APX-02Core CrmLeafAdministrator

Role and Module Access Planning Matrix

All editions. Planning aid for Administrators.

Availability: All editions. Planning aid for Administrators.

Overview

Plan access by role before you invite anyone. Mapping roles to departments once turns every future hire into a single role assignment, instead of a fresh access decision. This appendix gives you a template and a worked example.

This functionality is available only to Administrators.

How to Use This Matrix

  1. List the job roles in your organisation, not the individuals.
  2. For each role, decide which modules it needs at all.
  3. For each of those modules, choose the narrowest permission scope that still lets the person do their job - owned, added, both or all.
  4. Decide who approves what: leave, timesheets, expenses, purchase orders, requisitions, budgets, tasks.
  5. Record the decision in a table like the one below, and keep it with your account documentation. Reviewers will ask for it.

Planning Template

Job roleCrmLeaf roleModules neededScopeApproves
 admin / employee / client none / owned / added / both / all 
     
     

Worked Example

Job roleCrmLeaf roleModules neededTypical scopeApproves
Managing directoradminReports and dashboards; read access across modulesallBudgets above threshold
Sales manageremployeeLeads, deals, estimates, proposals, reportsall on leads and dealsDiscounts, quotes
Sales representativeemployeeLeads, deals, tasks, meetingsownedNothing
Project manageremployeeProjects, tasks, timesheets, expenses, budgets, requisitionsall within their projectsTimesheets, expenses, requisitions
Team memberemployeeTasks, timesheets, leave, attendanceownedNothing
HR manageradminEmployees, attendance, leave, payroll, recruitmentallLeave, shift changes, offers
Finance manageradminInvoices, payments, expenses, bills, vendor payments, finance reportsallVendor payments, credit notes
Procurement officeremployeeVendors, purchase orders, bills, inventoryall on procurementPurchase orders below threshold
Support agentemployeeTickets, knowledge base, clientsowned or both on ticketsNothing
Dispatch manageremployeeOrders, dispatches, inventoryAssigned dispatchesDelivery confirmation
CustomerclientClient portal onlyTheir own recordsEstimates, proposals, contracts

Treat the scopes above as a starting point, not a recommendation for your business. Confirm each one against your own reporting needs.

Important Notes

  • Start narrow and widen on request. Widening access is a small change; discovering that everyone could see payroll is not.
  • Review access whenever someone changes role, and remove access promptly when someone leaves.
  • Activating a paid module adds its permissions to your roles. Review them at that moment rather than assuming a safe default.
  • Financial and payroll data deserves the tightest scopes in the account.
  • Client users are real accounts. Confirm what the client portal exposes before inviting a customer.
Still need a hand?

Our support team answers on business days. Reference APX-02 so we can jump straight in.