Role and Module Access Planning Matrix
All editions. Planning aid for Administrators.
Part 16 · Appendices2 min read
Availability: All editions. Planning aid for Administrators.
Overview
Plan access by role before you invite anyone. Mapping roles to departments once turns every future hire into a single role assignment, instead of a fresh access decision. This appendix gives you a template and a worked example.
This functionality is available only to Administrators.
How to Use This Matrix
- List the job roles in your organisation, not the individuals.
- For each role, decide which modules it needs at all.
- For each of those modules, choose the narrowest permission scope that still lets the person do their job -
owned,added,bothorall. - Decide who approves what: leave, timesheets, expenses, purchase orders, requisitions, budgets, tasks.
- Record the decision in a table like the one below, and keep it with your account documentation. Reviewers will ask for it.
Planning Template
| Job role | CrmLeaf role | Modules needed | Scope | Approves |
|---|---|---|---|---|
| admin / employee / client | none / owned / added / both / all | |||
Worked Example
| Job role | CrmLeaf role | Modules needed | Typical scope | Approves |
|---|---|---|---|---|
| Managing director | admin | Reports and dashboards; read access across modules | all | Budgets above threshold |
| Sales manager | employee | Leads, deals, estimates, proposals, reports | all on leads and deals | Discounts, quotes |
| Sales representative | employee | Leads, deals, tasks, meetings | owned | Nothing |
| Project manager | employee | Projects, tasks, timesheets, expenses, budgets, requisitions | all within their projects | Timesheets, expenses, requisitions |
| Team member | employee | Tasks, timesheets, leave, attendance | owned | Nothing |
| HR manager | admin | Employees, attendance, leave, payroll, recruitment | all | Leave, shift changes, offers |
| Finance manager | admin | Invoices, payments, expenses, bills, vendor payments, finance reports | all | Vendor payments, credit notes |
| Procurement officer | employee | Vendors, purchase orders, bills, inventory | all on procurement | Purchase orders below threshold |
| Support agent | employee | Tickets, knowledge base, clients | owned or both on tickets | Nothing |
| Dispatch manager | employee | Orders, dispatches, inventory | Assigned dispatches | Delivery confirmation |
| Customer | client | Client portal only | Their own records | Estimates, proposals, contracts |
Treat the scopes above as a starting point, not a recommendation for your business. Confirm each one against your own reporting needs.
Important Notes
- Start narrow and widen on request. Widening access is a small change; discovering that everyone could see payroll is not.
- Review access whenever someone changes role, and remove access promptly when someone leaves.
- Activating a paid module adds its permissions to your roles. Review them at that moment rather than assuming a safe default.
- Financial and payroll data deserves the tightest scopes in the account.
- Client users are real accounts. Confirm what the client portal exposes before inviting a customer.
Related Articles
Still need a hand?
Our support team answers on business days. Reference APX-02 so we can jump straight in.