Automation, security & integrations
Roles, permissions & record-level access
Access decided in the database, not hidden in the interface.
Used by: System
Kestrel Platform — RolesSystem
| Staff member | Role | Two-factor | Can see reserves |
|---|---|---|---|
| Aoife Brennan | Administrator | Enabled | Yes |
| Daniel Okoye | Negotiator | Enabled | No |
| Maeve Cullen | Lettings | Enabled | No |
| Temp — reception | Read-only | Enabled | No |
How this works
Controls who can see and do what: staff roles for the office, and record-level rules so a buyer or seller can only ever reach their own data.
Who uses it
Branch director assigning roles · Every user, invisibly
Step by step
- 1Roles are held separately from user profiles so they cannot be self-edited — administrator, negotiator, lettings, auctioneer, read-only.
- 2Each role grants a defined set of actions, checked on the server for every request.
- 3Record-level rules restrict rows to their owner: a seller sees their property, a buyer sees their offers.
- 4Staff two-factor authentication is required for administrative roles.
Data captured
- Role assignments with who granted them and when
- Permission checks and denials
Emails it sends automatically
- Role changed notification to the affected staff member
Why it matters commercially
A junior staff member cannot accidentally see a confidential reserve, and no client can ever see another client's file.
This screen is a faithful preview of a private area, filled with invented data. Nothing on it is editable here.