Product guideOpen GoRefer
On this page
Firm adminsPreparersClientsLimited agentsAffiliates

Roles, access, and notifications

Know what each role can see, where permissions are enforced, and how people control their notifications.

Verified September 5, 2026

Role model

GoRefer changes both navigation and record scope by role. A hidden menu item is not the security boundary: the backend applies the same role and tenant rules to the underlying request.

  • Firm admins configure the tenant and can oversee practice-wide work.
  • Preparers work with assigned clients, cases, compliance items, training, and payouts; the full Messages inbox remains admin-only.
  • Clients use a reduced portal for intake, referrals, retained data, and notifications.
  • Limited agents use only their My Account shell, File Manager, and personal notifications.
  • Affiliates use a separate workspace for GoRefer subscription referrals, earnings, and payouts.

Permission controls

Route reach comes from the built-in role policy. Use the permission editor for granular data and action capabilities inside role-reachable areas; plan gates and rollout toggles can still hide a feature.

Notifications

The tenant notification center shows events the signed-in user is allowed to receive. Preferences control delivery choices where that event and channel support them. Affiliate accounts remain inside their separate portal and cannot open these tenant notification routes.