Security layers
Roles
Use the role that reflects the person’s actual responsibilities. Directors and authorised Practice Managers can hold broader administration rights; managers, staff and contractors should receive the minimum access needed for their work.
Client-level access
Client allocation is a separate control from module access. A staff member who can use Accounting Workspace should still see only the clients they are authorised to work on where client restrictions apply.
Read-only access
Read-only is for visibility without edit authority. It should prevent changes consistently across Practice Management, Accounting Workspace and Final Accounts rather than operating differently by module.
Accounting and finalisation locks
Locks protect controlled states such as finalised accounts or closed workflow stages. Do not work around a lock. Reopen or correct through the authorised process so the audit trail explains the change.
Periodic access review
Review users, roles, client allocations and dormant accounts periodically and whenever staff responsibilities change. Disable leavers promptly and do not recycle their accounts for replacements.