Security & Access

Access Control, Data Scopes & Audit Logging Not everyone should see every client.

Role permissions decide what a person can do; data scopes and fine-grained visibility rules decide which records they ever see. Every significant action is written to an audit log that cannot be edited or deleted.

Three layers, not one switch

Access in a practice is rarely all-or-nothing. Who someone is, what they may do, and which records they may see are decided separately.

Tenant isolation

Each firm’s data is fully separate. A user of one firm can never reach another firm’s records.

Role permissions

What a person can do. A missing permission blocks the action, and the attempt itself is written to the audit log.

Data scope

Which records they see — only their own assigned records, their team’s, or all firm records.

Data rules

Fine-grained narrowing by practice entity, contact type, tag or team, assignable to a user or a whole team.

Combined roles

Permissions combine across roles; data scope resolves to the most restrictive. More roles never means quietly more visibility.

Self-escalation blocked

Nobody can change their own role or escalate their own permissions, or lock themselves out of their own data.

The six standard roles

Every firm is provisioned with these. They cannot be edited or deleted — so the baseline stays the baseline — and a firm may add up to 20 custom roles alongside them.

Administrator — all records

Full control of the firm’s workspace, including users and settings.

Partner — all records

Full client, job, billing and reporting access; read-only settings; no user administration.

Manager — team records

Manages the assigned team’s clients, jobs and approvals, with limited billing.

Accountant — assigned records

Works their own assigned clients and jobs, and sees nothing beyond them.

Front Desk — all records

Contact management and scheduling, with no billing access.

Billing User — all records

Invoices, payments and financial reports.

What the platform guarantees

Stated narrowly and only where the application enforces it.

  • Each firm’s data is isolated; a user of one firm can never access another firm’s data.

  • A missing permission blocks the action, and the attempt is recorded in the audit log.

  • Data scope limits which records a user sees — assigned only, team, or all firm records.

  • A user cannot modify their own role or escalate their own permissions.

  • A user cannot assign themselves or their team a data role that would lock them out of their own data.

  • The six standard roles cannot be edited or deleted; a firm may create up to 20 custom roles.

  • Where a user holds several roles, permissions combine and the data scope resolves to the most restrictive.

  • Sensitive identifiers are stored encrypted and revealed only to authorised readers.

  • Contacts are archived rather than permanently deleted.

  • Audit log entries cannot be modified or deleted by anyone.

  • Login is blocked entirely while a firm is suspended or deactivated.

  • Passwords must be 8 to 128 characters with upper case, lower case, a digit and a special character.

Frequently Asked Questions

Frequently asked questions

How is one firm’s data kept away from another’s?

The platform is multi-tenant with enforced isolation: a user of one firm can never access another firm’s data. Each firm is provisioned with its own workspace, roles, settings and records.

What is the difference between permissions and data scope?

Permissions decide what a person can do — send an invoice, reopen a job. Data scope decides which records they ever see: only records assigned to them, their team’s records, or all firm records. Two people in the same role can legitimately see different data.

Can we restrict someone to one office or client type?

Yes. Fine-grained data rules narrow visibility further — by practice entity, contact type, tag or team — and can be assigned to individual users or to whole teams.

Can an administrator give themselves more access?

A user cannot modify their own role or escalate their own permissions. They also cannot assign themselves or their own team a restrictive data role that would lock them out of their own data.

What roles ship with a new firm?

Six standard roles — Administrator, Partner, Manager, Accountant, Front Desk and Billing User — each with its own permissions and data scope. The six cannot be edited or deleted, and a firm can add up to 20 custom roles of its own.

What if someone holds more than one role?

Permissions combine — any role granting a capability wins — while the data scope becomes the most restrictive of their roles. Adding a role never quietly widens what someone can see.

Can the audit log be edited?

No. Audit log entries cannot be modified or deleted by anyone, including firm administrators. Missing-permission attempts are logged too, not just successful actions.

How is sensitive client data handled?

Sensitive identifiers are stored encrypted and revealed only to authorised readers. Contacts are archived rather than permanently deleted, so history survives a cleanup.

See Praxio on your own engagements.

Book a walkthrough and we'll configure it around the way your firm actually works — your engagement types, your review steps, your billing model.