Introduction
This guide is designed to help Washstacks operators make informed decisions when configuring Roles and Permissions for their teams inside the Operations module. One of the most common questions we receive during training calls is, "What permissions should I give to this role?" The answer often depends on the size of the organization, the chain of command at each location, and how much oversight you want from your corporate team. This document walks through every permission setting available in the Operations module and provides our recommendations for who should have access to what.
Washstacks uses a permissions matrix made up of five possible actions for most features: View, Add, Edit, Delete, and Reports. Not every permission area uses all five actions — some are intentionally limited based on the design of the feature. For example, the Checklists row now offers only View and Delete, and the Templates – Checklists (Global) and (Multi-site) rows offer only Add, Edit, and Delete. A few features also add extra toggles in an Additional Access area at the bottom of the permissions screen, such as Run adhoc checklists. Each section below explains what the action does, followed by a recommendation table and the reasoning behind that recommendation.
💡 Important Note: These are recommendations only. Every car wash organization is structured a little differently. The suggestions in this document reflect what we have seen work well across most operations, but you are free to configure permissions in whatever way best fits your business. You know your team, your management structure, and your level of trust better than anyone. Use this document as a starting point — not as a rulebook.
Understanding the Five Permission Types
Before assigning permissions, it is important to understand what each checkbox actually does. In the Operations module, you will typically see up to five columns next to each permission row:
View — Allows the user to see the information, list, or feature. If a user does not have View access, the menu item or page is typically hidden from them entirely.
Add — Allows the user to create new records (a new contact, a new work order, a new checklist template, etc.).
Edit — Allows the user to modify existing records. This is often paired with Add for users who need to maintain data over time.
Delete — Allows the user to permanently remove records. This is the most powerful permission and should be reserved for trusted, accountable roles.
Reports — Allows the user to view the reporting view associated with that feature. Some Reports checkboxes are still under development; those are noted in each section below.
Where a column is left blank for a row, that action does not exist for that feature. A useful rule of thumb: when in doubt, start with less and add more. It is easier to grant additional access when an employee asks for it than it is to recover from accidentally deleted data.
Role Categories Used in This Guide
Throughout this document we will reference the following general role categories. Your organization may use different titles, but the responsibilities typically map directly to these groupings:
Corporate Management — Owners, VPs of Operations, Directors, and other home office leadership with oversight across all locations.
Top Store Management — The General Manager or Site Manager who has ultimate accountability for a single location.
Mid-Level Store Management — Assistant Managers, Shift Managers, and Supervisors who help run the store but report to a top store manager.
Lower-Level Management — Team Leads, Key Holders, and Shift Leaders who may run a single shift but do not have full management authority.
Maintenance Management — Regional or site-level Maintenance Managers responsible for equipment, parts, and work order completion.
Maintenance Employees — Technicians and maintenance staff who execute work orders but do not manage the program.
Supply Managers — Home office or warehouse staff responsible for fulfilling and tracking supply requests.
Front-Line Staff — CSAs (Customer Service Associates), Attendants, and other hourly team members.
1. Assets
Assets are the physical pieces of equipment at each site — tunnels, blowers, vacuums, pay stations, and the machinery your maintenance program keeps running. Accurate asset records are the foundation of your Work Order and Parts workflows, so control over who can change them belongs with the people accountable for equipment.
What Each Permission Does
View — User can see all asset records.
Add — User can create new asset records.
Edit — User can modify existing asset records.
Delete — User can permanently remove an asset record.
Reports — User can view the asset report.
Recommended Settings
Role | View | Add | Edit | Delete | Reports |
Corporate Management | ✓ | ✓ | ✓ | ✓ | ✓ |
Top Store Management (GM, Site Manager) | ✓ | ✓ | ✓ | ✓ | ✓ |
Maintenance Managers | ✓ | ✓ | ✓ | ✓ | ✓ |
Maintenance Employees / Technicians | ✓ | ✗ | ✗ | ✗ | ✓ |
Assistant Managers / Shift Managers | ✓ | ✗ | ✗ | ✗ | ✗ |
Team Leads / Key Holders | ✓ | ✗ | ✗ | ✗ | ✗ |
CSAs / Attendants | ✗ | ✗ | ✗ | ✗ | ✗ |
Why We Recommend This
Assets underpin your entire maintenance program, so full access should sit with the people who own equipment: corporate management, top store management, and maintenance managers. Maintenance employees and technicians should have View (and Reports) so they can look up an asset while they work, but they should not be creating, editing, or deleting the underlying records. Other store management can have View if they need visibility into site equipment, and front-line staff generally do not need access at all.
2. Checklists
Checklists are the backbone of daily operational accountability inside Washstacks. They cover everything from opening and closing routines to weekly maintenance and safety walks. In the current version of the platform, this Checklists row controls whether a user can see and complete the checklists assigned to them, and whether they can delete a checklist. Creating and editing checklists is now handled separately under the Templates – Checklists permissions (see sections 14–16).
What Each Permission Does
View — User can see and complete checklists assigned to their role.
Delete — User can permanently delete a checklist.
Add / Edit — Not set here. Creating and editing checklists is controlled by the Templates – Checklists permissions (section 14).
Reports — Not applicable for this row.
Recommended Settings
Role | View | Add | Edit | Delete | Reports |
Corporate Management | ✓ | — | — | ✓ | — |
Top Store Management (GM, Site Manager) | ✓ | — | — | ✓ | — |
Assistant Managers | ✓ | — | — | ✗ | — |
CSAs / Attendants / Front-Line Staff | ✓ | — | — | ✗ | — |
Why We Recommend This
Everyone who is assigned checklists needs View so they can see and complete them each day. Delete should stay with top store management and corporate management so a live checklist is not removed by mistake. To let a role actually build or change checklists, grant the Templates – Checklists permissions described in section 14 rather than anything on this row.
A Note on Running Ad Hoc Checklists
Ad hoc checklists (one-off checklists triggered manually) are now controlled by a separate Run adhoc checklists toggle in the Additional Access area at the bottom of the permissions screen, rather than by the old Global checklist setting. Enable Run adhoc checklists for any role you want to be able to launch a checklist on demand — typically your store management. The permissions that govern building the templates themselves (including global and multi-site templates) are covered in sections 14–16.
3. Chemicals
The Chemicals area tracks the detergents, waxes, presoaks, and other chemistry that run through your wash, along with the records tied to them. Because chemical cost and dilution directly affect both wash quality and your bottom line, control over these records should sit with the people who manage your chemical program.
What Each Permission Does
View — User can see all chemical records.
Add — User can add new chemical records.
Edit — User can modify existing chemical records, including updating daily inventory counts.
Delete — User can delete existing chemical records.
Reports — User can view the chemicals report.
Recommended Settings
Role | View | Add | Edit | Delete | Reports |
Corporate Management | ✓ | ✓ | ✓ | ✓ | ✓ |
Top Store Management (GM, Site Manager) | ✓ | ✓ | ✓ | ✓ | ✓ |
Maintenance Managers | ✓ | ✓ | ✓ | ✓ | ✓ |
Assistant Managers / Shift Managers | ✓ | ✗ | ✓ | ✗ | ✗ |
Team Leads / Key Holders | ✓ | ✗ | ✓ | ✗ | ✗ |
CSAs / Attendants | ✗ | ✗ | ✗ | ✗ | ✗ |
Why We Recommend This
Chemical inventory usually needs to be updated daily, and it is not always the top manager doing the count — often it is an assistant manager, shift manager, or team lead running the shift. For that reason, everyone at the store above the front line should have View and Edit so they can keep chemical inventory current. Add and Delete, which create or remove the chemical records themselves, should stay with corporate management, top store management, and maintenance managers, who own the chemical program and are accountable for cost and dilution. Front-line staff (CSAs/Attendants) typically do not need any access.
4. Close Outs
If your organization uses Washstacks for nightly close outs, these permissions control who can count, reconcile, and finalize the day's money. Cash handling is one of the highest-risk areas in any retail operation, so it deserves careful thought.
What Each Permission Does
View — User can see existing nightly close outs.
Add — User can create a new nightly close out.
Edit — User can modify a previous nightly close out.
Delete — User can permanently remove a close out.
Reports — User can view the close out reporting screen.
Recommended Settings
Role | View | Add | Edit | Delete | Reports |
Corporate Management | ✓ | ✓ | ✓ | ✓ | ✓ |
Top Store Management (GM, Site Manager) | ✓ | ✓ | ✓ | ✓ | ✓ |
Assistant Managers / Shift Managers | ✓ | ✓ | ✓ | ✗ | ✓ |
Team Leads / Key Holders | ✓ | ✓ | ✓ | ✗ | ✗ |
CSAs / Attendants | ✗ | ✗ | ✗ | ✗ | ✗ |
Why We Recommend This
Anyone who has the authority to handle the daily money should be able to View, Add, and Edit a close out. That includes assistant managers, shift managers, team leads, and key holders — basically anyone who might be closing the store on a given night and needs to count and rectify daily sales. However, only the top store manager and corporate management should have Delete access. You do not want supervisors, key holders, or team leads deleting financial data, even by accident. Removing the Delete checkbox for these mid-level roles creates an important guardrail while still giving them everything they need to do their job.
5. Contacts
The Contacts area stores phone numbers, emails, and details for vendors, service providers, and other people your team interacts with regularly. While contact data may seem low-risk, it is often the first thing employees will leak or mishandle when they leave, so it pays to limit who can edit or remove records.
What Each Permission Does
View — User can view all contacts that have been added.
Add — User can add new contacts.
Edit — User can modify existing contacts.
Delete — User can delete existing contacts.
Reports — Not applicable for this feature.
Recommended Settings
Role | View | Add | Edit | Delete | Reports |
Corporate Management | ✓ | ✓ | ✓ | ✓ | — |
Top Store Management (GM, Site Manager) | ✓ | ✓ | ✓ | ✓ | — |
Assistant Managers / Shift Managers | ✓ | ✗ | ✗ | ✗ | — |
Team Leads / Key Holders | ✓ | ✗ | ✗ | ✗ | — |
CSAs / Attendants | ✓ | ✗ | ✗ | ✗ | — |
Why We Recommend This
Give your top store-level management and corporate management full permissions. They are the people who will be onboarding new vendors and keeping records accurate. Everyone below that level should be limited to View access only. Your team still needs to be able to look up a vendor's phone number when something breaks at 6 a.m., but they do not need the ability to change or delete that information.
6. Customers
The Customers area stores customer and membership records — names, contact details, plans, and account status. This is some of the most sensitive data in your account, and it is also data your front-line team touches constantly when they look up members or sign new ones up at the point of service.
What Each Permission Does
View — User can look up existing customer records.
Add — User can create new customer or membership records.
Edit — User can update existing customer records.
Delete — User can permanently remove a customer record.
Reports — Not applicable for this feature.
Recommended Settings
Role | View | Add | Edit | Delete | Reports |
Corporate Management | ✓ | ✓ | ✓ | ✓ | — |
Top Store Management (GM, Site Manager) | ✓ | ✓ | ✓ | ✓ | — |
Assistant Managers / Shift Managers | ✓ | ✓ | ✓ | ✗ | — |
Team Leads / Key Holders | ✓ | ✓ | ✓ | ✗ | — |
CSAs / Attendants | ✓ | ✓ | ✓ | ✗ | — |
Why We Recommend This
Front-line staff enroll and update members every day at the point of service, so View, Add, and Edit make sense across the board. Delete, on the other hand, should be restricted to top store management and corporate management to protect customer records and preserve the audit trail — a removed customer or membership can be difficult to recover. If your attendants do not handle sign-ups or account changes, feel free to drop the lower roles to View only.
7. Downtime
Tracking downtime is essential for understanding revenue loss, equipment reliability, and operational performance. The Downtime feature allows your team to log when the wash (or a piece of equipment) is offline so corporate can see patterns over time.
What Each Permission Does
View — User can view and add downtime incidents on the website (not the app).
Add — User can add a new downtime incident on both the app and the website.
Edit — User can edit an existing downtime incident on the website.
Delete — User can delete an existing downtime incident on the website.
Reports — User can view the downtime report on the website.
Recommended Settings
Role | View | Add | Edit | Delete | Reports |
Corporate Management | ✓ | ✓ | ✓ | ✓ | ✓ |
Top Store Management (GM, Site Manager) | ✓ | ✓ | ✓ | ✓ | ✓ |
Assistant Managers / Shift Managers | ✓ | ✓ | ✓ | ✗ | ✗ |
Team Leads / Key Holders | ✓ | ✓ | ✓ | ✗ | ✗ |
CSAs / Attendants | ✗ | ✗ | ✗ | ✗ | ✗ |
Why We Recommend This
All levels of management at a store should be able to view, add, and edit downtime. There will be plenty of times when lower-level management — a team lead or key holder — is the one running a shift, and they need to be able to communicate that the site is down. Reaction time matters here, so do not block them. No one below a management level should have any access to downtime. Only top store management and corporate management should have full permissions, including the ability to delete records and view the downtime report.
8. Import Locations
Import Locations is an administrative feature intended for bulk setup of new sites in the Washstacks system. It is rarely used day-to-day.
What Each Permission Does
Currently, the View and Add checkboxes for Import Locations have no functionality. Edit, Delete, and Reports are not applicable. This row may become active in a future release, but for now the recommendation focuses on the eventual intended use.
Recommended Settings
Role | View | Add | Edit | Delete | Reports |
Corporate Management | ✓ | ✓ | — | — | — |
Top Store Management (GM, Site Manager) | ✗ | ✗ | — | — | — |
All Other Store Roles | ✗ | ✗ | — | — | — |
Why We Recommend This
Only corporate-level management should have access to Import Locations. No one at the store level — including top managers — needs this. Bulk location imports affect the entire account structure and should be controlled tightly at the home office.
9. Import Parts
Import Parts allows users to bring in a list of parts from a CSV file rather than entering each one manually. This is a powerful feature that can quickly populate or change your parts inventory.
What Each Permission Does
View — User can view and add parts from a CSV file (requires Add to also be checked).
Add — User can view and add parts from a CSV file (requires View to also be checked).
Edit / Delete / Reports — Not applicable for this feature.
Recommended Settings
Role | View | Add | Edit | Delete | Reports |
Corporate Management | ✓ | ✓ | — | — | — |
Top Store Management (GM, Site Manager) | ✗ | ✗ | — | — | — |
All Other Store Roles | ✗ | ✗ | — | — | — |
Why We Recommend This
Just like Import Locations, only corporate-level management should have full access to Import Parts. No one at the store, including top managers, should have any access. CSV imports can overwrite or duplicate large amounts of inventory data in a single action, and that level of risk belongs at the home office.
10. Library
The Library is where you store SOPs, training materials, MSDS sheets, equipment manuals, and any other reference documents your team needs. It is the central knowledge base for your operation.
What Each Permission Does
View — User can view all documents in the Library.
Add — User can upload new documents to the Library.
Edit — User can modify existing Library documents.
Delete — User can delete existing Library documents.
Reports — Not applicable for this feature.
Recommended Settings
Role | View | Add | Edit | Delete | Reports |
Corporate Management | ✓ | ✓ | ✓ | ✓ | — |
Top Store Management (GM, Site Manager) | ✓ | ✓ | ✓ | ✓ | — |
Assistant Managers / Shift Managers | ✓ | ✗ | ✗ | ✗ | — |
Team Leads / Key Holders | ✓ | ✗ | ✗ | ✗ | — |
CSAs / Attendants | ✓ | ✗ | ✗ | ✗ | — |
Why We Recommend This
All employees should have View access to the Library. The whole point of the Library is to make information accessible to everyone, so blocking visibility defeats the purpose. Only top store management and corporate management should have full access to add, edit, and delete documents. Document version control is important — you do not want five different versions of the same SOP floating around because everyone with the app can upload their own.
11. Parts
The Parts area tracks your equipment parts inventory — the bearings, pumps, hoses, and consumables you use to keep the wash running. Accurate parts data drives both your work order workflow and your replenishment decisions.
What Each Permission Does
View — User can view all parts in inventory.
Add — User can add new parts to inventory.
Edit — User can modify existing parts in inventory.
Delete — User can delete existing parts from inventory.
Reports — Not applicable for this feature.
Recommended Settings
Role | View | Add | Edit | Delete | Reports |
Corporate Management | ✓ | ✓ | ✓ | ✓ | — |
Top Store Management (GM, Site Manager) | ✓ | ✓ | ✓ | ✓ | — |
Maintenance Managers | ✓ | ✓ | ✓ | ✓ | — |
Maintenance Employees / Technicians | ✓ | ✗ | ✗ | ✗ | — |
Assistant Managers / Shift Managers | ✓ | ✗ | ✗ | ✗ | — |
Team Leads / Key Holders | ✓ | ✗ | ✗ | ✗ | — |
CSAs / Attendants | ✗ | ✗ | ✗ | ✗ | — |
Why We Recommend This
No one below management should have any access to anything Parts-related. Top store management, corporate management, and any maintenance managers should have full Parts access — they are the people responsible for inventory accuracy. Maintenance employees and technicians should have View access so they can look up part availability while they work on equipment, but they should not be able to add, edit, or delete inventory records. All other managers and supervisors should also be limited to View access. They may need to look up whether a part is in stock, but they do not need the ability to change inventory counts or delete part records.
12. Supplies
Supplies typically refers to the soap, wax, towels, and other consumables that are stored at an off-site location like a home office or central warehouse. Because supplies inventory is usually managed centrally, the store-level permissions are intentionally narrow.
What Each Permission Does
View — User can view all supplies in inventory.
Add — User can add new supplies to inventory.
Edit — User can modify existing supplies in inventory.
Delete — User can delete existing supplies from inventory.
Reports — User can view the supplies report.
Recommended Settings
Role | View | Add | Edit | Delete | Reports |
Corporate / Home Office Management | ✓ | ✓ | ✓ | ✓ | ✓ |
Top Store Management (GM, Site Manager) | ✓ | ✗ | ✗ | ✗ | ✗ |
Assistant Managers / Shift Managers | ✓ | ✗ | ✗ | ✗ | ✗ |
Team Leads / Key Holders | ✓ | ✗ | ✗ | ✗ | ✗ |
CSAs / Attendants | ✓ | ✗ | ✗ | ✗ | ✗ |
Why We Recommend This
Anyone at the stores — management included — should only have View access to supplies. The store team needs to know what is available so they can plan and request what they need, but they should not be adding to, editing, or deleting central inventory records. Corporate or home office management should have full permissions, since they are the ones who actually receive shipments, stock the warehouse, and keep counts accurate — and they are also the right group to review the supplies report.
13. Supply Requests
Supply Requests is the bridge between your stores and your home office or warehouse. When a store runs low on a consumable, this is how they ask for it. Because supply requests turn into real-world shipments and dollars, the approval and fulfillment side should be locked down.
What Each Permission Does
View — User can see supply requests that have been submitted from the team.
Add — User can place a new supply order/request.
Edit — User can edit or complete an existing supply request.
Delete — User can delete an existing supply request.
Reports — Not applicable for this feature.
Recommended Settings
Role | View | Add | Edit | Delete | Reports |
Corporate Management | ✓ | ✓ | ✓ | ✓ | — |
Supply Managers | ✓ | ✓ | ✓ | ✓ | — |
Top Store Management (GM, Site Manager) | ✓ | ✓ | ✗ | ✗ | — |
Assistant Managers / Shift Managers | ✓ | ✗ | ✗ | ✗ | — |
Team Leads / Key Holders | ✓ | ✗ | ✗ | ✗ | — |
CSAs / Attendants | ✗ | ✗ | ✗ | ✗ | — |
Why We Recommend This
All store management should have View access so they can see what has been requested and track its status. Top store management and corporate management should also have Add access so they can place new supply orders when their location is running low. Only corporate-level management and supply managers should have full Edit and Delete permissions — they are the people actually processing, fulfilling, and closing out supply requests. Keeping Edit and Delete restricted prevents a store from changing or removing a request after it has been submitted, which protects the audit trail between the location and the home office.
14. Templates – Checklists
This is where checklist templates are built and maintained. In the current version of Washstacks, creating and editing checklists is controlled here — under Templates — rather than on the Checklists row itself. If a manager needs to build or change the checklists their team completes each day, this is the permission that governs it.
What Each Permission Does
View — User can see the checklist template library.
Add — User can create new checklist templates.
Edit — User can modify existing checklist templates.
Delete — User can delete checklist templates.
Reports — Not applicable for this feature.
Recommended Settings
Role | View | Add | Edit | Delete | Reports |
Corporate Management | ✓ | ✓ | ✓ | ✓ | — |
Top Store Management (GM, Site Manager) | ✓ | ✓ | ✓ | ✓ | — |
Assistant Managers / Shift Managers | ✓ | ✗ | ✗ | ✗ | — |
Team Leads / Key Holders | ✗ | ✗ | ✗ | ✗ | — |
CSAs / Attendants | ✗ | ✗ | ✗ | ✗ | — |
Why We Recommend This
Template control is what keeps your daily routines consistent from shift to shift, so the ability to add, edit, and delete checklist templates should sit with top store management and corporate management. Assistant managers may be given View so they can reference the templates in use without changing them. Below that level, no access is needed — front-line staff complete checklists through the Checklists row (section 2), not here.
15. Templates – Checklists (Global)
Global checklist templates apply across your entire account. A change here can affect every location at once, so this permission carries more weight than a single-site template. Note that this row exposes only Add, Edit, and Delete — there is no separate View or Reports checkbox.
What Each Permission Does
Add — User can create global (account-wide) checklist templates.
Edit — User can modify global checklist templates.
Delete — User can delete global checklist templates.
View / Reports — Not applicable for this row.
Recommended Settings
Role | View | Add | Edit | Delete | Reports |
Corporate Management | — | ✓ | ✓ | ✓ | — |
Top Store Management (GM, Site Manager) | — | ✗ | ✗ | ✗ | — |
All Other Store Roles | — | ✗ | ✗ | ✗ | — |
Why We Recommend This
Because a global template touches every location in your account, this permission should be reserved for corporate or home office management. A single edit or deletion here ripples out to all of your sites, so it does not belong at the store level — even with your top store managers.
16. Templates – Checklists (Multi-site)
Multi-site checklist templates let you build one template and assign it across a selected group of locations. This is ideal for operators who run several sites and want consistent routines without rebuilding the same checklist at each one. Like the Global row, this row exposes only Add, Edit, and Delete.
What Each Permission Does
Add — User can create multi-site checklist templates.
Edit — User can modify multi-site checklist templates.
Delete — User can delete multi-site checklist templates.
View / Reports — Not applicable for this row.
Recommended Settings
Role | View | Add | Edit | Delete | Reports |
Corporate Management | — | ✓ | ✓ | ✓ | — |
Top Store Management (GM, Site Manager) | — | ✓ | ✓ | ✓ | — |
Mid-Level Management and Below | — | ✗ | ✗ | ✗ | — |
Why We Recommend This
Multi-site templates are meant for people who oversee more than one location, so this permission fits corporate management and any top store managers who are responsible for a group of sites. Keep it away from mid-level and lower roles, whose responsibilities are limited to a single location — they should be working from templates, not pushing them out across sites.
17. Work Orders
Work Orders are the lifeblood of maintenance management in Washstacks. They track every repair, inspection, and improvement project across your sites. Getting Work Order permissions right is essential because this is where maintenance staff, store managers, and corporate visibility all intersect.
What Each Permission Does
View — User can see all Work Orders.
Add — User can add a new Work Order.
Edit — User can edit an existing Work Order.
Delete — User can delete an existing Work Order.
Reports — User can view the Work Order report.
Recommended Settings
Role | View | Add | Edit | Delete | Reports |
Corporate Management | ✓ | ✓ | ✓ | ✓ | ✓ |
Top Store Management (GM, Site Manager) | ✓ | ✓ | ✓ | ✓ | ✓ |
Maintenance Managers | ✓ | ✓ | ✓ | ✓ | ✓ |
Maintenance Employees / Technicians | ✓ | ✓ | ✓ | ✗ | ✓ |
Assistant Managers / Shift Managers | ✓ | ✗ | ✗ | ✗ | ✗ |
Team Leads / Key Holders | ✗ | ✗ | ✗ | ✗ | ✗ |
CSAs / Attendants | ✗ | ✗ | ✗ | ✗ | ✗ |
Why We Recommend This
Top store-level managers, maintenance managers, and corporate managers should have all permissions, including Delete. Maintenance employees should have everything except Delete — they need to create and update work orders all day long, but you do not want a technician accidentally erasing a record that affects warranty tracking or compliance history. Other store management (assistant managers, shift managers) should be limited to View access so they can see what is open and plan around it, but should not be modifying work orders. Anyone below that — team leads, key holders, attendants, CSAs — should have no Work Order access at all. They are not part of the maintenance workflow and giving them access only creates noise.
Putting It All Together
As you work through your roles inside Washstacks, remember that permissions are not set in stone. You can always adjust as you learn more about how your team uses the system. The goal is to give every employee exactly what they need to do their job well — no more, no less. Too few permissions slows people down and creates frustration; too many permissions creates risk and inconsistency.
If you ever find yourself unsure whether to grant a specific permission, ask yourself three questions:
Does this person need this information or capability to do their daily job?
Is this person accountable for the outcome if the data changes?
If they make a mistake here, how hard is it to recover?
If the answer to the first two is yes and the third is "easy," grant the permission. If the recovery would be painful, hold the line and keep the permission with a more senior role.