Who can do what in your WrkLst account: how to invite team members, what a role controls, and how an administrator can see WrkLst as another user or follow what happened in the account.
Inviting a team member
- Open Settings → User Management and choose New user.
- Enter the Name and Email and pick a Role.
- Choose Save & Send Invite.

Settings → User Management: 1 Add · 2 Role · 3 Deactivate
New users are always invited: they set up their own sign-in through the invitation link, and their Status stays Invited until they do. Saving the user again sends the invitation again. You can invite a colleague with the email address they already use at another gallery or collection; they keep one user account and one password and simply gain access to yours.
Deactivating, reactivating and deleting
Deactivate stops a user from signing in; their records stay untouched, and Reactivate lets them back in at any time. Delete user removes a user permanently; it is not possible while the user has linked records. A user's email address can only be changed by that person, in their own profile. If they can no longer reach it, contact support.
Helping a user back in
Under Security & access, Reset sign-in credentials clears a user's two-factor authentication, passkeys and active sessions. They keep their password, so this is the way to help someone who has lost their authenticator and recovery codes.
Roles
Settings → User Roles lists your roles. For each area of WrkLst a role grants View and Edit & delete separately, and a Share limit sets how much a user may share. Bulk edit switches everything on or off at once. System roles have fixed permissions and cannot be edited; your own roles can. To delete a role, choose Delete role, pick the role its users move to, and confirm with Delete & reassign.

Settings → User Roles: 1 Add · 2 Mobile App
Some permissions are decided per role and are worth knowing about:
- API access and AI assistant access let a role connect other software and AI assistants. Admin roles have them; others do not until you grant them.
- Syncing the address book to a phone or computer is allowed per role.
- Payments, the bank reconciliation under Sales, is available to administrators and can be granted to other roles.
- Sales reports on exhibitions and consignments are shown to everyone who may see them.
- Sharing documents from templates needs the share permission.
- The Mobile App permission is needed for the WrkLst mobile app; see Permission Requirements.
Administrators also see, in the change history of a work or contact, what changed in each edit, with the old and the new value side by side, for changes Privacy · Terms ·in the past year.
Seeing WrkLst as another user
To check what a colleague can and cannot see, an administrator opens the menu under their name and chooses Impersonate user. A banner then says that you are impersonating that user and viewing WrkLst exactly as they see it; Return to your own name ends it.
Who did what: the Interaction Log
Under Settings → Interaction Log an administrator can follow every request made to the account: per day and per channel (Web interface, Mobile app, API, AI assistant (MCP), WordPress plugin and Address book sync), on a map of where requests came from, and as a searchable list filtered by channel, user, day and text. Entries are kept for one year.

The Interaction Log.
Working at the same time
When someone else is already editing a contact or an exhibition, WrkLst shows you that it is in use instead of letting you both change it at once, and warns you before you save if the record changed while you had it open. On a work you see at a glance when a colleague is already working on a linked sale, exhibition or consignment.