Just a moment
Staff

Who on your team should see what

Most small businesses give everyone full access because setting up permissions felt like a job for later. Later usually arrives as an unpleasant surprise.

The Youzse team11 May 20264 min read

In most small businesses everybody can see everything. It is not a decision, it is what happens when a system is set up in one evening and permissions look like a job for a quieter week.

The cost of that shows up in three ways, and by the time it does, it is too late to set them up quietly.

What actually goes wrong

Somebody sees the takings. Once a stylist knows exactly what the business turns over, and has their own view of what they contribute, the conversation about pay changes and it changes with incomplete information.

Somebody sees another client's notes. Health information, addresses and personal circumstances get read by people with no reason to read them. Under UK GDPR you should be limiting access to what each person needs, and unrestricted internal access is one of the more common findings when something goes wrong.

Somebody exports the client list. Usually on their last week. It is often not even malicious, since a departing stylist may genuinely believe their clients are theirs. The export happened because it was possible.

The rule to work from

Give each person what they need to do their job well, and nothing beyond it. Not as a statement of distrust, but because access is a risk that has to be balanced against a benefit, and access somebody never uses has no benefit at all.

Frame it that way to the team, because the version where permissions arrive with no explanation reads as an accusation and generates far more resentment than the change deserves.

A sensible starting shape

  • Front desk needs the diary, customer contact details, bookings, payments and the ability to take money. It does not need clinical notes, staff pay, business reporting or the ability to export the customer list.
  • A stylist, technician or therapist needs their own diary, the client history for the people they are treating and the notes relevant to the work. Whether they see other people's columns depends on how you actually cover for each other.
  • A manager needs everything operational, including reporting and refunds, and usually not the billing account or the ability to remove other administrators.
  • The owner needs everything, including the parts nobody else should have. Billing, plan changes, permissions, integrations and anything that can delete data permanently.
  • Anybody temporary or on trial should start at the smallest useful set and be widened, rather than starting wide and never being narrowed.

The four permissions worth being strict about

Exporting customer data. This is the one that becomes a competitor's mailing list. It should be a deliberate act by one or two people.

Deleting records. Deletion should be restricted and, ideally, recoverable. Most systems that allow anyone to delete a customer will eventually have somebody delete a customer.

Refunds and discounts. Not because you distrust the team, but because a discount is money and money should leave with a name attached to it.

Changing prices. Prices are a business decision and it is remarkably easy to change one by accident on a busy Saturday.

The part that makes it survivable

Everybody should have their own login. Shared accounts destroy the entire point, because an audit trail that says "reception" tells you nothing on the day you actually need it.

Two factor authentication on anybody with wide access is worth the twenty seconds. And when somebody leaves, access ends that day rather than at the end of the month, which is only possible if you knew who had what in the first place.

Doing it now takes half an hour. Doing it after an incident takes considerably longer and happens in front of an audience.

Topics

StaffPermissionsSecurity

We value your privacy

Cookies keep Youzse running, improve the platform and help deliver relevant content. Read our privacy policy and cookie policy.