Team and roles
Inviting people into a wallet, what owners and editors can each do, and how access works for API keys.
A wallet can be shared. Everyone in it sees the same assets, transactions and reports; what differs is what they may change.
Roles
| Role | Can |
|---|---|
| Owner | Everything, including inviting and removing people, changing the base currency, and deleting the wallet |
| Editor | Read everything and change the data: assets, transactions, categories, plans, scenarios |
The difference is deliberately narrow. An editor is a full participant in the money; an owner additionally controls who else is.
Inviting someone
Invite by email address from the members view. They get a link; if they do not have an account yet, registering with that address puts them straight into the wallet. An invitation can be withdrawn before it is accepted.
What a shared wallet does not do
There is no read-only role and no per-asset permission. Somebody you invite sees everything in the wallet. If part of your picture should stay private, that part belongs in a separate wallet.
API keys and access
An API key is scoped to one wallet and carries its own role, so a key can be an editor in a wallet where you are the owner. Keys belong to the wallet rather than to the person who made one: they keep working if that person leaves, which is convenient for automation and worth remembering when someone does.
Support access
Walletguide support can sign in as you to investigate a problem, and when they do, every total is hidden from them: net worth, asset balances, and every chart of money. They can see a single transaction's amount, because that is usually the thing being debugged. You are not shown anything when this happens, and it is logged.