Before you start
- You’ll find roles under Team members → Roles, between People and Groups
- To see roles, you need the View users permission. To create, edit, delete or assign roles, you need Manage users
- Only administrators can hold a role. Cardholders can’t
Note:Don’t see Roles under Team members? Either roles aren’t turned on for your business yet or you don’t have the View users permission. To turn on roles, contact Administrator Support or your Customer Success representative.
The predefined roles
Every business starts with six roles. Primary Admin is locked, so nobody can rename it, change its permissions or delete it. You can rename, edit or delete the other five, so the names in your account may be different.
*On Credit Expense accounts this permission is called Pay statement early through ACH.
A few things to know about these roles:
- Primary Admin and Administrator have the same permissions. The only difference is that Primary Admin is locked
- Manager works across your whole business. A role’s permissions apply to your entire account, so Manager isn’t limited to a team, group or department
- Read only starts with no permissions. Assigning it to an existing administrator doesn’t change what they can do, so add the permissions you want before you assign it
Note:You only see the permissions your business can use. For example, Fund cards and Approve funding requests apply to Prepaid accounts, and the Vendors permissions appear if you use PEX Bill Pay. Permissions you can’t see stay unchanged in the role.
How roles and individual permissions work together
- One role at a time. Each administrator can hold one role
- A role replaces individual permissions. While an administrator holds a role with at least one permission, they have exactly that role’s permissions. You can’t give someone a role plus one extra permission. Pick a role that fits, create a new one or choose Custom
- Custom means no role. An administrator on Custom has the permissions you pick for them one by one, the way permissions worked before roles
- Individual permissions are kept. While an administrator holds a role, their own permissions stay saved. Switch them back to Custom and those permissions apply again
- Invited administrators start from the role. When someone accepts an invite with a role, the role’s permissions at that moment are also saved as their own permissions. That’s what they have if you later switch them to Custom
- Editing a role changes access for everyone who holds it
When roles are turned on for your business
- We add the six predefined roles to your account
- Administrators who already have every permission available in your business get Primary Admin automatically. Inactive administrators aren’t included
- Nobody gets any other role automatically
- Everyone else shows as Custom and keeps exactly the permissions they had
View roles
1
Log in to the Dashboard at dashboard.pexcard.com.
2
Go to Team members in the left menu and select the Roles tab.
3
Each column is a role and each row is a permission. A green check means the role includes that permission, and a red ✕ means it doesn’t. Hover over the info icon next to a permission to see what it covers.
Create or edit a role
You need the Manage users permission.1
On the Roles tab, click Edit roles.
2
To add a role, click Add role. A new column named New role appears with every permission turned off.
3
To rename a role, type a new name in its name field. Names can be up to 30 characters and must be unique. Capital letters don’t count, so “Finance” and “finance” are the same name.
4
Turn permissions on or off for each role. Turning on Manage users also turns on View users, and turning off View users also turns off Manage users.
5
Click Save roles. You’ll see a Roles updated confirmation.
Note:Keep at least one permission turned on in any role people hold — a role with no permissions doesn’t limit what its holders can do.Your account can have up to 10 roles, including the predefined ones. Primary Admin can’t be renamed or edited, so its column stays read-only. If a change can’t be saved, your edits stay on screen so you can fix them and try again. If you edit a role you hold, the change applies to you right away.
Delete a role
You can delete a role only when nobody holds it.1
On the Roles tab, click Edit roles.
2
Click Delete role.
3
Choose the role from the Role to delete list. Each role shows how many users hold it. Primary Admin and roles that are still assigned are grayed out.
4
Click Delete.
Assign a role to an administrator
You need the Manage users permission.1
Go to Team members → People and click the administrator’s name.
2
Click Edit profile.
3
Under Role & Permissions, choose a role from the Role dropdown. Its permissions appear below, read-only. To pick permissions one by one instead, choose Custom.
4
Click Update. Enter your security code if you’re asked for one.
Where you’ll see roles
- People list: the Role column on Team members → People shows each administrator’s role, or Custom if they don’t hold one. Cardholders show as Cardholder, with a card icon next to their name. The Role filter offers only Cardholder and Administrator
- Administrator profiles: the role appears next to the administrator’s name and in the Permissions row
- Invitations: invite details show the invited role, or Custom
- Your own profile: on My Profile, your role appears next to your name, and the Permissions tab is now called Role & Permissions
Frequently asked questions
Can I give someone a role plus one extra permission?
Can I give someone a role plus one extra permission?
No. A role replaces individual permissions. Pick a role that has everything they need, create a new role or choose Custom and set their permissions one by one.
Can an administrator hold more than one role?
Can an administrator hold more than one role?
No. Each administrator holds one role at a time.
Can I change my own role?
Can I change my own role?
Yes, if you have Manage users. If you pick a role without Manage users, you won’t be able to change your role or permissions again yourself.
Do roles affect who can approve requests?
Do roles affect who can approve requests?
Yes. Who can approve requests follows each administrator’s permissions, including the ones from their role. Before you assign a role to someone who approves requests, check that it includes the approval permissions they need.
How do roles work with linked accounts?
How do roles work with linked accounts?
A role belongs to one business. If you invite an administrator with a role and also give them access to other accounts under Additional accounts, they get the role’s permissions in those accounts as individual permissions and show as Custom there.
Can Cardholders have a role?
Can Cardholders have a role?
No. Only administrators can hold a role. Your Cardholders keep exactly the access they have today.
Do roles change my groups?
Do roles change my groups?
No. Roles are assigned to individual administrators, and your groups stay as they are.
Do roles work in the PEX mobile app?
Do roles work in the PEX mobile app?
You manage roles in the Dashboard. The PEX mobile app has no role settings, but it uses the same permissions, including the ones that come from a role.
Does this affect the PEX API?
Does this affect the PEX API?
If your team uses the PEX API, contact adminsupport@pexcard.com with questions about roles.
Questions? Contact us at adminsupport@pexcard.com
Related topics
- How to manage permissions — what each permission covers, including the names that changed in August 2026
- How to create and send a new administrator invite
- Groups are now unified in PEX