🛡️
Access Control
LiveRole-based permissions — Owner · Manager · Staff
📖
Access Control — SOP
How this module works
⚠️ SOP outdated — module code changed since this was written
✅ Up to date with current module code
Lets the owner define which of the app's 42 modules each role (Owner, Manager, Staff) is intended to access, and set an optional 4-digit PIN to lock specific sensitive pages. Honest note: right now this page is a settings-and-audit-trail tool — it records what access SHOULD look like and logs every change, but toggling a module here does not yet stop anyone from opening it elsewhere in the app. Real enforcement (checking these settings before a Manager or Staff session can load a page) is a separate, not-yet-built project.
Sections
👥
Role Matrix
Owner, Manager and Staff each get their own list of all 42 modules with an On/Off switch per module, grouped by category (Dashboard, Sales, Finance, AI Tools, Team, System).
🔒
Owner PIN Lock
An optional 4-digit PIN, with automatic lockout after 5 wrong attempts. Choose which pages ask for it.
📊
Compare View
A side-by-side table of every module against Manager and Staff, so differences are easy to scan at a glance.
📜
Recent Changes
A running log of the last few permission edits, who made them, and when.
🗺️
Security Roadmap
A preview of what is planned next for this module, including real enforcement (see the Overview note above).
1
Pick a role (Owner, Manager or Staff) from the left list — Owner always has full access and cannot be changed.
2
Toggle any module On or Off for that role, or use a category's All On / All Off buttons to flip a whole group at once.
3
Every change saves instantly and appears in Recent Changes below — there is no separate Save button for the matrix.
4
Use Compare to see Manager and Staff side by side for every module in one table.
5
Optionally set a 4-digit Owner PIN and choose which pages should ask for it before opening.
6
Reset to defaults restores a role's original recommended module list at any time.
🔗
None yet
This is an honest gap, not an oversight: no other module currently reads these permission settings. A role's module list here does not change what that role can actually open anywhere else in the app today. Wiring real enforcement is tracked as a future project.
528/2000
Owner lock
3 roles
42 permissions
1
Owner member
0
Manager members
0
Staff members
42
Total accessible modules
Owner
FULL ACCESS
1 member
Manager
SALES + OPS
0 members
Staff
LIMITED
0 members
Owner PIN Lock
PIN Protection
Owner
Full access to everything — all modules, settings, financial data
FULL ACCESS
Permissions locked — owner always has full access
Manager
Sales & operations access — can manage leads, team, and view reports
SALES + OPS
22 modules accessible
Staff
Limited to own tasks, attendance, and assigned follow-ups
LIMITED
7 modules accessible
Dashboard
2 modules
Dashboard
Morning Brief
Sales
8 modules
Leads (CRM)
Follow-up
Nurture
Proposals
WA Engine
Smart Reply
Sales Report
Lost Deal Analyzer
Finance
8 modules
Invoice
Expenses
P&L Live
AI CFO
GST Tracker
Tax Calendar
Vendors
Financial Reports
AI Tools
4 modules
Social AI
Brand Vault
Calendar
Predictions
Team OS
8 modules
Team OS
Projects
Goals
Salary
Leaves
SOP Library
Day Planner
Staff Portal
System
12 modules
Health Score
Auto-Pilot
Industry Brain
Vastu Soul
Voice Command
White Label
Integrations
Audit Log
Custom Fields
Access Control
Settings
Alerts
Dashboard
2 modules
Dashboard
Morning Brief
Sales
8 modules
Leads (CRM)
Follow-up
Nurture
Proposals
WA Engine
Smart Reply
Sales Report
Lost Deal Analyzer
Finance
8 modules
Invoice
Expenses
P&L Live
AI CFO
GST Tracker
Tax Calendar
Vendors
Financial Reports
AI Tools
4 modules
Social AI
Brand Vault
Calendar
Predictions
Team OS
8 modules
Team OS
Projects
Goals
Salary
Leaves
SOP Library
Day Planner
Staff Portal
System
12 modules
Health Score
Auto-Pilot
Industry Brain
Vastu Soul
Voice Command
White Label
Integrations
Audit Log
Custom Fields
Access Control
Settings
Alerts
Dashboard
2 modules
Dashboard
Morning Brief
Sales
8 modules
Leads (CRM)
Follow-up
Nurture
Proposals
WA Engine
Smart Reply
Sales Report
Lost Deal Analyzer
Finance
8 modules
Invoice
Expenses
P&L Live
AI CFO
GST Tracker
Tax Calendar
Vendors
Financial Reports
AI Tools
4 modules
Social AI
Brand Vault
Calendar
Predictions
Team OS
8 modules
Team OS
Projects
Goals
Salary
Leaves
SOP Library
Day Planner
Staff Portal
System
12 modules
Health Score
Auto-Pilot
Industry Brain
Vastu Soul
Voice Command
White Label
Integrations
Audit Log
Custom Fields
Access Control
Settings
Alerts
| Module | Manager | Staff |
|---|---|---|
| Dashboard | ||
| Dashboard | ||
| Morning Brief | ||
| Sales | ||
| Leads (CRM) | ||
| Follow-up | ||
| Nurture | ||
| Proposals | ||
| WA Engine | ||
| Smart Reply | ||
| Sales Report | ||
| Lost Deal Analyzer | ||
| Finance | ||
| Invoice | ||
| Expenses | ||
| P&L Live | ||
| AI CFO | ||
| GST Tracker | ||
| Tax Calendar | ||
| Vendors | ||
| Financial Reports | ||
| AI Tools | ||
| Social AI | ||
| Brand Vault | ||
| Calendar | ||
| Predictions | ||
| Team OS | ||
| Team OS | ||
| Projects | ||
| Goals | ||
| Salary | ||
| Leaves | ||
| SOP Library | ||
| Day Planner | ||
| Staff Portal | ||
| System | ||
| Health Score | ||
| Auto-Pilot | ||
| Industry Brain | ||
| Vastu Soul | ||
| Voice Command | ||
| White Label | ||
| Integrations | ||
| Audit Log | ||
| Custom Fields | ||
| Access Control | ||
| Settings | ||
| Alerts | ||
Has access
Restricted
Last saved
All changes auto-save instantly
Security Roadmap
✅
Phase 1
Visual role design & permission matrix
Done
🔐
Phase 2
PIN-based owner lock for sensitive modules
In Progress
📱
Phase 3
Team member login via phone OTP
Q4 2026
🛡️
Phase 4
Full role-based route protection
Q4 2026
Recent Permission Changes
No permission changes yet.
Set Owner PIN
Set a 4-digit PIN to protect sensitive pages like Salary, Settings, and Access Control.