• Sign In
  • Pricing
  • Sign In
  • Instant Demo
  • Get Started Free
Products
  • HRMS

    Manage employees, track time, & more

  • Invoicing

    Turn time into invoices and deliver in bulk

  • Business Intelligence

    Compile your data into helpful reports

  • Performance Management

    Set goals and track your team

  • Employer of Record

    Built-in payroll outsourcing

Solutions
  • Contract

    Manage all of your contractors on assignment

  • Direct Hire

    Store direct hire starts, invoice, and create reports

  • Owners & Managers

    Performance management, easy-to-use reports

  • Pay & Bill Admins

    Integrated system streamlines your back-office

  • Individual Contributors

    Personal metrics reports, bullpen dashboards

Integrations
  • ActivateStaff logo
    ActivateStaff

    Candidate Engagement

  • Bullhorn logo
    Bullhorn

    Applicant Tracking System

  • JobAdder logo
    JobAdder

    Applicant Tracking System

  • Oorwin logo
    Oorwin

    Applicant Tracking System

  • PrismHR logo
    PrismHR

    Payrolling

  • SmartSearch logo
    SmartSearch

    Applicant Tracking System

  • Sage logo
    Sage

    Accounting | Coming soon!

  • StaffUpApp logo
    StaffUpApp

    Candidate Engagement

  • Top Echelon logo
    Top Echelon

    Applicant Tracking System

  • Quickbooks logo
    QuickBooks Online & Desktop

    Payrolling & Accounting

Resources
Support
  • The Bilflo Blog

    Helpful insights into back-office automation

  • Ebooks

    Dive deeper and improve your processes

  • Automate Your Back Office

    Watch the free webinar

  • Case Studies

    How companies increased cash flow & scaled

  • Press Releases

    Company and product updates

  • FAQ

    Frequently asked questions

  • Knowledge Base

    How-tos and other helpful info

    Contact Support

    Having problems? We can help you

    Contact Sales

    We'll answer all your questions

Bilflo Team Member Permissions Guide

PostedJune 9, 2026
Last Updated OnJune 9, 2026
ByMichael Olson
You are here:
  • Main
  • Team Members
  • Bilflo Team Member Permissions Guide
← All Topics

For admins managing internal back-office staff (recruiters, account managers, billing, payroll, admins). Team members are internal users — different from contractors (who get a contractor portal) and client contacts (who get the approver portal).

Before you start

You need:

  • Administrator role (Role 2) — required to create team members and edit permissions
  • The new team member’s full name and work email
  • A clear answer to: what role do they need (recruiter, AM, biller, payroll, admin)? That drives which permissions to check

The model — read this once

Bilflo permissions work on three layers. Understanding them avoids hours of trial-and-error:

LayerWhat it controlsExamples
RoleBroad category — sets the type of userAdministrator, Production
Navigation permissionsGranular menu/feature accessCan see Billing, can create Invoices, can access Settings
Super User flagOverride switch — unlocks everythingOne toggle, used sparingly for owners/leads

A team member needs both a role AND navigation permissions to do anything useful. Setting a role alone gives them login access but an empty sidebar.

Roles for internal team members

The roles that matter for back-office staff:

RoleWhen to use
AdministratorMost back-office staff: recruiters, AMs, billing, payroll, ops
ProductionLimited access: timecard review, PTO, production dashboard. Use for floor supervisors or timecard-only roles

Step 1 — Create the team member

  1. From the sidebar, click People → Team Members.
  2. Click + Create New (or New) at the top of the list.
  3. You land on the Team Member Detail screen (URL: /people/team-members/new).

Fill in the form:

SectionRequired fieldsNotes
Personal InformationFirst Name, Last NameEmail is needed if you want them to log in
Team Member TypeW2, 1099, or NonePick None for back-office team members; pick W2/1099 if you’re also paying them through Bilflo
TaxesState/Federal filing (W2 only)Skip if Team Member Type = None
Work StatusFull Time / Part Time / Term + effective datesAffects reporting, not permissions
CompensationHourly / Salary / BurdenOnly matters if you’re paying them through Bilflo
Active / RegisteredChecked by defaultUncheck Active to disable login
  1. Click Save.

The team member exists but can’t see anything yet — no role and no permissions.


Step 2 — Assign a role

From the team member’s detail page (or the Team Members list, click their row), open their profile and set the Role dropdown.

For most internal back-office staff: pick Administrator.

For timecard-only / floor supervisor roles: pick Production.

Save the profile.


Step 3 — Set navigation permissions

This is where you control what they actually see and can do.

  1. From the Team Members list, click the Permissions button (or icon) next to the team member’s row.
  2. You land on the Permissions screen (URL: /people/team-members/permissions/{userId}).

You’ll see:

  • Super User checkbox at the top — leave unchecked for normal staff; check only for owners/leads who need to bypass all permission gates
  • Receive Approval Notifications — appears if Super User is checked
  • A hierarchical checkbox tree of features grouped under: Billing, People, Reports, Tools, Settings, Production, Approvals

Check the boxes for what they need. Each parent reveals child permissions; each child can reveal grandchildren.

  1. Click Save.

Important: the team member must log out and back in for new permissions to take effect (JWT token caching).


Common role recipes

Use these as starting points — adjust per individual.

Recruiter / Account Manager

Goal: see their book of business, set up jobs, approve time, view reports.

  • People → Clients, Contractors
  • Billing → Jobs (Setup, Approval), Contract (Setup, Starts, Overview, Approve Time, Missing Time)
  • Reports → Dashboards, Contract Summary, Sales & GP

Billing Clerk

Goal: generate, deliver, and track invoices; check time before billing.

  • Billing → Contract (Approve Time, Missing Time, Bulk Time), Invoices (Create, Deliver, History)
  • Billing → Accounting (Sync, Export) if they push to QuickBooks
  • People → Clients, Contractors (read-only is fine — they need to look records up)
  • Reports → Sales & GP, Custom Field

Payroll Specialist

Goal: review approved timecards, prep payroll exports.

  • Billing → Contract (Overview, Missing Time)
  • Billing → Accounting (Sync, Export, Payments)
  • Reports → Payroll, Census, Work Comp
  • Settings → Burden (read-only if just viewing)

Operations / Production Supervisor

Goal: approve timecards, manage PTO requests, watch the production dashboard. Use Role: Production here.

  • Billing → Contract → Approve Time
  • Production → Dashboard, Timecards
  • Approvals → all
  • Paid Time Off

Back-office Admin / Lead

Goal: everything plus settings, integrations, burden config.

  • Check Super User OR
  • Grant all of Billing, People, Reports, Tools, Settings, Production, Approvals
  • Settings → Company, Pay Bill Items, Custom Fields, Global Lists, Benefit Time Rules, Email, Invoicing, Burden, Billing, Integrations

Settings permissions worth special care

These can change company-wide config that affects every invoice, payroll, or contractor. Restrict tightly:

PermissionWhat it touches
Settings → BurdenCompany-wide burden rates — wrong number changes every GP calc
Settings → Pay Bill ItemsThe catalog of pay/bill items used on every Contract Job
Settings → Recalculate B-GPTriggers a company-wide recalc — heavy and irreversible
Settings → IntegrationsAPI credentials for Bullhorn, QuickBooks, Everee, etc.
Settings → BillingInvoice template, numbering, defaults
Accounting → Import / SyncPushes/pulls financial data to/from QuickBooks

Keep these to leads and admins only.


Updating a team member’s permissions

  1. People → Team Members → click their row → Permissions button.
  2. Check or uncheck what’s needed.
  3. Save.
  4. Tell them to log out and back in — token cache is the #1 reason people think permissions “didn’t save.”

Deactivating vs. removing a team member

WhatEffectWhen to use
Active unchecked on their profileSoft-disable; they can’t log in, record stays in reportsLeave of absence, short-term suspension, history retention
Remove roleStrips all access but keeps profileDemoting someone or rebuilding access from scratch
Delete (Actions → Delete on the detail page)Hard deleteOnly if the record was created by mistake; otherwise prefer Inactive

Don’t delete a team member who has ever approved a timecard, generated an invoice, or owns a Contract Job — you’ll orphan history. Use Inactive instead.


Common pitfalls

IssueWhat to do
New team member logs in and sees a blank sidebarThey have a role but no navigation permissions — go to People → Team Members → Permissions and check the boxes for what they need
Changed permissions but the team member still can’t see the new menuThey need to log out and log back in for the JWT token to refresh
Accidentally removed your own admin roleIf no other Administrator exists, you’re locked out — contact Bilflo support; ensure at least one other Administrator always has full access
Can’t find the Permissions buttonOnly Administrators see this button — confirm your own role
Team member can see menus they shouldn’tCheck the Super User checkbox on their Permissions page — if it’s on, they bypass all granular gates. Uncheck it if not intended
SSO-provisioned user has Bilflo login but no sidebarSSO auto-creates the user but doesn’t auto-assign navigation permissions — go to their Permissions page and check the right boxes
Permission shows in tree as available but they still get an “access denied” pageSome pages do server-side role checks in addition to navigation checks — confirm they have the right role (Administrator vs Production matters here)
Removed someone’s role but they can still see menusSidebar caches client-side until next login; force a logout

Permission cheat-sheet (most-used)

The full system has ~67 navigation permissions. The ones you’ll touch most:

PermissionUnlocks
BillingBilling parent menu
Contract Jobs (Create)Create new Contract Job
Approve TimeApprove timecards
Missing TimeMissing Time list
Direct Hire (Create)Create Direct Hire placement
Invoices → CreateCreate invoices
Invoices → DeliverDeliver invoices
Invoices → HistoryInvoice history
Accounting → Sync / Export / ImportPush/pull with QuickBooks
PeoplePeople parent menu
ClientsClients list & creation
ContractorsContractors list & creation
Team MembersTeam Members list & creation (needed to manage other team members)
ReportsReports parent menu
Reports → Dashboards / Sales & GP / Payroll / Work Comp / CensusSpecific reports
SettingsSettings parent menu
Settings → CompanyCompany-level config
Settings → Pay Bill ItemsPay/bill item catalog
Settings → IntegrationsBullhorn / QuickBooks / Everee credentials
Settings → InvoicingInvoice templates and defaults
Settings → BurdenBurden rates and items
Tags:
  • Permissions
  • Settings
  • Team Members
Previous How to Approve Timecards in Bilflo
Next Removing a Team Member in Bilflo
Table of Contents

Features
  • HRMS
  • Invoicing
  • Business Intelligence
  • Performance Management
  • Employer of Record
Solutions
  • Contract
  • Direct Hire
  • Owners & Managers
  • Pay & Bill Admins
  • Individual Contributors
Integrations
  • Bullhorn
  • JobAdder
  • Oorwin
  • PrismHR
  • SmartSearch
  • Top Echelon
Resources
  • The Bilflo Blog
  • Ebooks
  • Webinar
  • Case Studies
  • FAQ
  • Knowledge Base
  • Developers
Company
  • Pricing
  • Contact
  • Releases
  • Terms & Privacy
  • Cookie Policy

© 2026 Bilflo