Users, teams and roles
Last updated: August 27, 2026
Three screens under User Management decide who gets into Govflo, how work reaches them, and what they can do once they are in. They are set up together, because each depends on the other two.
How to add a user
Go to Settings, then User Management, then Users.
Click New user.
Enter their details, choose a Role, and assign a Team.
Send the invite. They show as Invited until they first sign in.
Use Bulk invite to bring several people in at once.
Choosing the role
Give people Member unless they need more. It covers the daily job: the queue, documents, requesters and approvals.
Administrator adds Settings, where changes take effect immediately across the whole agency. Grant it conservatively.
Approver is for people who decide but do not do casework, such as counsel or a supervisor. An approver often holds no casework permissions at all, which is the point of the role.
Teams, and why the default assignee matters
Go to Settings, then User Management, then Teams. Create a team, add members, and set the default assignee.
That last field is the one that matters. When a request is routed to a team, the team's default assignee is applied, so the request gets an owner at the moment of handover. Without it, routing to a team produces an unassigned request, and unassigned requests are the largest single source of overdue work because nothing surfaces them into anyone's queue.
Each team also carries a Notify on assign setting. Leave it on: it tells the team when work arrives, which is the difference between a queue people watch and one they discover late.
Name teams after the work rather than the people. "Legal Review" survives a departure; "Sarah's team" quietly becomes wrong the day she moves.
Roles and what they reach
Go to Settings, then User Management, then Roles. Each role has a View and an Edit switch per area: Dashboard, Requests, Approvals, Documents, Requesters, Admin Settings and Analytics. Edit requires View, and changes save automatically.
Changes apply to everyone holding that role, immediately.
Add role creates a custom one. Create a custom role when a group of people needs a different combination, not when one person does. A role per person becomes impossible to reason about inside a year.
The safeguard
At least one role must always keep the ability to manage settings. Govflo refuses any change that would leave nobody able to administer the agency.
If the product blocks a change you are making, this is usually why. Grant the permission elsewhere first, then remove it here.
Some areas are gated twice
A role permission is necessary but not always sufficient. Certain areas are also gated by a tenant setting with no self-service screen. Analytics is the clearest example: switching its permission on does not make it appear if the tenant gate is closed.
If you have granted a permission and the area still does not show, more permission changes will not help. Raise it with your Govflo contact.
Removing someone
Deactivate rather than delete, so their name stays attached to what they did and the audit trail stays readable. Deactivated users appear under the Deactivated tab.
Reassign their open requests first. A request owned by a deactivated user is still assigned to them and will not appear in anyone else's queue. Check their pending approvals too, because an approval waiting on someone who has left blocks a release and will not resolve itself.