Finance Permissions for Startup Teams: Who Should See Revenue?
Why do open finance permissions hurt early teams?
Because informal access does not scale past the founder’s memory. Everyone “knowing the number” works until it does not — wrong discount assumptions, accidental exports, support staff seeing contract terms they should not repeat. Gates are not about distrust; they are about matching UI to job function so CRM and finance stay linked without everyone living in the ledger.
Who gets what — a seed-stage default
| Role | Should see | Should not see |
|---|---|---|
| Founder / CEO | Full finance + pipeline | — |
| Finance / ops lead | Ledger, invoices, forecasts, Insight finance datasets | Admin SSO keys unless also admin |
| Sales | Pipeline, customer health, their deals | Company-wide revenue exports, expense detail |
| Support | Cases, account context | Invoices, margins, bank transactions |
| Engineering | Cases tied to incidents | Commercial terms, ARR dashboards |
Adjust for your stage — the point is a written default, not perfection on day one.
Where gates show up in the product
- Ledger — revenue, expenses, budgeting, invoices, forecasts, transactions require finance permissions.
- Dashboard — finance KPIs hide when your profile lacks access.
- Insight — finance and revenue datasets disappear from the schema explorer without finance access.
- Admin — org settings, user directory, and admin quick view stay org-admin only; the shield icon hides for everyone else.
Finance gates also stop spinning when org context is missing — a reliability fix that matters during subdomain and custom-domain setups.
Rollout checklist
- List who currently exports revenue for board decks — that is your finance profile cohort.
- Remove finance KPIs from seller home screens; keep pipeline front and center.
- Align Insight semantic metrics definitions with Ledger so ARR means one thing.
- Review after first hire in sales or finance — permissions drift silently otherwise.
Permission gates expanded in Changelog #11. For import/export with the same respect for access, see CRM data import and export.