Please read this first: your team members can do less than they could yesterday
Until today, anyone you invited as a member could do anything an owner could, apart from approving a quote. They could send a quote to a customer, issue an invoice, mark one paid, void or write one off, send a purchase order, and delete a client, project or vendor.
From this release, those actions need an owner or an admin.
If someone with the member role runs your invoicing or sends your quotes, change their role to admin before you update — otherwise their next attempt will simply be refused. You can do that in Settings → Team. It takes a few seconds and nothing else about their account changes.
Members keep everything involved in preparing work:
- building draft quotes, invoices and purchase orders, including all the line items
- creating clients, projects, vendors, SKUs and tasks
- logging and editing their own time
- notes, contacts and addresses
- moving an invoice between draft and pending review
The dividing line is deliberate: a member can prepare anything, and the moment something becomes irreversible or a customer sees it, it needs someone accountable for it. That distinction did not exist before — it does now, and it applies the same way whether the action happens in the app or through Claude.
We know this is a change to how some teams work. It is the right default for actions that cannot be undone, and promoting someone to admin is a deliberate, easy answer where it is not.
Claude can now do the work, not just look at it
Connecting Current.business to Claude used to give it read access. It can now create and change things — more than seventy of them, covering clients, projects, tasks, time, quotes, invoices, purchase orders, vendors, SKUs, notes and your organisation's settings.
You can ask for the work rather than doing it:
"Log three hours against the Contoso firewall project for this morning." "Build a quote for Contoso from the SKUs we used on their last one." "Which invoices are overdue, and how much is outstanding?"
Anything a customer or vendor would see, or that moves money, asks you first. Sending a quote, issuing an invoice, marking one paid, voiding one, deleting a client — each of those shows you exactly what will happen, naming the document, the amount and who receives it, and waits for you to confirm. Confirmations expire after five minutes and cannot be reused, so an old one cannot be replayed later.
Claude also respects the roles above. Connected as a member, it is not even offered the actions a member may not perform — they do not appear in its list, so it cannot try and fail.
Two things it deliberately cannot do at all: change anyone's role or permissions, and record or delete a payment. Those stay in your hands.
Your data is only ever visible to the organisation you connect. Cost prices and margins remain hidden from members, exactly as they are in the app.
Sending a quote by email works again
If you have tried to email a quote with an approval link since late July and it failed, that is fixed.
A component the approval link depends on was missing from every workspace database after our July platform migration. Any attempt to send a quote with a customer approval link failed at the moment it tried to create the link. Invoices and purchase orders were unaffected and sent normally throughout.
The fix applies automatically when this release goes out. Nothing on your side to do.
We are sorry — this was live for several weeks. It was invisible from inside the app because it only failed at the final step, and because the part of the system that generates the rest of your record identifiers kept working perfectly.
Read-only accounts are now genuinely read-only
The viewer role is meant to be able to look at everything and change nothing. We found fourteen places where a viewer could still make a change — including deleting the records created by a data import, changing the prices on a quote, and emailing a quote to a customer.
Thirteen are now closed. The fourteenth we left alone deliberately: it records that someone searched your product catalogue, and a viewer searching the catalogue is exactly what that role is for. Blocking it would not have stopped the search, only the record of it — and it would have quietly skewed the "popular searches" figures by leaving out everything your read-only people look for.
No customer data was affected, and all of this required an existing account inside your organisation. But if you have ever invited an accountant, a client contact or a contractor as a viewer because that role cannot change anything, it now behaves the way you expected.
Also fixed
- A team member could edit or delete a colleague's time entries by following a stale link, even though the entries were not visible to them. Time entries can now only be changed by the person who logged them, or by an owner or admin.
- Notes on a task were silently lost. The notes tab on a task accepted what you typed and failed to save it. Notes on tasks now work.
- Tasks belonging to a client's projects were missing from anything that listed that client's tasks — the list came back empty rather than showing them.
- Deleting a draft invoice now returns its source quote to the state it was in beforehand, rather than leaving the quote stuck.
- A missing record now says so. Several places reported "not found" when the real answer was "you do not have permission", and three places reported success after sending a document while failing to record that it had been sent.