Administration

Company-Controlled Roles and Per-User Permissions

Understand the difference between company ownership, role permissions, and per-user access overrides in a multi-user business workspace.

Reviewed

Direct answer

Workspace follows a company-controlled access model: a person joins as a company member, the company assigns a role, and access can be narrowed or expanded for that individual without assuming that every administrator has identical authority.

Company ownership comes first

The company account represents the organization. Invited administrators, partners, directors, and employees remain people working within that organization rather than becoming separate company owners automatically.

This model keeps the company responsible for deciding who can view, create, approve, or manage each operational area.

Roles provide a reusable baseline

A role groups common access for a type of responsibility. For example, two managers may share a role that permits task assignment and team reporting.

  • Roles reduce repetitive configuration for similar team members.
  • A role name alone should never be treated as unlimited authority.
  • Sensitive actions still require server-side authorization, not only hidden navigation links.

Per-user overrides handle real organizations

Two people with the same role can still require different access. Per-user overrides allow the company to grant or remove a specific capability for one person while keeping the shared role unchanged.

This separation is especially useful when an administrator is also a working employee whose own leave, overtime, or expenses may still require company review.

Key facts

  • The company controls role assignment and access decisions.
  • Role permissions and per-user overrides are separate layers.
  • An administrator can have elevated operational access without becoming the final authority for every company action.