Features / Permissions
Who sees which clients, decided per person.
Not everybody on your team should see everybody’s clients. A new colleague starts with access to nothing, and you give them what they need: the whole organisation, or a named list.
Team
Each person, their role and their reach
Priya Shah
Admin · every client
Dev Chandra
Staff · 14 clients
Erin Boyle
Viewer · 6 clients
The whole model, in one place
There is no fourth concept to learn. A person has a role, and a reach.
- Admin runs the organisation, the team and the settings
- Team member does the work on the clients they can reach
- Viewer reads, and changes nothing but their own account
- Reach is every client, a named list, or only the requests handed to them
- A new invitation starts with nothing until you choose
- Access can be given per client, or per project inside one
- Changing somebody’s role and reach is one action, logged
Least privilege by default
Invite a colleague, a temp or a subcontractor and they can reach nothing until you say otherwise. That is the safe way round, and it takes one more click than the unsafe way.
A viewer really is read only
Not a member with the buttons hidden. The refusal happens on the server, so it holds however the request arrives.
Every change is on the record
Who changed whose access, and when. It is one line on the activity trail like everything else.
Proved, not asserted
The rules are checked against the running deployment before every release: an admin, a colleague across the whole organisation, a colleague given one client, and a viewer, each doing what they should and being refused what they should not.
- A restricted colleague sees one client and is refused the other
- A viewer cannot create or rename anything
- The team list stays with admins
- Signed out, the interface answers nothing at all
Who can see Ardley Foods
Access is per client, not per request
Priya Shah
Can edit · owner
Dev Chandra
Can edit
Erin Boyle
Can read, cannot send
Two-factor when you want it
An authenticator app, recovery codes, and an admin who can lift it off a colleague who is locked out. A password reset never sidesteps it.
Two-factor authentication
On your own sign-in, and required across the team
Authenticator app
Added 12 August
Recovery codes
8 of 10 unused
Where you are signed in
2 places · this laptop and a phone
Invite a colleague and try it.
Free for 14 days, no card.