Ask a human
waxTable

Account & team

Permissions explained

Each role bundles a set of permissions — what a person can see, draft, approve and manage — so the right people handle drafting, sign-off and billing without stepping on each other.

5 min readUpdated 18 Jun 2026

How permissions work

Permissions in waxTable are grouped into roles. Instead of deciding what each individual can touch, you assign a role when you invite a teammate, and waxTable grants the matching access. It's simpler to manage and far less error-prone than per-person rules.

The guiding principle is least privilege: give each person enough to do their job well, and no more. Sensitive areas — billing, team management, workspace settings — should sit with a small number of trusted administrators.

What the areas cover

Working on documents

Approving and sending

  • Review documents submitted for sign-off.
  • Approve or reject as part of an approval ladder.
  • Send approved documents from your domain and track opens.

Managing the workspace and billing

  • Invite, re-role and remove team members.
  • Change workspace-wide settings and branding.
  • View and manage the plan, top-ups and invoices.

Roles at a glance

Roles stack: higher roles generally include what lower roles can do, plus more. Use this as a guide when deciding who gets what.

A typical mapping of roles to permissions. Role names and the exact split may differ in your workspace.
CapabilityDrafterApproverAdministrator
Create projects & draft with WaxeYesYesYes
Edit documentsYesYesYes
Approve & send documentsNoYesYes
Manage team & rolesNoNoYes
Manage billing & planNoNoYes

Choosing the right level

  1. Start with the job

    Decide what the person actually needs to do day to day.

  2. Pick the smallest fitting role

    Grant the lowest role that covers that job. You can widen access later.

  3. Reserve admin for a few

    Keep billing and team management with a small, trusted group.

  4. Review periodically

    As responsibilities shift, re-role people so access stays accurate.

Permissions and accountability

Permissions decide what someone can do; the audit log records what they actually did. The two work together: tight roles prevent mistakes, and a clear history makes every action traceable.

Give people exactly the access their work needs — no more, no less — and let the record show the rest.

For the trail of who did what and when, see The audit log.

Frequently asked questions

Can a drafter send a document?

In a typical setup, sending sits with approvers and administrators. If your team uses an approval ladder, a drafter submits for sign-off and an approver sends once it's approved. See Approval ladders.

Who can see billing and invoices?

Billing is an administrator capability, so plan, top-ups and invoices are visible to administrators rather than every member. See Invoices & tax IDs.

Can I give someone read-only access?

Access follows the role you assign. Pick the lowest role that fits — if you need a narrower arrangement than the standard roles offer, contact support to discuss your needs.

If I change someone's role, when does it apply?

Role changes take effect right away, so you can broaden or restrict what a person can do as soon as their responsibilities change.

Does a lower role limit how much they can use Waxe?

Permissions control what areas a person can work in, not how much Waxe work the workspace can do. That's governed by your shared credits — see How credits work.

Still need a hand?

Waxe answers most questions right inside the app. For everything else, our team replies within one business day.

Email support