Roles, Not Plans: Designing Permissions for a Small Team — Herarx Blog

Roles, Not Plans: Designing Permissions for a Small Team

In an organisation workspace, features are switched on by role — not by who is paying. Here is how to design roles that match how a team actually works.

February 04, 2026
Roles, Not Plans: Designing Permissions for a Small Team
Back to blog

A personal Herarx workspace is governed by a plan: Free, Premium or Max decide what it can do. An organisation workspace is different. Every member has a role, and the role decides what they can see and do. The organisation's owner designs the roles.

That is deliberate. In a team, "who can delete a case" should not be a billing question.

What a role controls

A role is a name plus a set of toggles: read, create, edit and delete cases; see hidden cases; manage contacts, files and templates; use Mail, e-sign, accounting, Insights; invite members; and so on. Members get the role's permissions the moment it is assigned, and lose them the moment it changes.

Three roles cover most teams

  1. Owner / Admin — everything, including members, roles, templates and the organisation's settings. Keep this to one or two people.
  2. Case worker — create and edit cases, contacts and files; use Mail and e-sign; no delete, no template editing, no member management.
  3. Viewer / Auditor — read cases and files, export, see analytics; no changes. Accountants, supervisors and external reviewers live here.

Add roles when a real distinction appears — a field team that should only see the phone view, a finance person who posts to the books but should not edit case text — not before.

Roles versus case membership

A role says what a member could do. Case membership says which cases they do it on. A case worker with no cases assigned sees nothing. Templates can set default share audiences so new cases of a given kind are visible to the right group automatically; sensitive matters can be marked hidden so only their members know they exist.

Advanced Security cases

Some matters need a second wall. An Advanced-Security case is encrypted with its own key, invisible on screen to anyone who is not a member — including admins and the assistant — and matches search only by title and case number, and only for its members. Use it for the handful of cases where "the admin can technically see it" is itself a problem.

The mistake to avoid

Giving everyone the admin role "for now". It is never revisited, and the first accidental deletion or template change teaches the lesson expensively. Start narrow. Widening a role takes ten seconds; explaining a leak takes rather longer.