Knowledge · Business Operations

    Roles, Permissions and Module Access

    An application role decides what someone can open. A crew role decides what they do on site. Learn how to separate the two and grant the narrowest access that works.

    What is the difference between an application role and a job role?

    An application role controls what a person can open in the system — which modules, and whether they can read or change what they see. A job role describes what they do on site, such as lead installer or helper. They are unrelated: a foreman may need less system access than a coordinator.

    Key takeaways

    • Application access and job-site responsibility are two independent decisions.
    • Grant the narrowest role that lets someone finish their work unassisted.
    • Sensitive employment data should be reachable by owners and administrators only.
    • External parties get scoped, revocable access — never an internal role.
    • Review access on role change and on exit, not once a year.

    Two ladders that must not be merged

    The first ladder is organisational: owner, administrator, internal member. It decides which modules open and whether the person can change what they see. The second ladder is operational: lead, installer, helper, inspector. It decides responsibility on the job site.

    Merging them creates two symmetrical mistakes. Promote a foreman to a job-site lead and accidentally hand them financial reporting. Or keep a dispatcher on a low role and force them to ask someone else to make the changes they were hired to make.

    The principle: narrowest role that works

    Start every person at the least access that lets them complete their work without asking a colleague to do it for them. Widen deliberately when a real task requires it. This is not distrust — it is damage control. Most data incidents in small businesses are accidents by people who never needed the access they had.

    What deserves a hard boundary

    • Employment records containing personal and pay details — owners and administrators only.
    • Financial reporting, margin and cost data.
    • Anything that can delete records or change access for other people.
    • External party access, which should never be an internal role with extra filters.

    Access is a lifecycle, not a setting

    Access is granted at onboarding, changed at promotion or transfer, and removed at exit. The exit step is the one businesses skip, which is how a departed employee still has a working login six months later.

    Tie the review to events, not to the calendar. Every role change is a prompt to ask what should now be removed, not only what should be added.

    Where URBLD fits

    URBLD gates modules by organisation role, and the sensitive employee record is restricted to owner and administrator roles while a non-sensitive directory serves scheduling and assignment. Subcontractor access is a separate scoped surface rather than an internal role.

    Principles reinforced

    This page rests on the following foundational ideas.

    FAQ

    Frequently Asked Questions

    Straight answers about how URBLD runs the business end-to-end.

    More in Business Operations

    The daily mechanics: workflows, checklists, scheduling and handoffs.

    Browse Business Operations
    Share this page