Ръководство

Roles and Permissions for Small Businesses: Who Should See What as You Grow

In a team of five, everyone can see everything and nobody minds. The founder approves the expenses, the same three people touch every customer record and there is nothing worth hiding from a colleague who sits two metres away.

Then the team grows. A contractor joins for three months. Someone is hired to do the payroll. A new manager needs to approve leave for their team but has no business reading salary details for everyone else. Access that was handed out freely in year one becomes a risk in year three, and untangling it later is far harder than setting it up properly now.

This guide explains how roles and permissions work, a simple structure that suits most small businesses, and the habits that keep access tidy as people join, move and leave.

Why access control matters earlier than you think

Most small businesses put off thinking about permissions because nothing has gone wrong yet. There are three reasons to do it before something does.

  • You hold personal data. Employee records, candidate CVs and customer details are covered by UK GDPR, which expects you to limit access to the people who need it for their job. "Everyone is an admin" is a hard position to defend.
  • Mistakes are more common than malice. The usual incident is not a rogue employee. It is someone deleting a record they did not know mattered, or editing a setting they should never have been shown.
  • Clutter slows people down. A new starter who can see every feature and every record spends their first weeks working out what to ignore.

Roles first. People second.

The most common mistake is granting access person by person. Sam needs to see invoices, so Sam gets invoices. Priya covers for Sam in August, so Priya gets invoices too. Two years later nobody can say why anyone has the access they have.

A role fixes this. A role is a named set of permissions that describes a job, not a person. You decide once what a manager can do, then give that role to every manager. When the job changes, you change the role and everyone who holds it changes with it. When someone moves from one job to another, you change their role and their old access goes away in the same step.

Give people the least access that lets them do the job

Security people call this the principle of least privilege. In plain terms: start from nothing and add what the job needs, instead of starting from everything and removing what looks dangerous.

It sounds restrictive, but in practice it is kinder to the team. Someone with a focused view of the system makes fewer mistakes and finds what they need faster. And it is always easier to grant one more permission when somebody asks than to take one away after it has been misused.

Four roles that cover most small teams

You do not need a role for every job title. Most businesses under fifty people can start with four and add more only when a real need appears.

  • Administrator. Full access to everything, including settings, billing and other people's access. Keep this to two or three trusted people. One is a risk if they are on holiday. Ten is a risk every day.
  • Manager. Can see and act on their area of the business, including approving requests such as leave, expenses or timesheets. Cannot change company settings.
  • Standard. The everyday role for most staff. Can create and edit their own work and see what they need to collaborate. Cannot delete shared records or approve anything.
  • Read-only. Can look but not change. Useful for an accountant, an auditor, a board member or anyone who needs visibility without responsibility.

Add a specialist role when a job needs something none of the four provide. A payroll role that can see pay details, a recruiter role that can manage candidates or a finance role that can raise invoices are typical first additions. If you have more roles than a quarter of your headcount, you are probably recreating person by person access under another name.

Separate seeing from doing

Good permission systems do not treat access as a single on or off switch. For each area of the business, there are several separate questions:

  • Can this role view the records at all?
  • Can it create new ones?
  • Can it edit existing ones?
  • Can it delete them?
  • Can it take the actions that carry real weight, such as approving a request or converting a lead to a customer?

Thinking in these terms makes decisions easier. Almost everyone who can view expenses should be able to create one. Very few should be able to approve them. Deleting is the permission to be most careful with, because it is the one that is hardest to undo.

Handle the exceptions with sharing

Roles describe what a job can do in general. They are a poor fit for one-off needs, such as a single confidential project or a folder of board papers. If you create a new role every time one record needs special treatment, the role list becomes unmanageable.

The better answer is to share the individual record. Give the project, folder or document to the specific people or the department that needs it, and choose whether they can view it, edit it or manage it. The role stays simple and the exception stays attached to the thing it applies to.

Joiners movers and leavers

Access goes wrong at the moments when people change, so build it into the routine for each one.

  • Joiners. Decide the role before the first day and assign it when the account is created. Do not copy the access of "someone similar", because you copy their accumulated exceptions too. Our employee onboarding checklist covers the rest of the first week.
  • Movers. When someone changes job, change their role on the same day. People who keep their old access and gain new access end up with more than anyone intended.
  • Leavers. Deactivate the account on the last working day, not at the end of the month. Reassign the records they owned, such as open leads, tickets and projects, so nothing is left with nobody watching it.

Review access on a schedule

Permissions drift. A temporary grant becomes permanent because nobody remembers to remove it. Put a short review in the calendar every six months, and after any reorganisation. It takes less than an hour for a small business.

  • List everyone with the Administrator role. Does each of them still need it?
  • Check that every active account belongs to a current member of staff or a current contractor.
  • Look at each role and ask whether it still matches the job it describes.
  • Go through anything shared with a named individual and remove shares that are no longer needed.

Keep a note of the date and what you changed. If you are working towards a scheme such as Cyber Essentials, or a customer sends you a security questionnaire, that record is the evidence you will be asked for.

Mistakes to avoid

  • Making someone an administrator to fix one problem. Find the single permission they are missing and grant that.
  • Sharing a login. Two people on one account means you cannot tell who did what, and you cannot remove one of them without locking out the other.
  • Roles named after people. "Sam's access" stops making sense the day Sam leaves.
  • Forgetting contractors and agencies. External people need the tightest roles and the most prompt removal.
  • Setting it up once and never looking again. The structure that suited eight people will not suit thirty.

How this works in Wizard Application

Roles and permissions are included on every plan, so you can set access up properly from the first day.

  • Four starter roles. Every workspace begins with Administrator, Manager, Standard and Read-only. The Administrator role always has full access and cannot be edited.
  • Your own roles. Create custom roles for jobs the starter roles do not fit and adjust them as the business changes.
  • Permissions for each feature. For every feature you choose whether a role can view, create, edit or delete, along with the actions specific to that feature, such as approving a request or converting a lead.
  • One role for each user. Every user holds exactly one role, which keeps the answer to "what can this person do" in one place.
  • A tidy sidebar. Features a role cannot view are hidden from the menu, so people only see the parts of the platform they use.
  • Sharing for the exceptions. Share an individual project, document, folder, form, dashboard or court bundle with a user or a whole department, and choose view, edit or admin access for each.

Because the same roles apply across HR, sales, projects and documents, you define access once instead of once for each tool.

Frequently asked questions

What is the difference between a role and a permission?

A permission is a single thing someone is allowed to do, such as view invoices or approve leave. A role is a named collection of permissions that matches a job. You assign roles to people, not individual permissions.

How many administrators should a small business have?

Two or three. You need more than one so the business is not stuck when someone is away, but every extra administrator is another account that can change or delete anything.

How often should we review who has access to what?

Every six months is a sensible rhythm for a small business, plus a check whenever someone leaves or the team is reorganised.

Can a user have more than one role in Wizard Application?

No. Each user has one role. If someone does two jobs, create a role that combines what both need, or keep their role simple and share the specific records they need with them.

Are roles and permissions included on the free Starter plan?

Yes. Roles and permissions are included on every plan.

Access control is one part of running a tidy business. If your sales process is next on the list, read our guide to sales pipeline stages. To see how we look after your data, visit our security page.

Обратно към блога

Готови ли сте да започнете?

Открийте как Wizard Application може да оптимизира вашия бизнес. Започнете безплатно днес.