Skip to main content

Access

Last updated: September 17, 2026

The Access area controls who can use Lextree and what they can reach. Account admins manage it under Admin → Access. It has three sections: People, Groups, and Records.

People

Manage your members, invitations, and each person’s access.

Inviting someone

New Invite walks the decisions in the order the form asks for them:

  1. Email — who you’re inviting.
  2. Admin — whether they get the account admin flag (see below).
  3. Module permissions — per module, Editor , Viewer , or None. Everything defaults to Editor, so narrowing is the action: set None on modules they shouldn’t see.
  4. Guest — forces Viewer everywhere, excludes admin and reporting, and doesn’t occupy a seat. Use it for outside collaborators.
  5. Reporter — read access across the whole subscription through Reports. Hand it out carefully — see Reports before assigning it.
  6. Record access — All records, or limited to selected access groups ( Enterprise , once at least one group exists).

Save sends the invitation. Pending invites appear in the People list with their expiry — Manage lets you edit access before acceptance, or cancel it.

Seats count active, non-guest members who hold module access — deactivated accounts and guests don’t occupy one.

Roles

  • Editor — can view and edit records in that module.
  • Viewer — can view but not change records in that module.
  • Guest — limited, invitation-based access (for example, an outside collaborator).
  • Reporter — read access across the whole subscription through Reports, not just one module. Assign it carefully.

On Pro , everyone with access to a module is an Editor there. Per-module Editor/Viewer roles, the Guest role, and the Reporter role become available on Business and Enterprise plans.

Separately, the account admin flag (is_admin) governs who can manage billing, users, and permissions. On its own it grants no access to compliance data. Admins who also work with records need module roles too — and the reverse holds as well: a module role never sees more than a person’s record access setting and access groups already allow, admin or not.

For example: as an all-access user granted Viewer on a module, someone sees every record it holds, restricted ones included. Narrow their record access setting to a single access group and the restricted ones disappear — nothing changed but what they can see. Promote them to Editor and they can create and edit records, but still only the ones their record access setting and groups already show them.

Email Domain Allowlist

Restrict sign-in to chosen email domains from the People facet. Lextree blocks you from locking yourself out, and warns you — by name — if turning it on would exclude current members.

Groups

Create and manage access groups — named collections, such as a region or division, that a person’s record visibility can be scoped to. Each person has a record access setting: either they see all records in their modules, or their view is limited to the access groups they belong to. Group-based scoping is an Enterprise feature.

Records

Sharing isn’t set on every record individually — it’s set on the top-level record each record hangs from. In most modules that’s the organization or person the records belong to: share the organization, and its related records follow automatically. Contracts and properties are their own top-level records and are shared directly. A top-level record’s audience is one of three things: visible to everyone with module access, shared with specific access groups, or restricted — visible only to all-access users. New top-level records start restricted, so share one deliberately once it’s ready to be seen. Per-record visibility scoping is an Enterprise feature.

Search