Access control in Autovella works at three levels: your role, per-module permissions, and record-level sharing, so the right people see exactly the right work.
As a team grows past a handful of people, “everyone sees everything” stops being a reasonable default. Autovella's permission model is built to scale from a small team where most people have broad access to a larger organization where access needs to be precise, without requiring a full rebuild in between.

Autovella ships with a set of default roles: Admin (full access, billing, integrations, org settings), Manager (approves time and expenses, manages team projects), Employee (logs time, works assigned tasks), Contractor (similar to Employee, typically scoped to specific projects), and Finance (invoicing, expenses, payment tracking, without project management access). These cover most organizations without any customization needed on day one, see Getting Started with Autovella for how to assign them during setup.
When the default roles don't fit, a client-facing coordinator role that needs to see projects but not financials, for example, custom roles can be built from Settings → Roles. Each custom role is a specific combination of module-level permissions (read, create, update, delete) across CRM, projects, time, billing, and every other module, so access can be as broad or as narrow as the position actually requires.
Beyond role-based module access, individual records, a specific project, a specific account, can be shared with a team or an individual regardless of their default role permissions. This is what lets a contractor see exactly the one project they're staffed on without being granted broad access to every project in the organization.
Record-level sharing is the difference between "can this role see projects" and "can this person see this project." Most access problems in a growing team come from needing the second, more specific answer, not the first.
We'll walk through setting up roles that match how your organization is actually structured.
Yes, roles can be changed at any time from Settings → Team without needing to re-invite the person, and the change takes effect immediately on their next action in the app.
A role sets baseline permissions across an entire module (e.g., can this person see any project). Record-level sharing grants or restricts access to one specific record regardless of their role, useful for giving a contractor visibility into exactly one project without broader access.
No, SSO and SCIM are optional and available on the Enterprise plan for organizations with existing identity provider requirements. Smaller teams typically use standard email/password or Google sign-in without any issue.