Docsroom

Features / Permissions

Who sees which clients, decided per person.

Not everybody on your team should see everybody’s clients. A new colleague starts with access to nothing, and you give them what they need: the whole organisation, or a named list.

Team

Each person, their role and their reach

Priya Shah

Admin · every client

Admin

Dev Chandra

Staff · 14 clients

Selected clients

Erin Boyle

Viewer · 6 clients

Read only
The model

The whole model, in one place

There is no fourth concept to learn. A person has a role, and a reach.

  • Admin runs the organisation, the team and the settings
  • Team member does the work on the clients they can reach
  • Viewer reads, and changes nothing but their own account
  • Reach is every client, a named list, or only the requests handed to them
  • A new invitation starts with nothing until you choose
  • Access can be given per client, or per project inside one
  • Changing somebody’s role and reach is one action, logged

Least privilege by default

Invite a colleague, a temp or a subcontractor and they can reach nothing until you say otherwise. That is the safe way round, and it takes one more click than the unsafe way.

A viewer really is read only

Not a member with the buttons hidden. The refusal happens on the server, so it holds however the request arrives.

Every change is on the record

Who changed whose access, and when. It is one line on the activity trail like everything else.

Evidence

Proved, not asserted

The rules are checked against the running deployment before every release: an admin, a colleague across the whole organisation, a colleague given one client, and a viewer, each doing what they should and being refused what they should not.

  • A restricted colleague sees one client and is refused the other
  • A viewer cannot create or rename anything
  • The team list stays with admins
  • Signed out, the interface answers nothing at all

Who can see Ardley Foods

Access is per client, not per request

Priya Shah

Can edit · owner

Owner

Dev Chandra

Can edit

Edit

Erin Boyle

Can read, cannot send

Read

Two-factor when you want it

An authenticator app, recovery codes, and an admin who can lift it off a colleague who is locked out. A password reset never sidesteps it.

Two-factor authentication

On your own sign-in, and required across the team

Authenticator app

Added 12 August

On

Recovery codes

8 of 10 unused

Where you are signed in

2 places · this laptop and a phone

Invite a colleague and try it.

Free for 14 days, no card.