Who Sees What: Why It's Important to Limit Access Rights in a Workshop
Published
Workshop owners often make the mistake of giving all employees “administrator rights.” The logic is understandable: “so they don’t run around with every question.” But the consequences of such freedom are chaos in data, accidental order deletion, and the risk of information leakage.
The right approach is the principle of least privilege: each employee sees only what they need to perform their daily tasks.
Why Limit Access
Limiting rights is not about “distrust,” but about productivity and security:
- Focus. A receptionist doesn’t need to see financial reports and salary structures. They need the order creation form and the order list. The fewer “extra” buttons there are, the faster they work.
- Protection Against Errors. A technician should not have the ability to change prices in the price list or delete orders. An accidental click shouldn’t cost you a missed order.
- Security. If a receptionist sees the cost price of spare parts or the total profit of the entire network, this data can accidentally or intentionally be disclosed to third parties.
How Roles Work in WorkPan
In the system, you can flexibly configure exactly what is available to a specific employee. This is done in the “System” -> “Privileges” section.
Role: Receptionist
Their task is to quickly accept an order and issue a finished one. They need rights to:
- View all orders (or only their own).
- Create a new order.
- View the Control Panel regarding sales.
- They do not need rights to manage service directories, prices, or financial analytics.
Role: Technician
Their task is repair.
- Sees their list of tasks in the Workshop Panel.
- Has access to workshop tickets to record work progress.
- They don’t need to see the customer database (phones, addresses) or company financial flows.
Role: Manager / Administrator
Sees everything: analytics, money flow, employee management. They should have full rights to configure the system, including Directories.
Practical Setup Tips
- Restriction by branch. If you have a network, configure visibility so that an employee of the “Center” branch does not see orders from the “Suburbs” branch, unless required by business processes. This removes visual noise.
- Regular Audit. Check the list of employees once a quarter. If a person has quit or moved to a different position — change their rights immediately. Forgotten access rights are the most common channel for data leakage.
- Don’t Fear “Lack of Rights.” If an employee lacks something to work, they will say so themselves. This is much better than them having access to what they aren’t supposed to know.
Security starts with your employee seeing only their tasks in the system. When everyone has their own area of responsibility, a CRM turns from a “general dump” into a tool that helps you work rather than creating additional risks.