Access Control, Data Scopes & Audit Logging Not everyone should see every client.
Role permissions decide what a person can do; data scopes and fine-grained visibility rules decide which records they ever see. Every significant action is written to an audit log that cannot be edited or deleted.
Three layers, not one switch
Access in a practice is rarely all-or-nothing. Who someone is, what they may do, and which records they may see are decided separately.
Tenant isolation
Each firm’s data is fully separate. A user of one firm can never reach another firm’s records.
Role permissions
What a person can do. A missing permission blocks the action, and the attempt itself is written to the audit log.
Data scope
Which records they see — only their own assigned records, their team’s, or all firm records.
Data rules
Fine-grained narrowing by practice entity, contact type, tag or team, assignable to a user or a whole team.
Combined roles
Permissions combine across roles; data scope resolves to the most restrictive. More roles never means quietly more visibility.
Self-escalation blocked
Nobody can change their own role or escalate their own permissions, or lock themselves out of their own data.
The six standard roles
Every firm is provisioned with these. They cannot be edited or deleted — so the baseline stays the baseline — and a firm may add up to 20 custom roles alongside them.
Administrator — all records
Full control of the firm’s workspace, including users and settings.
Partner — all records
Full client, job, billing and reporting access; read-only settings; no user administration.
Manager — team records
Manages the assigned team’s clients, jobs and approvals, with limited billing.
Accountant — assigned records
Works their own assigned clients and jobs, and sees nothing beyond them.
Front Desk — all records
Contact management and scheduling, with no billing access.
Billing User — all records
Invoices, payments and financial reports.
What the platform guarantees
Stated narrowly and only where the application enforces it.
Each firm’s data is isolated; a user of one firm can never access another firm’s data.
A missing permission blocks the action, and the attempt is recorded in the audit log.
Data scope limits which records a user sees — assigned only, team, or all firm records.
A user cannot modify their own role or escalate their own permissions.
A user cannot assign themselves or their team a data role that would lock them out of their own data.
The six standard roles cannot be edited or deleted; a firm may create up to 20 custom roles.
Where a user holds several roles, permissions combine and the data scope resolves to the most restrictive.
Sensitive identifiers are stored encrypted and revealed only to authorised readers.
Contacts are archived rather than permanently deleted.
Audit log entries cannot be modified or deleted by anyone.
Login is blocked entirely while a firm is suspended or deactivated.
Passwords must be 8 to 128 characters with upper case, lower case, a digit and a special character.
Frequently asked questions
How is one firm’s data kept away from another’s?
What is the difference between permissions and data scope?
Can we restrict someone to one office or client type?
Can an administrator give themselves more access?
What roles ship with a new firm?
What if someone holds more than one role?
Can the audit log be edited?
How is sensitive client data handled?
Explore the platform
- Jobs & WorkflowsTemplated engagements with stage gates, task assignment, recurrence and dependencies
- Time & BillingTime capture, approval, WIP ledger, invoicing, quotes and financial periods
- Client PortalSecure per-client access to jobs, documents, invoices, quotes and messaging
- Document ManagementCentral store, versioning, document requests, malware scanning and text extraction
- Automation & SLANo-code automation rules, per-job-type SLA targets, warnings and escalation
- Capacity PlanningAvailability, workload forecasting, utilization thresholds and load balancing across staff
- Reporting & AnalyticsWIP, aged receivables, realization, profitability and utilization reporting
- Solo & Small FirmsReplace the folder-and-spreadsheet stack without a six-month implementation
- Growing FirmsStandardised workflows, approval gates, SLA targets and per-team data scopes
- Multi-Entity FirmsPer-entity branding, invoice numbering, tax defaults and job codes under one firm
- Switching PlatformsStaged CSV import with review at each step, including CCH iFirm exports
See Praxio on your own engagements.
Book a walkthrough and we'll configure it around the way your firm actually works — your engagement types, your review steps, your billing model.