Two ladders that must not be merged
The first ladder is organisational: owner, administrator, internal member. It decides which modules open and whether the person can change what they see. The second ladder is operational: lead, installer, helper, inspector. It decides responsibility on the job site.
Merging them creates two symmetrical mistakes. Promote a foreman to a job-site lead and accidentally hand them financial reporting. Or keep a dispatcher on a low role and force them to ask someone else to make the changes they were hired to make.
The principle: narrowest role that works
Start every person at the least access that lets them complete their work without asking a colleague to do it for them. Widen deliberately when a real task requires it. This is not distrust — it is damage control. Most data incidents in small businesses are accidents by people who never needed the access they had.
What deserves a hard boundary
- Employment records containing personal and pay details — owners and administrators only.
- Financial reporting, margin and cost data.
- Anything that can delete records or change access for other people.
- External party access, which should never be an internal role with extra filters.
Access is a lifecycle, not a setting
Access is granted at onboarding, changed at promotion or transfer, and removed at exit. The exit step is the one businesses skip, which is how a departed employee still has a working login six months later.
Tie the review to events, not to the calendar. Every role change is a prompt to ask what should now be removed, not only what should be added.