Employee
Prepares their own reports and evidence, responds to returns and follows their reimbursement status.
Give each employee and reviewer the scope their expense work requires.
Summarised from the authored role permissions. Scope restrictions such as “own records” still apply; these symbols do not indicate completeness or runtime access.
| Table | Controller / CFO | Finance Reviewer | Manager | Employee | Cardholder | Audit |
|---|---|---|---|---|---|---|
| master | ||||||
ExpensePolicies | Specific actions: Approve ExpenseReports above ExpensePolicies.HighValueThreshold (the auto-added Controller step in the approval chain) | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated |
| transaction | ||||||
CardTransactions | —No table-specific permission stated | Specific actions: Update on CardTransactions (set Status: Disputed or Excluded, manually pair to MatchedExpenseLine) | —No table-specific permission stated | —No table-specific permission stated | Specific actions: Update on own CardTransactions to advance Status: Unmatched → Matched by linking to a self-authored ExpenseLines.PaymentMethod = CorporateCard row, or to flag Status: Disputed with a dispute reason | —No table-specific permission stated |
ExpenseReports | Specific actions: Approve ExpenseReports above ExpensePolicies.HighValueThreshold (the auto-added Controller step in the approval chain) | Specific actions: Update on ExpenseReports (approve / reject / hold at the Finance step), ExpenseLines (adjust ApprovedAmount and Disallowance), ExpenseApprovalSteps, PolicyViolations (mark Justified or Waived for Soft / Hard) | Specific actions: Update on ExpenseReports for own reports' chain step (approve / reject / hold at the Manager step) | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated |
| line item | ||||||
ExpenseLines | —No table-specific permission stated | Specific actions: Update on ExpenseReports (approve / reject / hold at the Finance step), ExpenseLines (adjust ApprovedAmount and Disallowance), ExpenseApprovalSteps, PolicyViolations (mark Justified or Waived for Soft / Hard) | —No table-specific permission stated | —No table-specific permission stated | Specific actions: Update on own CardTransactions to advance Status: Unmatched → Matched by linking to a self-authored ExpenseLines.PaymentMethod = CorporateCard row, or to flag Status: Disputed with a dispute reason | —No table-specific permission stated |
PolicyViolations | —No table-specific permission stated | Specific actions: Update on ExpenseReports (approve / reject / hold at the Finance step), ExpenseLines (adjust ApprovedAmount and Disallowance), ExpenseApprovalSteps, PolicyViolations (mark Justified or Waived for Soft / Hard) | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated |
ExpenseApprovalSteps | —No table-specific permission stated | Specific actions: Update on ExpenseReports (approve / reject / hold at the Finance step), ExpenseLines (adjust ApprovedAmount and Disallowance), ExpenseApprovalSteps, PolicyViolations (mark Justified or Waived for Soft / Hard) | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated |
Prepares their own reports and evidence, responds to returns and follows their reimbursement status.
Justifies and matches their own company-card charges without approving the statement.
Reviews direct reports for business purpose; cannot approve their own claim or replace Finance line-level decisions.
Reviews policy, evidence and approved amounts; prepares reimbursement and card reconciliation work.
Owns required high-value decisions and signs the card statement reconciliation.
Reads the permitted evidence and reporting population without changing decisions.
Configures identities, rules and integrations; cannot use administrative access to replace an independently assigned financial decision.
Oversight role. Reviews high-value reports, audits PolicyViolations trends, signs off CardReconciliations, and owns the relationship with the card program and the reimbursement-channel decision (PayrollAddOn vs SeparateACH).
CRUD on ExpensePolicies, PolicyRules, CardReconciliationsRead on all tablesApprove ExpenseReports above ExpensePolicies.HighValueThreshold (the auto-added Controller step in the approval chain)Override or waive Hard PolicyViolationscannot waive Block-severity without break-glassSign off CardReconciliations (Status: Balanced → Approved)Expense review waits for the finance reviewer.
The post-manager approver. Checks policy compliance, releases the reimbursement, owns the CardTransactions matching backlog, and is the primary preparer on CardReconciliations.
CRUD on Reimbursements, CardReconciliations, MealsAndEntertainmentUpdate on ExpenseReports (approve / reject / hold at the Finance step), ExpenseLines (adjust ApprovedAmount and Disallowance), ExpenseApprovalSteps, PolicyViolations (mark Justified or Waived for Soft / Hard)Update on CardTransactions (set Status: Disputed or Excluded, manually pair to MatchedExpenseLine)Read on CorporateCards.CardLast4, CardTransactions.RawDescription, all Receipts including OCR fieldsCannot approve a Block-severity PolicyViolation, modify ExpenseCategories / ExpensePolicies / PolicyRules (Admin / Controller scope), or post directly to the GL (the gl-post-on-approval workflow does that)Expense review waits for the finance reviewer.
Line manager with scope over direct reports only. The first approver in the chain. Sees aggregate spend for own team but cannot see another team's reports.
Read on ExpenseReports and ExpenseLines where ExpenseReports.Submitter.Manager = selfUpdate on ExpenseReports for own reports' chain step (approve / reject / hold at the Manager step)Read on Receipts and PolicyViolations for those same linesCannot see another manager's team's reports, cannot see CorporateCards, CardTransactions.RawDescription, or Reimbursements.Amount of reportsCannot waive Hard or Block PolicyViolations (routes to Finance Reviewer)Cannot modify ApprovedAmount — the Manager step is approve-as-submitted or rejectBusiness-purpose approval waits for the manager.
Self-service submitter. Files own ExpenseReports, uploads Receipts, captures Mileage, registers own Vehicles. Reads own reimbursement status. Cannot see anyone else's data.
CRUD on own ExpenseReports, ExpenseLines, Receipts, MileageEntries, Vehicles, MealsAndEntertainment (when authoring own M&E lines) while ExpenseReports.Status IN (Draft, Held, Rejected)Read on own Reimbursements (Amount, Status, ScheduledFor, PaidAt)Read on ExpenseCategories, ExpensePolicies, PolicyRules, MileageRates, PerDiemRates (the published rule set the submitter must comply with)Cannot edit a Submitted report without recall (recall flips Status back to Draft and voids the prior approval steps)Cannot approve own reportCannot see other employees' reports, receipts, mileage, or reimbursements| Report Number | Report Title | Report Date | Total Amount | Violation Count |
|---|---|---|---|---|
| ER-55874 | Draft er-862 | 23 Sep | 35,007.68 | 40 |
| ER-85238 | Held er-818 | 09 Sep | 6,045.03 | 24 |
| ER-67722 | Rejected er-948 | 06 Sep | 22,364.51 | 40 |
| ER-55379 | Draft er-233 | 21 Sep | 20,652.06 | 37 |
| ER-50233 | Held er-299 | 27 Sep | 17,294.00 | 25 |
| ER-10944 | Rejected er-608 | 24 Sep | 35,083.61 | 14 |
A Permissions attribute on Employee — set true when the Employee has at least one CorporateCards.Cardholder = self row in Status: Active. Inherits all Employee permissions plus card-specific surfaces.
Read on own CorporateCards (CardLast4 visible to self, masked to non-self Employees)Read on own CardTransactions (RawDescription visible to self)Update on own CardTransactions to advance Status: Unmatched → Matched by linking to a self-authored ExpenseLines.PaymentMethod = CorporateCard row, or to flag Status: Disputed with a dispute reasonRequired to justify (attach Receipt + Category + Description) every CardTransaction within ExpensePolicies.JustificationWindowDays (default 30)Cannot see another Cardholder's transactions or cards| Report Number | Report Title | Report Date | Total Amount | Violation Count |
|---|---|---|---|---|
| ER-55874 | Draft er-862 | 23 Sep | 35,007.68 | 40 |
| ER-85238 | Held er-818 | 09 Sep | 6,045.03 | 24 |
| ER-67722 | Rejected er-948 | 06 Sep | 22,364.51 | 40 |
| ER-55379 | Draft er-233 | 21 Sep | 20,652.06 | 37 |
| ER-50233 | Held er-299 | 27 Sep | 17,294.00 | 25 |
| ER-10944 | Rejected er-608 | 24 Sep | 35,083.61 | 14 |
Read-only seat for periodic audit sampling — internal Audit team, external auditor, or controls reviewer. Full visibility across the expense surface; access is audit-logged at the row level.
Read on all tables including CorporateCards.CardLast4, CardTransactions.RawDescription, Receipts (including OCR fields), PolicyViolations, ExpenseApprovalSteps, Reimbursements, and CardReconciliationsCannot create, update, or delete any rowCan export reportsAll Audit reads write a row to the access logOwn-report and direct-report scope applies to records, receipt files, exports, references and API actions. Preserve sensitive card and employee payment fields. Test delegated actions and copied links alongside ordinary queues.
Systems administrator. Owns configuration, integrations, and master data. Not the day-to-day expense submitter or approver.
Oversight role. Reviews high-value reports, audits PolicyViolations trends, signs off CardReconciliations, and owns the relationship with the card program and the reimbursement-channel decision (PayrollAddOn vs SeparateACH).
The post-manager approver. Checks policy compliance, releases the reimbursement, owns the CardTransactions matching backlog, and is the primary preparer on CardReconciliations.
Line manager with scope over direct reports only. The first approver in the chain. Sees aggregate spend for own team but cannot see another team's reports.
Self-service submitter. Files own ExpenseReports, uploads Receipts, captures Mileage, registers own Vehicles. Reads own reimbursement status. Cannot see anyone else's data.
A Permissions attribute on Employee — set true when the Employee has at least one CorporateCards.Cardholder = self row in Status: Active. Inherits all Employee permissions plus card-specific surfaces.
Read-only seat for periodic audit sampling — internal Audit team, external auditor, or controls reviewer. Full visibility across the expense surface; access is audit-logged at the row level.
Create your ERP.AI account and get started with Proto.
We use essential cookies to run the site and optional cookies for features, analytics, and relevant content. See Cookie policy
We use cookies to enhance your experience, analyze site traffic, and serve relevant content. By clicking "Accept All," you agree to our use of cookies. You can customize your preferences at any time.
Learn more about how we use cookiesThese cookies are required for the website to function properly. They ensure security, enable basic features like page navigation, and store user session data. You cannot disable these cookies.
These cookies enable additional features that enhance your experience, such as live chat, video playback, personalized content recommendations, and remembering user preferences.
These cookies help us understand how visitors interact with our site by collecting anonymous usage data. This allows us to measure performance, detect issues, and continuously improve the user experience.
These cookies allow us and advertising partners, including X, to deliver ads tailored to your interests. They track browsing habits across sites to provide relevant advertising and measure ad effectiveness.