CapitelistHelp Center

Security guide

Coming soon

Users, Invites and Roles

Use user management to invite collaborators while keeping sensitive owner-only boundaries intact.

Current Capitelist screen for Users, Invites and Roles.

Before you start

Decide what should be visible in normal workspace views and what must stay protected. Sensitive access details belong in encrypted/private areas, not ordinary notes or shared exports.

You know whether private data is currently hidden or included.
Sensitive details are ready to be stored only in protected fields.
You know who should and should not see this information.

Detailed steps

01

Open Settings > Users

Start from the screen named in the step and confirm the portfolio in the top bar before you change anything. If the wrong portfolio is selected, switch portfolios first.

02

Invite the collaborator with the least privilege needed

Use this step to turn loose information into a clear portfolio record. If you are missing an input, note the gap instead of guessing.

03

Review active users and revoke access when a relationship changes

Compare the screen against your source before relying on the result. Check name, value, currency, date, ownership, liquidity and whether private data should stay hidden.

04

Keep Held Away and recovery-sensitive areas owner-only unless explicit policy says otherwise

Use this step to turn loose information into a clear portfolio record. If you are missing an input, note the gap instead of guessing.

Field guide

Visibility

Who can see the record in normal use.

Keep private operational details out of standard fields.
Recovery context

How the information can be understood later.

Document non-secret context clearly.
Protected notes

Sensitive details encrypted behind private controls.

Never store raw secrets in regular notes.
Release level

What a trusted person may receive.

Match the role and relationship deliberately.

Decision rules

What it adds

  • Supports collaboration without sharing owner credentials.
  • Creates an accountable access path.
  • Helps separate operational help from private secrets.

What it does not do

  • A role is not a substitute for legal authority.
  • Some sensitive areas remain excluded even when portfolio access exists.
  • Invites require the recipient to complete acceptance.

Common mistakes

What to check

  • Use time-limited or scoped access where possible.
  • Remove advisors, assistants or family users promptly when access is no longer needed.
  • Do not use shared login credentials.

Entering a clean-looking value without recording where it came from.

Ignoring currency, ownership percentage or valuation date because the total appears reasonable.

Using ordinary notes for private access information.

Assuming Users, Invites and Roles produces advice, verification or execution beyond the workflow described here.

After you save

  • Return to Net Worth and confirm totals changed as expected.
  • Open Capital Review to see whether the record created, resolved or changed any review item.
  • Check whether the record should affect Forecast, Investment Plan, exports or share links.
  • Revisit this security guide when source evidence changes.

Keep reading