Managing Users and Permissions
Installing the package doesn't make it visible to anyone. Access comes from one of four permission sets, assigned from TwoCanConnect Configuration → Manage Users. Every plan includes unlimited users and the sets are licenceless, so the only question is what each person should be able to do.
The four permission sets
| Permission set | Who it's for | What they can do |
|---|---|---|
| Admin User | One or two people who configure the integration | Everything, including the configuration wizard, Xero authorisation, matching and product sync |
| Standard User | Everyone who raises documents | Create and send invoices, quotes and purchase orders; resync; view sync errors. Reference data from Xero (accounts, tax types, branding themes) is read-only. No access to configuration or matching |
| Read Only | Finance or management who only need to look | View documents and their sync status. No editing, no configuration |
| Integration User | The API-only user the sync runs as — not a person | Standard access plus Modify All Data, with no pages or tabs. Set up under Running the sync as a dedicated user |
Keep Admin to as few people as possible: configuration changes what syncs and in which direction, so it affects everyone's data.
Assigning from Manage Users
Each row on the screen has three buttons:
- Manually Assign opens the permission set in Salesforce Setup. Under Manage Assignments → Add Assignment, choose a list view (All Users is usually right), tick the users and confirm.
- Mass Assign gives the set to every active user on a Salesforce licence who doesn't already have it. Fine for Standard User in a small org; think twice before using it for Admin.
- Mass Remove takes the set off everyone who holds it.
The assignment screen has an Expires On column. Useful for a contractor or a temporary admin — the access removes itself rather than relying on someone remembering.
A user also needs access to the Connected App, which is granted by profile — see Configuring the Connected App. Someone with the permission set but no Connected App access will still hit errors.
Xero
Real Estate
Equifax