All Help Center guides
Administration

Roles, permissions and tenant access

Configure organisation membership, least-privilege roles, product entitlements and safe access to operational data.

8 min read Updated August 15, 2026Organisation owners and administrators

Organisation membership comes first

A user must belong to an organisation before they can use that organisation’s workspace. Product entitlements then determine which industry modules are available to the organisation.

This separation allows an organisation to add or remove a module without mixing records between tenants.

Assign the least privilege required

Use administrator access for configuration and membership management, operational roles for day-to-day records and read-only roles for review or reporting. Avoid giving every user full access simply because it is convenient during setup.

Review access when someone changes role, leaves a team or starts working with a different organisation.

Validate access with a pilot user

After changing permissions, test the experience using a user with the same role as the intended audience. Check the sidebar, record actions, reports, AI prompts and export controls.

Access checks happen on the server as well as in the interface, protecting tenant boundaries even when a URL or request is manipulated.

Need a guided start?

See how this works with your team and data.

Book a walkthrough or explore the public product portfolio before you configure your workspace.