Skip to content
worksuiteWorkSuite

335 permissions, and why that is the point

Seeing an employee, seeing their identity number and seeing their bank account are three different things. Most systems treat them as one.

Livezen Technologies

The WorkSuite Drive details panel showing access and versions

Access control in most business software is a list of roles, and each role is a list of screens. It works until somebody needs half a screen — the manager who must approve expenses but must not see salaries, the storekeeper who counts stock but must not see what it cost.

WorkSuite is built the other way round. There are 335 named permissions, and a role is whichever of them you grant. Nothing is implied.

Three things, not one

Seeing an employee record is one permission. Seeing their identity number is another. Their personal details, a third. Their bank account, a fourth. HR can be given the first two and not the last, and nothing about the screen has to be redesigned to make that true.

The same pattern runs through the suite. Cost price and margin in Inventory sit behind their own permission. Bank details in Payroll do. Another company’s figures in Accounting do. Payroll is finely divided enough that calculating a run, approving it and releasing the payments are three separate acts by design — releasing money should never be a side effect of pressing Save.

Viewing is not sending

One of the quieter ones: print, email, download, share by link, send to chat and send on WhatsApp are six separate permissions. Somebody who may read a price list does not automatically acquire the right to email it out of the building. Drive carries fifteen permissions of its own, and changing another person’s access to a file is separate from sharing it in the first place.

What it costs you

Honestly: setup time. Three hundred and thirty-five of anything takes a morning to think through. The alternative is a role that is roughly right, which is the same as saying somebody can see something they should not.