← Back to Blog

Finance Permissions for Startup Teams: Who Should See Revenue?

At five people, everyone knows the number. At fifteen, someone screenshots ARR in Slack and a new AE quotes a discount against a margin nobody explained. Finance permissions are not bureaucracy — they are how you keep sellers focused on pipeline while finance, founders, and admins see revenue, expenses, invoices, and forecasts without accidental leaks. Salestrics now gates Ledger surfaces, dashboard finance metrics, and Insight finance datasets by role. Here is a sensible default map for seed-stage teams.

Why do open finance permissions hurt early teams?

Because informal access does not scale past the founder’s memory. Everyone “knowing the number” works until it does not — wrong discount assumptions, accidental exports, support staff seeing contract terms they should not repeat. Gates are not about distrust; they are about matching UI to job function so CRM and finance stay linked without everyone living in the ledger.

Who gets what — a seed-stage default

RoleShould seeShould not see
Founder / CEOFull finance + pipeline
Finance / ops leadLedger, invoices, forecasts, Insight finance datasetsAdmin SSO keys unless also admin
SalesPipeline, customer health, their dealsCompany-wide revenue exports, expense detail
SupportCases, account contextInvoices, margins, bank transactions
EngineeringCases tied to incidentsCommercial terms, ARR dashboards

Adjust for your stage — the point is a written default, not perfection on day one.

Where gates show up in the product

  • Ledger — revenue, expenses, budgeting, invoices, forecasts, transactions require finance permissions.
  • Dashboard — finance KPIs hide when your profile lacks access.
  • Insight — finance and revenue datasets disappear from the schema explorer without finance access.
  • Admin — org settings, user directory, and admin quick view stay org-admin only; the shield icon hides for everyone else.

Finance gates also stop spinning when org context is missing — a reliability fix that matters during subdomain and custom-domain setups.

Rollout checklist

  1. List who currently exports revenue for board decks — that is your finance profile cohort.
  2. Remove finance KPIs from seller home screens; keep pipeline front and center.
  3. Align Insight semantic metrics definitions with Ledger so ARR means one thing.
  4. Review after first hire in sales or finance — permissions drift silently otherwise.

Permission gates expanded in Changelog #11. For import/export with the same respect for access, see CRM data import and export.