Bring your bookkeeper or partner into NoteHarbor with the right level of access. NoteHarbor has four access levels.
Read this before you invite anyone: there is no view-only level. Every teammate you add (including Team Member, the lowest level) can create and edit loans, borrowers, lenders, owners, and properties, and can record and edit payments. The levels differ in what they add on top of that, not in whether they can change your loan book.
The four access levels
- Owner: full control, including billing, branding, the per-loan Audit Log, per-seat report access, and managing the team. The person who creates the account is the Owner. An Owner can also promote a teammate to co-owner, a full peer; only the original account creator can promote or demote co-owners.
- Admin: everything except billing, manage loans, borrowers, payments, escrow, and documents, delete records, and manage the team (invite teammates, change access levels, remove people). Views the Audit Log read-only. Can't change billing, promote co-owners, or set per-seat report access.
- Manager: full day-to-day servicing, create and edit loans, record and edit payments, manage documents and reports. No deletions, team management, billing, or audit log.
- Team Member: the same operational access as Manager. Manager is a seniority label, not a higher permission. Choose either based on what you want to call the seat.
Picking a level
Give a trusted operations lead Admin. Note this includes deleting records and managing the team. Give Manager or Team Member to anyone who services loans day to day; they are equivalent in what they can do. Keep Owner for whoever owns the billing relationship.
If you need someone who genuinely cannot change anything (an outside CPA, say), don't give them a seat at all, because every seat can edit. Send them the CPA export instead: a one-click ZIP they can open without touching your account.
Fine-tune Reports access per person
Per-seat Reports access (Owner only, on the Team page) is a different tool from the four levels above, and worth not confusing with them: it narrows which Reports surfaces, Data, CPA Packets, and Reports → Audit (the org-wide audit trail export), an existing teammate can open. It does not reduce their ability to edit loans and payments, and it does not touch the separate per-loan Audit Log tab on a loan's own page, which stays Owner/Admin-only regardless of any override.
Each surface has an Inherit / Allow / Deny control under Settings → Team: Inherit keeps the seat default (Data and CPA open to every seat; Reports → Audit for Owner/Admin), Allow grants a surface the seat wouldn't normally see (for example, giving a Manager Reports → Audit), and Deny removes one it normally has (for example, hiding CPA Packets from a Team Member). Changes save instantly and are written to the audit trail; only the Owner sees these controls. When MFA enforcement is on, a teammate granted Reports → Audit is held to the same two-factor requirement as an Owner or Admin.
Access levels control what's visible and editable in the app: match the level to the trust and responsibility of each teammate.