How do I control what each team member can see and do?
Short answer
Give people the access their job needs and nothing more: techs see their own schedule and job details, office staff handle customers and invoices, and owners see financials and settings. Review it whenever someone changes roles or leaves.
Before you start
- A list of everyone who needs access.
- What each role actually does daily.
- Which data is sensitive.
- An offboarding checklist.
Step by step
- 1
Write the roles before the users
Field, office, manager, owner. Define what each needs to do the job.
Per-person permissions become unmanageable at five people.
- 2
Default to least access
Start narrow and widen when someone hits a genuine wall.
It is far easier to grant access than to claw it back.
- 3
Protect financial data
Revenue, margins, and payment settings belong to owners and managers only.
Most access incidents are about money, not customers.
- 4
Limit field access to their work
Techs see their own schedule, customer details, and job notes, not the whole database.
A phone left in a truck should not expose your customer list.
- 5
Offboard the same day
Deactivate the login, reassign open tasks, and transfer number routing immediately.
Lingering access is the most common security gap in small businesses.
- 6
Review access quarterly
Check who has what and remove anything nobody uses.
Permissions accumulate quietly as people change roles.
What good looks like
- People see what they need and nothing else.
- Financial data stays with the owners.
- Departures do not leave open doors.
- Access matches current roles.
Common mistakes
The ways this goes wrong in team, and what to do instead.
Everyone as an admin›
One accidental change to settings affects the whole business.
Do this instead: Create roles with least privilege and reserve admin for one or two people.
Shared logins›
You cannot tell who did what and offboarding is impossible.
Do this instead: Give every person their own login, even part-timers.
Slow offboarding›
A former employee keeps access to the customer database for weeks.
Do this instead: Deactivate access on the last day as part of a written checklist.
Frequently asked
5 questions about set up user permissionsRelated guides
Pick the next thing to set up, or back up a step if something here assumed work you have not done yet.
Do this next
The natural follow-on tasks once this one is working.
People usually get here from
Guides that lead into this one, in case you skipped a step.
More in Team
Nearby tasks that share the same setup and vocabulary.
Was this guide helpful?
Tell us what worked and what didn't. It shapes what we rewrite next.
You didn't get into business to be in the tech business.
Managed Tech clients hand this to us. We build it, test it, maintain it, and add to it as the business changes, so nobody on your team has to become the person who knows how the system works.

