Enterprise Access Control & RBAC Permissions
Safeguard your company data with Smart Business 360's multi-tenant architecture. Built with a 4-Tier Access Model, granular Module.Resource.Action key evaluation, and strict Segregation of Duties.
The 4-Tier Enterprise Access Model
Four sequential checks determine exactly what data and actions each user can access.
Module Entitlement
First check: Is the module enabled for this company contract tenant?
RBAC Key Permission
Second check: Does the user's role hold the exact Module.Resource.Action key?
Record Role Scope
Third check: Whose records can they see? (SuperAdmin, TenantAdmin, TeamManager).
Department Hierarchy
Fourth check: Is the record within the user's assigned department or team scope?
Module.Resource.Action Key System
Permissions are evaluated using an explicit 3-part key structure: Module.Resource.Action. This allows administrators to grant exact CRUD operations or extended business actions without over-exposing data.
Accounts.Voucher.Post
Grants specific permission to post financial vouchers to the ledger, separate from creating or editing vouchers.
CRM.*.Read or *.*.Read
Wildcards automatically grant read permissions to new sub-resources added during system upgrades without manual re-configuration.
Baseline System Roles
| Role | Scope & Purpose |
|---|---|
| Tenant Administrator | Full company administration & settings management. |
| Sales Officer | Working leads, opportunities, activities, and inbox threads. |
| Sales Manager | Team lead visibility, deal approvals, and commission oversight. |
| Accountant | Posting journal vouchers, managing ledgers, bank reconciliations. |
| HR Officer | Biometric attendance, leave approvals, and payroll processing. |
Segregation of Duties (SoD) Safeguards
Prevent financial fraud and internal risk by enforcing strict role separation across high-risk pairs.
Accounts.Voucher.Create + Accounts.Voucher.Post
Separates entry preparation from final commitment to the double-entry financial ledger.
SalesManagement.Receipt.Create + SalesManagement.Receipt.Approve
Separates cash/payment collection entry from managerial authorization.
SalesManagement.Refund.Create + SalesManagement.Refund.Approve
Separates customer refund initiation from financial disbursement release.
HRM.Salary.Create + HRM.Salary.RunPayroll
Separates payroll salary calculations from actual fund release and disbursement.
Inventory.Procurement.Create + Inventory.Procurement.Approve
Separates purchase requisitions from vendor procurement approvals.
System.UserManagement.Create + System.Permissions.Update
Separates user account creation from privilege escalation grants.
Multi-Company Setup & Data Layer Isolation
Manage multiple independent companies or subsidiaries within a single Smart Business 360 platform.
Two Administrator Levels
| Level | Role Scope | Responsibility |
|---|---|---|
| Platform Super Admin | PlatformSuperAdmin |
Creating companies, module entitlements, subscription plans. |
| Company Administrator | TenantAdmin |
Company-specific configuration: users, roles, departments, ledgers. |
Ongoing Administration Audit Cadence
Enterprise RBAC & Security FAQ
CRM.*.Read and CRM.Lead.Update, they can read all CRM resources and update lead records.
TeamManager or TenantAdmin) determine whose records a user can see, whereas RBAC keys determine which actions they can perform on those records.
Secure your business operations with Enterprise RBAC
Schedule a call with our technical team to explore custom roles and security controls.