4. Workspaces & roles
Every account type gets its own scoped workspace. Admins configure the system; Staff work the pipeline; Clients track progress; Companies manage their teams and branch-scoped data.
Role summary
| Role | Description | Typical menus |
|---|---|---|
| Admin | Full CRM access — users, roles, menus, and configuration | All modules + Administration |
| Company | Organization account with branch-scoped menus and data | Branch operations, team overview, scoped reports |
| Staff | Assigned internal team access | Enquiries, conversion, calendar, communication |
| Client | Self-service portal | Profile, documents, case / visa / migration milestones |
Admin
Purpose: Own the system configuration and user access.
Can typically:
- Manage users, roles, and menu visibility
- Configure enquiry & conversion statuses
- Maintain lead sources, providers, and lookup tables
- Control API route permissions per role
- Set up branches, countries, programs, and services
Should not: Use Admin for day-to-day counselling if a Staff account is available — keep admin privileges limited.
Company
Purpose: Organization-level view for agencies with branches, franchises, or partners.
Can typically:
- Work within branch-scoped menus and data
- Oversee team activity within their organization scope
- Coordinate multi-brand / multi-region operations where configured
Staff
Purpose: Daily case work — enquiries, pipeline, follow-ups.
Can typically:
- Capture and update enquiries (status, source, assignee)
- Move cases through conversion stages
- Log comments, emails, and documents
- Use calendar and leave (plan-dependent)
- See only records and actions allowed by their role permissions
Client
Purpose: Transparent progress without emailing the agency for every update.
Can typically:
- View profile and uploaded documents
- Track visa, skill migration, and PR application progress
- Complete onboarding when profile is incomplete
- Message / view mail visible in the client area (where enabled)
Permissions model
- Menus control what appears in navigation.
- API route permissions (synced to roles) enforce what actions the backend allows.
- Changing a user’s role updates both UI and API access — no separate “hidden” admin bypass for Staff.
Switching context
Users with multiple memberships may use the workspace selector after login. Always confirm the active workspace before editing records so you do not update the wrong branch’s data.
→ Next: Modules
