Use permissions to control who can view, edit, export, and manage sensitive data in Avid. You can also control who can view invoices and receive billing emails, and optionally require third-party sign-in for your organization.
Use this article when…
- You need to give a teammate access to Avid (or restrict access).
- You need to confirm who can view invoices or update billing details.
- Invoice emails are going to the wrong person (or nobody is receiving them).
- You want to require Google, Microsoft, or Salesforce sign-in instead of email and password.
Applies to
| Roles | Admins and anyone with permission to manage team members |
|---|---|
| Where you manage it |
Settings » Team for user access levels. Settings » organization Profile » Login Security for third-party sign-in. |
| Time | 2–5 minutes |
Permission levels overview
For each platform section, you can assign one or more permissions:
- View: See available content or configurations.
- Edit: Modify configurations, input data, or update content.
- Export: Download data (for example, PowerPoint exports).
Where to manage user permissions
-
Go to Settings » Team
Click the Settings gear in the left navigation, then open Team.
Expected result: You see a list of team members and their access levels. -
Edit a team member
Find the user, click the ellipses ( … ), then select Edit Team Member.
Expected result: You see the user’s details and access level options. -
Choose an access level
Select one of the following:- Full Access — Full View, Edit, and Export access across Avid.
- View Only — View Avid features and reports, but no edits or exports.
- Notifications Only (No Access) — No access to Avid features, but can receive platform notifications.
- Custom — Set access per feature area (see below).
Require third-party sign-in (optional)
Separately from per-user access levels, organization admins can require users to sign in with Google, Microsoft, or Salesforce instead of email and password. This is an organization-wide Login Security setting on the Profile page.
Before you turn this on
Confirm at least one admin can sign in with the Microsoft, Google, or Salesforce button using the same email as their Avid account. After you enable the setting, email and password sign-in (including forgot password) is disabled for users in your organization.
-
Open organization Profile
Go to Settings, then open the organization Profile tab.
Expected result: You see your organization profile settings. -
Find Login Security
Scroll to Login Security.
Expected result: You see the third-party login toggle. -
Turn on the requirement
Enable Require third-party login (Google, Microsoft, or Salesforce), then save.
Expected result: The setting is saved for your organization. -
Verify with a teammate
Ask a teammate to sign out, try email and password, then sign in with Microsoft, Google, or Salesforce using the same email as their Avid user.
Expected result: Password sign-in shows: Your organization requires you to sign in with Google, Microsoft, or Salesforce. Third-party sign-in succeeds when the emails match.
What this does and does not do
- This uses Avid’s built-in Google, Microsoft, and Salesforce sign-in buttons.
- It does not set up a separate custom Entra or Okta app connection.
- Users with Settings & Team Members Edit access can change organization Profile settings, including Login Security.
- You can turn the toggle off later to restore password sign-in.
More Profile and team invite context: Your Organization and Brand and Adding Your Team.
Invoices and billing permissions
Invoice visibility and invoice emails depend on both team access and personal notification settings. For a full explanation of how billing permissions and invoice delivery work together, see Invoices and Billing Permissions.
Who can view invoices and manage billing details
- A user with Full Access can view invoices and receive invoices from Avid.
- A user with Full Access can also update the billing contact and charge items to the account (where available).
- An admin manages this in Settings » Team.
Billing email gotcha
Team access level controls what a user can do in Avid. It does not guarantee they will receive invoice emails. A user can have invoice access but still have billing emails turned off in their own profile.
How to turn billing invoice emails on or off
-
Open your profile settings
Go to Settings and open Profile.
Expected result: You see your profile page. -
Find Email Notifications
Locate Email Notification (email notification categories).
Expected result: You see category toggles (including Billing). -
Turn Billing notifications on or off
Toggle Billing on to receive invoice emails, or off to stop receiving them.
Expected result: Your billing email preference is saved for your user.
What admins can and can’t do
- Admins can change access in Settings » Team.
- Admins cannot edit another user’s personal notification toggles.
Troubleshooting: invoice emails are missing or going to the wrong person
-
Confirm team access
In Settings » Team, verify the intended recipient has Full Access (or the access level your process requires).
Expected result: The correct user has the correct access level. -
Confirm Billing email notifications
Ask the user to check Settings » Profile and verify Billing email notifications are enabled.
Expected result: Billing notifications are on for that user. -
Check spam/junk filters
Have the recipient search spam/junk for recent invoice emails.
Expected result: You confirm whether emails are being filtered.
If invoices still aren’t arriving
If the user has the correct access in Settings » Team and has Billing notifications enabled, submit a support ticket.
Collect diagnostics
- Organization name.
- Intended recipient email address.
- A screenshot of the user’s access level in Settings » Team.
- A screenshot of the user’s Billing email notification setting in Profile.
- Approximate time the invoice was expected.
LockStep insight
For shared inboxes (like ap@YOURORG.org), consider using Notifications Only plus Billing notifications enabled. This keeps billing email separate from product access.
Customizing a user’s access
With Custom access, you control permissions per feature area.
-
Benchmarks — General and seasonal benchmarks.
- View: Access benchmark data.
- Export: Download benchmark slides.
-
Scorecard — Performance ratings and projections across key fundraising metrics.
- View: See scorecard data.
- Edit: Apply custom filters to segment reporting.
-
Insights & Reports — Dashboards, presentation builder, and report pages.
- View: Access dashboards and reports.
- Edit: Edit goals for reports and segments.
- Export: Generate presentations and download aggregate tables.
-
Pathways — Manage integrations with connected marketing and advertising platforms.
- View: See connections and synced record counts.
- Edit: Modify connections, fields, and filters.
- Export: Create new Pathways.
-
Connections & Files — CRM, email, ad platform connections, and uploaded files.
- View: See mapping and setup configurations.
- Edit: Add or update connections and preferences.
- Export: Download uploaded data files.
-
Settings & Team Members — Organizational settings and user management.
- View: See organization profile info and team roster.
- Edit: Update profiles and manage team access (including invites). Edit also allows changing organization Profile settings such as Login Security.
-
Billing — Billing contacts, payment methods, and invoices.
- View: See billing information.
- Edit: Update billing details (where available).
What you’ll see
- Your team members have the right access for their role.
- You can confirm who can view invoices and who should receive invoice emails.
- Invoice emails match each user’s Billing notification preference.
- If Login Security is on, users sign in with Google, Microsoft, or Salesforce instead of email and password.
Best practices for user permissions
- Assign the least privilege necessary for each role.
- Grant Export only when downloads are required.
- Audit access regularly in Settings » Team.
- Use Edit sparingly for critical integrations (like Pathways and Connections).
- If you require third-party sign-in, confirm admin Microsoft/Google/Salesforce access works before you enable Login Security.
Next steps
- Invite a new teammate and assign an access level in Settings » Team.
- Have billing recipients verify Billing email notifications in Profile.
- Optionally require third-party sign-in under Settings » organization Profile » Login Security.
- If invoices are still missing, submit a support ticket with the diagnostics above.