CRM docsWorkspaces & roles

4. Workspaces & roles

Every account type gets its own scoped workspace. Admins configure the system; Staff work the pipeline; Clients track progress; Companies manage their teams and branch-scoped data.

Role summary

RoleDescriptionTypical menus
AdminFull CRM access — users, roles, menus, and configurationAll modules + Administration
CompanyOrganization account with branch-scoped menus and dataBranch operations, team overview, scoped reports
StaffAssigned internal team accessEnquiries, conversion, calendar, communication
ClientSelf-service portalProfile, documents, case / visa / migration milestones

Admin

Purpose: Own the system configuration and user access.

Can typically:

  • Manage users, roles, and menu visibility
  • Configure enquiry & conversion statuses
  • Maintain lead sources, providers, and lookup tables
  • Control API route permissions per role
  • Set up branches, countries, programs, and services

Should not: Use Admin for day-to-day counselling if a Staff account is available — keep admin privileges limited.

Company

Purpose: Organization-level view for agencies with branches, franchises, or partners.

Can typically:

  • Work within branch-scoped menus and data
  • Oversee team activity within their organization scope
  • Coordinate multi-brand / multi-region operations where configured

Staff

Purpose: Daily case work — enquiries, pipeline, follow-ups.

Can typically:

  • Capture and update enquiries (status, source, assignee)
  • Move cases through conversion stages
  • Log comments, emails, and documents
  • Use calendar and leave (plan-dependent)
  • See only records and actions allowed by their role permissions

Client

Purpose: Transparent progress without emailing the agency for every update.

Can typically:

  • View profile and uploaded documents
  • Track visa, skill migration, and PR application progress
  • Complete onboarding when profile is incomplete
  • Message / view mail visible in the client area (where enabled)

Permissions model

  • Menus control what appears in navigation.
  • API route permissions (synced to roles) enforce what actions the backend allows.
  • Changing a user’s role updates both UI and API access — no separate “hidden” admin bypass for Staff.

Switching context

Users with multiple memberships may use the workspace selector after login. Always confirm the active workspace before editing records so you do not update the wrong branch’s data.

→ Next: Modules