Teamabout 15 min

    How do I control what each team member can see and do?

    Short answer

    Give people the access their job needs and nothing more: techs see their own schedule and job details, office staff handle customers and invoices, and owners see financials and settings. Review it whenever someone changes roles or leaves.

    Before you start

    • A list of everyone who needs access.
    • What each role actually does daily.
    • Which data is sensitive.
    • An offboarding checklist.

    Step by step

    1. 1

      Write the roles before the users

      Field, office, manager, owner. Define what each needs to do the job.

      Per-person permissions become unmanageable at five people.

    2. 2

      Default to least access

      Start narrow and widen when someone hits a genuine wall.

      It is far easier to grant access than to claw it back.

    3. 3

      Protect financial data

      Revenue, margins, and payment settings belong to owners and managers only.

      Most access incidents are about money, not customers.

    4. 4

      Limit field access to their work

      Techs see their own schedule, customer details, and job notes, not the whole database.

      A phone left in a truck should not expose your customer list.

    5. 5

      Offboard the same day

      Deactivate the login, reassign open tasks, and transfer number routing immediately.

      Lingering access is the most common security gap in small businesses.

    6. 6

      Review access quarterly

      Check who has what and remove anything nobody uses.

      Permissions accumulate quietly as people change roles.

    What good looks like

    • People see what they need and nothing else.
    • Financial data stays with the owners.
    • Departures do not leave open doors.
    • Access matches current roles.

    Common mistakes

    The ways this goes wrong in team, and what to do instead.

    Everyone as an admin

    One accidental change to settings affects the whole business.

    Do this instead: Create roles with least privilege and reserve admin for one or two people.

    Shared logins

    You cannot tell who did what and offboarding is impossible.

    Do this instead: Give every person their own login, even part-timers.

    Slow offboarding

    A former employee keeps access to the customer database for weeks.

    Do this instead: Deactivate access on the last day as part of a written checklist.

    Frequently asked

    5 questions about set up user permissions

    They should see the job price they are delivering, not your margins or the full price book.

    Pick the next thing to set up, or back up a step if something here assumed work you have not done yet.

    Was this guide helpful?

    Tell us what worked and what didn't. It shapes what we rewrite next.

    You didn't get into business to be in the tech business.

    Managed Tech clients hand this to us. We build it, test it, maintain it, and add to it as the business changes, so nobody on your team has to become the person who knows how the system works.

    Schedule a fit callCallCalls are answered by Troy, our AI assistant. Troy answers questions about the system and services and can schedule, reschedule, or cancel appointments. He never sells or makes offers. Any communication with TactStack is stored in our systems and referenced by Troy during certain interactions. AI can make mistakes.Full documentation