Full beats Write, Write beats Read.


Good to know


  • New "Write" access level since August 2026. If many roles in your organization used to be set to Full because there was no middle ground: check whether Write is the more appropriate choice. Reduces deletion risk noticeably.
  • At least two owners recommended. If the only owner leaves the company or loses access, the organization is left without an admin. Two owners per account is a sensible minimum safeguard.
  • Invitation language can be chosen. In the invitation dialog you set per person whether the invitation email is sent in German or English — relevant for international teams.
  • Maintain roles, don't configure per person. With several members doing the same job, it pays off to set up a role once cleanly (see "How can I create new roles?") and assign that role to multiple people — instead of setting permissions individually per person.
  • Owner rights are not delegatable. Only an owner can set owner status. Members without owner rights see the owner list but cannot change it.
  • Onboarding with a standard set: for recurring onboarding (e.g. new hires per quarter), a predefined "Standard onboarding role" that every newcomer automatically gets helps — the rest is added situationally.



Updated on: 09/02/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!