Relay lets account admins invite team members with their own logins and assign one of six preset permission levels, with custom roles available when the presets do not match a specific job.
Who this is for
Business owners setting up their team on Relay for the first time
Admins reviewing what each teammate can currently see and do
Owners considering delegating bill pay, card management, or bookkeeping access
Accountants and bookkeepers being invited to a client account (see Advisor permissions in client accounts for the accountant-specific path)
How team member permissions work
An account admin invites a teammate by email from the Team settings area of Relay.
The admin picks one of the six preset permission levels, or picks a custom role the business has created.
The teammate accepts the invite, sets their own password, and enrols in two-factor authentication.
If the assigned role includes any transaction permission (sending payments, moving money, using a card), the teammate is required to add a personal address before they can transact.
Admins can change a teammate's permission level, restrict them to specific accounts, or remove them at any time.
The six preset permission levels
Every teammate is assigned exactly one preset role, unless the business has created a custom role for them. Each preset caps what a teammate can view, edit, and transact on.
Permission level | What they can do | Typical use |
Admin | Full control over accounts, cards, payments, team, and settings | Business owners, co-owners |
Manager | Manage cards and team; view-only on accounts and transactions | Operations leads |
Bill Payer | Send payments via ACH, wire, and check; manage payees | Bookkeepers, AP staff |
Cardholder | Manage their assigned card and view their own card transactions | Employees issued a card |
Deposit Only | Deposit checks and view assigned accounts only | Front-of-house staff, deposit clerks |
Read Only | View transactions, statements, and connected integrations | Auditors, silent partners |
What can an Admin do?
An Admin has full control over the Relay account, including opening and closing checking and savings accounts, issuing and freezing cards, sending payments, inviting or removing team members, and changing settings. Only owners and co-owners should hold Admin permissions.
What can a Manager do?
A Manager can issue and manage cards, invite and manage team members, and view all accounts and transactions, but cannot move money or open new accounts. Managers are the right fit for an operations lead who owns team and card administration without payment authority.
What can a Bill Payer do?
A Bill Payer can send payments through ACH, wires, and checks, add and manage payees, and view accounts they have been given access to. Bill Payers cannot issue cards, invite teammates, or change account settings. This is the standard role for bookkeepers and accounts payable staff.
What can a Cardholder do?
A Cardholder can view and manage the card they have been assigned, see their own card transactions, and freeze or unfreeze that card. Cardholders cannot view accounts, send payments, or see anyone else's card activity. Use this role for employees who need spending access without visibility into the wider business.
What can a Deposit Only user do?
A Deposit Only user can deposit checks into the accounts they have been given access to and view those accounts. They cannot send payments, issue cards, or view accounts they have not been assigned. This role suits deposit clerks and front-of-house staff who need to move incoming money into the account without any outbound authority.
What can a Read Only user do?
A Read Only user can view transactions, statements, and connected integrations across the accounts they have been given access to, but cannot make any changes. Read Only is the correct role for auditors, silent partners, and anyone reviewing activity without acting on it.
How to customize permissions beyond the preset roles
Relay supports custom roles for cases where none of the six presets match a job cleanly. Custom roles let an admin combine specific permissions (for example, Bill Payer authority scoped to one checking account, or Read Only access to statements but not to transactions). Custom roles are created in Team settings and can be reused across teammates.
What team members with transaction permissions need to provide
Any teammate assigned a role that lets them move money or use a card is required to add a personal address to their profile before they can transact. Business owners already on the account are exempt because their address is captured during application. See Why Relay needs a personal address for team members with transaction permissions for the specific security rationale.
What's included and what's not
Included in every preset role:
Two-factor authentication on the teammate's login
Session activity visible to admins
Ability for the admin to change the role, restrict accounts, or remove the teammate at any time
Not included in any team member role (owner-only actions):
Adding or removing business owners
Closing the Relay Account
Changing the legal business name or entity type
Updating the business address on file
Related articles
How to invite team members and advisors to your Relay account
How to remove team members and advisors from your Relay account
Why Relay needs a personal address for team members with transaction permissions
Talk to our Customer Experience team
If this article did not fully answer your question, our Customer Experience team is here to help.