CapitelistHelp Center

Security guide

Coming soon

Understand Role Permissions

Understand what owner, admin, editor and viewer style roles can and cannot do.

Current Capitelist screen for Understand Role Permissions.

Before you start

Decide what should be visible in normal workspace views and what must stay protected. Sensitive access details belong in encrypted/private areas, not ordinary notes or shared exports.

You know whether private data is currently hidden or included.
Sensitive details are ready to be stored only in protected fields.
You know who should and should not see this information.

Detailed steps

01

Open Settings > Users

Start from the screen named in the step and confirm the portfolio in the top bar before you change anything. If the wrong portfolio is selected, switch portfolios first.

02

Open role permissions or invite details

Start from the screen named in the step and confirm the portfolio in the top bar before you change anything. If the wrong portfolio is selected, switch portfolios first.

03

Compare allowed actions by role

Use this step to turn loose information into a clear portfolio record. If you are missing an input, note the gap instead of guessing.

04

Choose the least powerful role that supports the job

Pick the option that matches the real-world record you are adding or reviewing. If two options look similar, use the one that matches the source document, not the one that makes totals look cleaner.

Field guide

Visibility

Who can see the record in normal use.

Keep private operational details out of standard fields.
Recovery context

How the information can be understood later.

Document non-secret context clearly.
Protected notes

Sensitive details encrypted behind private controls.

Never store raw secrets in regular notes.
Release level

What a trusted person may receive.

Match the role and relationship deliberately.

Decision rules

What it adds

  • Makes collaboration safer and easier to explain.
  • Prevents accidental access escalation.

What it does not do

  • Role names do not override explicit private-data boundaries.
  • Some admin/support permissions may be internal only.

Common mistakes

What to check

  • Viewer should be enough for many external reviews.
  • Held Away and vault access should remain explicit.

Entering a clean-looking value without recording where it came from.

Ignoring currency, ownership percentage or valuation date because the total appears reasonable.

Using ordinary notes for private access information.

Assuming Understand Role Permissions produces advice, verification or execution beyond the workflow described here.

After you save

  • Return to Net Worth and confirm totals changed as expected.
  • Open Capital Review to see whether the record created, resolved or changed any review item.
  • Check whether the record should affect Forecast, Investment Plan, exports or share links.
  • Revisit this security guide when source evidence changes.

Keep reading