Open Settings → Team & Permissions. Access should follow job responsibility, not convenience.
Access review
- Identify the person and the work they must perform.
- Choose the smallest role or permission set that enables that work.
- Pay particular attention to Settings, payments, Billing, user administration, and pricing activation actions.
- Save, then verify the result using an appropriate test account or with the user present.
- Revisit access when a person changes responsibilities or leaves the organization.
Never share a user account to bypass a missing permission. Shared accounts weaken auditability and make it harder to remove access safely. If a user cannot sign in or complete a security challenge, use the approved account-recovery path.
When a user must sign in again
Sessions have a maximum lifetime even when the user remains active. By default, a sign-in with Remember me lasts no longer than 30 days. Without Remember me, the session is capped at 24 hours from sign-in. Continued activity does not restart that maximum lifetime, and sign-out or an administrative security action can end a session sooner.
An expired session requires a fresh sign-in; it does not by itself change the person’s role, memberships or security setup. After signing in, reopen the work and confirm what was saved before repeating a booking or payment action.
If sign-in succeeds but an area or action is still unavailable, review the user’s assigned role and the organization they are working in. If sign-in repeatedly fails, record the time and non-sensitive error message for the approved recovery or support process instead of broadening the user’s permissions.