Demonstration site. Sample properties and people. The public site is fully clickable; private areas are explained screen by screen.

Automation, security & integrations

Roles, permissions & record-level access

Access decided in the database, not hidden in the interface.

Used by: System

Kestrel Platform — RolesSystem
Staff memberRoleTwo-factorCan see reserves
Aoife BrennanAdministratorEnabledYes
Daniel OkoyeNegotiatorEnabledNo
Maeve CullenLettingsEnabledNo
Temp — receptionRead-onlyEnabledNo
Illustrative preview of a private screen, populated with sample data. Not a live sign-in.

How this works

Controls who can see and do what: staff roles for the office, and record-level rules so a buyer or seller can only ever reach their own data.

Who uses it

Branch director assigning roles · Every user, invisibly

Step by step

  1. 1Roles are held separately from user profiles so they cannot be self-edited — administrator, negotiator, lettings, auctioneer, read-only.
  2. 2Each role grants a defined set of actions, checked on the server for every request.
  3. 3Record-level rules restrict rows to their owner: a seller sees their property, a buyer sees their offers.
  4. 4Staff two-factor authentication is required for administrative roles.

Data captured

  • Role assignments with who granted them and when
  • Permission checks and denials

Emails it sends automatically

  • Role changed notification to the affected staff member

Why it matters commercially

A junior staff member cannot accidentally see a confidential reserve, and no client can ever see another client's file.

This screen is a faithful preview of a private area, filled with invented data. Nothing on it is editable here.