eProcureAI / Platform / Access and Permissions

Access and Permissions

Adding somebody should be
one decision, not fifteen

Permissions belong to departments rather than to people. Choose the department and the right access follows, for everyone who is there now and everyone who joins later.

This is the real screen. Org map, permission matrix and department baselines.

Access HubOrg map
How it feels to use

Permissions go wrong when they belong to people

Every access problem starts the same way. Somebody joins, an administrator copies the settings from whoever seems similar, and nobody checks it again for three years.

Do that a hundred times and you have a permission structure no one can explain, where the fastest way to work out what somebody can do is to ask them to try it.

In eProcureAI permissions attach to departments. Finance has a baseline of fifteen permissions. Everybody in Finance inherits those fifteen, including the person who joins next month. Adding somebody is a single decision about which department they are in.

The org map and the matrix

Two views of the same thing. The org map shows departments and what each one can do. The matrix shows permissions against departments, with each cell telling you whether all members have it, some members have it through an override, or nobody does.

Tapping a cell edits the baseline, which means changing what a whole department can do is one action rather than a morning of individual edits.

Overrides, visibly

Sometimes one person genuinely does need something extra. That is an override, and it shows as an override rather than blending into the baseline. When an access review comes round, the exceptions are the short list rather than the whole population.

How access is granted

From department down to a person

Step 1

Departments are defined

Eight of them in a typical setup, matching how the business is actually organised rather than an idealised structure.

Departments8
1
Step 2

Each gets a baseline

The set of permissions everybody in that department needs. Finance carries fifteen, which is more than most because of the approval and budget work.

Finance baseline15 permissions
2
Step 3

People inherit it

Adding somebody to a department gives them the baseline immediately. There is no copying from another user and hoping it was right.

Manual setupNone
3
Step 4

Exceptions are overrides

Anything beyond the baseline sits on top of it and is visibly an override, which keeps the review list short.

OverridesAlways visible
4
Step 5

Moves are clean

Changing somebody's department removes the old baseline and applies the new one, so nobody carries access from a job they left.

Orphaned accessNone
5
Baselines and overrides

Two concepts, and that is deliberate

The baseline does the work

Almost everybody should be covered by their department baseline. If most of your population needs overrides, the baseline is wrong rather than the people being unusual.

  • One baseline per department
  • Applies to current and future members
  • Edited by tapping a cell in the matrix
  • Changes apply to everyone at once
Finance baselineLive
DepartmentFinance
Baseline permissions15
MembersAll inherit
EditTap the cell
Applies toFuture joiners too
One decisionCovers everybody

Overrides stay visible

An override is a deliberate exception for one person. Because it is marked as an override rather than folded into the baseline, an access review looks at a handful of cases rather than the whole company.

  • Marked distinctly in the matrix
  • Attached to a person, not a department
  • Removed automatically when somebody changes department
  • The short list at review time
Matrix cell statesLive
All members have itFull baseline
Some membersOverride in place
Not grantedLeft clear
ReviewOverrides only
Three statesReadable at a glance

The map explains itself

When somebody asks who can approve a purchase over fifty thousand, the answer is a view rather than an investigation. That is the difference between a permission structure and a permission situation.

  • Org map by department
  • Matrix by permission
  • Both export for an access review
  • No need to ask people to test their own access
Access review exportLive
Departments8
Permissions15
OverridesListed separately
FormatExportable
Time to produceMinutes
A viewNot an investigation
What each role sees

Scoping is what makes the views usable

Three levels, taken from the product. Each one sees a genuinely different amount.

RoleSeesDoes not seeWhy it is scoped this way
Company headEvery team, workload and pending approvals across the businessNothing withheldNeeds the whole picture to spot where work is piling up
ManagerTheir own team's requests, workload and approvalsOther teams' workA manager looking at nine other teams stops looking at anything
Team memberTheir own requests and what they need to act onColleagues' requestsMost people only need their own work, and more than that is noise

Scoping is not only a control question. A view that shows somebody ten times more than they need is a view they stop opening.

Keeping it tidy

The habits that stop access drifting

Start narrow

Add rather than remove

A baseline that is slightly too tight generates requests you can grant. One that is too broad generates nothing at all until an audit.

DirectionAdd, do not remove
Review overrides

Not the whole population

Overrides are the exceptions, so a review means looking at those rather than confirming that everybody in Finance is still in Finance.

Review scopeOverrides only
Move, do not copy

Change the department

Moving somebody removes the old baseline and applies the new one, which is why nobody ends up carrying access from a role they left two years ago.

Orphaned accessRemoved
Watch new permissions

Every addition needs a home

When a new permission appears, deciding which baselines get it is a five minute conversation. Skipping it is how drift starts.

DecideAt creation
Export before the review

Bring the answer with you

The matrix exports, so an access review starts from a document rather than from a request for one.

ProduceIn minutes
Keep departments real

Match the business

Permission departments that do not match how the company is organised will always need overrides, which defeats the point.

MatchThe real structure
Who does what

The short version of everyone's job

Permissions stay understandable when they describe a role rather than a history of individual decisions.

What people do

Decide which department somebody belongs to. That is the decision, and almost everything else follows from it.

The human partLive
Choose a departmentWhen somebody joins
Set the baselineOnce per department
Grant an overrideWhere genuinely needed
Review overridesPeriodically
One decision per personNot fifteen

What eProcureAI does

Applies the baseline, keeps the matrix current, and cleans up when people move.

The automatic partLive
Apply the baselineOn joining
Update everybodyWhen a baseline changes
Remove old accessWhen somebody moves
Mark overridesDistinctly
Export the matrixFor a review
Nothing drifts quietlyBecause nothing is copied
0departments in a typical setup
0permissions in a Finance baseline
0states a matrix cell can be in
0decision to add a person
FAQ

Questions people actually ask

Why attach permissions to departments rather than people?
Because people move and departments do not. A baseline means the person joining next month gets the right access without anybody remembering to set it up, and the person leaving does not take stale access with them.
What if one person genuinely needs something extra?
That is an override. It sits on top of the baseline and is visibly marked as an override, so it appears on the short list at review time rather than disappearing into the population.
What happens when somebody changes department?
The old baseline is removed and the new one applied. Nobody keeps access from a role they left, which is the most common source of quiet permission creep.
Can we see who is able to do a particular thing?
Yes. The matrix shows every permission against every department, with each cell telling you whether all members, some members or nobody has it.
How does this relate to what people see on their dashboard?
Access controls what somebody can do, and role scope controls how much they see. A company head sees every team, a manager sees their own, and a team member sees their own work.
Is the structure exportable for an access review?
Yes, and it takes minutes. Most teams bring the export to the review rather than being asked to produce one afterwards.
Who is allowed to change baselines?
Whoever you nominate, usually a small group. Because a baseline change affects a whole department at once, it is worth keeping that list short.
What happens when a new permission is created?
You decide which department baselines receive it at the point of creation. Doing that immediately is what stops permissions accumulating without an owner.

Bring your org chart to the call

Thirty minutes is enough to map your departments and show what each person would actually see.

Book your free demo

Next in the chain: The full platform