Two independent controls, deliberately kept apart: what a role is allowed to do, and whose records a person can see. A bug in one must not open the other.
Admin, Manager, Customer Service Advisor, Setter, Technician and Super Admin, against sixteen named permissions in four groups. The defaults are sensible and every one of them is yours to change per company.
By default a tech gets field notes, checklists and recommendations — and not the permission to accept the work they just recommended. The person who benefits from the upsell is not the person who signs it off.
Until a manager, advisor or technician has passed their required courses, every permission returns false and they are sent to Training on login. Not a nag banner — the app will not let them work.
Intern, Apprentice, Tech I, Tech II, Senior, Master — each with a recommended number of completed jobs behind it, enforced only if you choose to enforce it.
Switched off by default. Switched on, everyone but an admin sees only records where they are the setter, closer, advisor or technician — and a manager sees their whole downline, however deep the org chart goes.
These controls are in the app, not in the database. They stop the honest mistake and they keep people in their lane; they are not a substitute for the access controls a security review would ask about, and we will not pretend otherwise.
Get a personalized demo of Sun Service CRM for your team.