Everyone sees exactly what they should see — right down to the single field
Roles, four-eyes approvals and a complete audit log — the foundation under all twenty-one modules.
Screens from a demo workspace. Companies, people and figures are fictitious.
Team & permissions at work
Five capabilities people actually open Team & permissions for. Everything else it can do is listed in full in section 04 — this is only what stands on its own.
Permissions down to the individual row
Per module and per action — create, read, change, delete — you set the reach: everything, the department, your own reporting line, only your own records, or nothing at all. Five levels for every single operation instead of a crude “admin/user” switch. Each data module gets a branch of its own that you fold open and shut.
for every single action, instead of a blunt admin-or-user switch
Approvals and the four-eyes principle
Approval policies attach themselves to critical operations — a role change, a permission change, a quote or contract above the threshold, a bulk export. The operation pauses and only continues once the responsible role confirms. Nobody approves their own request.
nobody approves their own request — the record waits until someone confirms
Access for a limited time only
If somebody briefly needs elevated permissions, they request them with a reason and a duration. A manager approves — no self-approval — the access takes effect immediately and expires by itself when the time is up. A reminder goes out beforehand, so that no permanent right ends up hanging around out of convenience.
automatically when the period ends — a reminder goes out beforehand
Role simulator — see it before you hand it out
Pick a person, a module, an action — and the app tells you yes or no immediately, plus the reach that actually applies in the end and the reasoning behind it: which rule, which role, which added permission bundle. No guessing whether somebody sees too much or too little; on a “denied” you get a suggestion for how to put it right.
straight away, with scope and reason — and a suggestion when it is a no
Field-level security
Permissions do not stop at the record. Your recruiter sees the salary in the application, the working student next to them only name and status — the same view, two truths. Per role you decide field by field who gets to see what: in sales, recruiting, projects and marketing. In sales the same rule applies to writing as well. And the mask applies to bulk export too — what a role may not see does not even appear as a column in its CSV.
who sees what — in sales, recruiting, projects and marketing, and in the CSV too
Paths that run through here
Permissions do not hang off a module page, they hang off the record. That is why the same answer holds in every register — there is no second permission system to forget.
What Team & permissions receives and passes on
Team & permissions decides who may see and do what. What a client sees from outside is decided by the customer portal.
Everything that is in it
47 capabilities in 7 groups — complete, not curated.
What it does not do
Every limit names the place where it happens instead.
- Other people’s sessions are off-limits.
Everyone sees their own signed-in devices and can sign them out. Admins do not get their colleagues’ sessions either — that is a lock, not a missing view.
- No identity provider of our own.
Sign-in with password and second factor, plus one-time links. Anyone who needs SAML or SCIM from a corporate directory needs more than what is here.
- Two levels, not arbitrarily many.
A main workspace with sub-workspaces below it — there is no deeper nesting. A group structure four levels deep is not what this models.
What teams want to know beforehand
Can I see what an employee sees before I give them the role?
Yes. The role simulator shows the interface from their point of view — before you assign it, not after the first complaint.
Can access be time-limited?
Yes, time-boxed and with an expiry. A permission bundle can be layered on top and lapses by itself — nobody has to remember to take it away.
Do our system emails come from our domain?
Yes, once you connect it — invitations, notifications and reminders then go out from your sender address. Templates for them exist and can be edited.
Is it logged who changed what?
Yes, and the log cannot be altered afterwards — it is append-only, not editable. Not even an administrator can delete an entry.
Team & permissions is one of 21. You get all of them.
Sign up and you'll hear from us the moment we go live. Not a newsletter — one message.
€50€150/ month · permanently
Only your email address. No spam, unsubscribe at any time.

