invoice.manage covers the document. payment.record covers the money against it.
What each capability unlocks
- invoice.manage
- payment.record
- See Invoices in the sidebar
- Open the invoice list and any invoice
- Create an invoice
- Edit a draft
- Send an invoice
- Void an invoice
- Export the PDF
- See the next automatic invoice number
- See which time and expenses are available to invoice
Roles at a glance
Four roles can invoice. Three cannot see the Invoices page at all.
Finance and Project Manager both invoice
They come at it from different directions.- Daniel Okafor (Finance) owns the money surface. He raises invoices, records payments and chases what is owed. He holds no rate capability, and no delivery capability – he cannot approve a timesheet.
- Priya Raman (Project Manager) owns delivery. She approves the time, manages budgets, and can invoice the work she runs.
Three gates, in order
A write into invoicing has to pass three separate checks.1
Is the app on?
The Invoices app can be switched off per workspace at Settings → Apps. Off means hidden – the sidebar item is gone, and a direct URL does not work either.
2
Does the plan include it?
Invoicing and payments are Pro features. Not on your plan means visible with an upgrade prompt, not hidden.
3
Do you hold the capability?
Without
invoice.manage, the page refuses to load its data.“Switched off” and “not on your plan” are different things. Off means gone. Not on your plan means it stays in the sidebar and shows an upgrade prompt, so you can always see what you are missing. See /concepts/apps-and-modules.
The plan gates in detail
Dropping to Free never hides your invoices. The list and every document stay readable, so your records are always yours. See /concepts/plans-and-features.
Cost never reaches an invoice
Invoices carry client-facing money only – subtotal, discount, tax, total, and the ledger. Internal cost is removed before any invoice data leaves the server, whoever is asking. That is why an invoice can safely be shown in the client portal, and why the PDF is safe to forward. Cost visibility is its own capability,rate.viewCost, and it applies to rates and time entries, not to invoices. See /rates/rate-permissions.
Client portal contacts
A portal contact holds zero internal capabilities. They see:- Invoices belonging to their own client company
- The invoice lines, redacted for a client audience
- Nothing about your other clients, your team’s rates, or your costs
Buttons appear only when you can use them
The invoice screen hides actions you cannot take, so you never click into a refusal:
Every one of them is re-checked on the server, so a hidden button is a convenience, not the security.
Capability is not scope
A capability says whether you may act. Which clients and projects you can act on is your supervision scope. Both have to pass, so a Project Manager withinvoice.manage can still only invoice the clients and projects in their scope.
Common questions
Can someone invoice but not take payment?
Can someone invoice but not take payment?
Yes, through a custom role with
invoice.manage but not payment.record. The default roles always hold both together.Can a Member see invoices for their own project?
Can a Member see invoices for their own project?
No. Members hold neither capability, so the Invoices page is not available to them.
Why can Finance invoice without seeing rates?
Why can Finance invoice without seeing rates?
Because pricing already happened. Every time entry carries the rate it was recorded at, so the builder shows money without ever showing a rate table.
Can a client see an invoice?
Can a client see an invoice?
Only through the client portal, only for their own company, and only redacted for a client audience.
What if the Invoices app is switched off?
What if the Invoices app is switched off?
The sidebar item disappears, direct URLs stop working, and nothing can be written. No data is deleted – turning the app back on brings everything back.
Can I stop one person invoicing without changing their role?
Can I stop one person invoicing without changing their role?
Some capabilities can be denied per person. Check the person’s record, or move them to a custom role.
Troubleshooting
Related guides
Roles and capabilities
The full permission model.
Apps and modules
The app switch.
Plans and features
What Pro unlocks.
Rate permissions
Why Finance sees no rates.
Invoicing overview
The whole flow.
Record a payment
What payment.record unlocks.