SECURITY & GOVERNANCE

Enterprise Access Control & RBAC Permissions

Safeguard your company data with Smart Business 360's multi-tenant architecture. Built with a 4-Tier Access Model, granular Module.Resource.Action key evaluation, and strict Segregation of Duties.

SECURITY ARCHITECTURE

The 4-Tier Enterprise Access Model

Four sequential checks determine exactly what data and actions each user can access.

1
Module Entitlement

First check: Is the module enabled for this company contract tenant?

2
RBAC Key Permission

Second check: Does the user's role hold the exact Module.Resource.Action key?

3
Record Role Scope

Third check: Whose records can they see? (SuperAdmin, TenantAdmin, TeamManager).

4
Department Hierarchy

Fourth check: Is the record within the user's assigned department or team scope?

GRANULAR RBAC

Module.Resource.Action Key System

Permissions are evaluated using an explicit 3-part key structure: Module.Resource.Action. This allows administrators to grant exact CRUD operations or extended business actions without over-exposing data.

Example Key: Accounts.Voucher.Post Grants specific permission to post financial vouchers to the ledger, separate from creating or editing vouchers.
Wildcard Support: CRM.*.Read or *.*.Read Wildcards automatically grant read permissions to new sub-resources added during system upgrades without manual re-configuration.
Baseline System Roles
Role Scope & Purpose
Tenant Administrator Full company administration & settings management.
Sales Officer Working leads, opportunities, activities, and inbox threads.
Sales Manager Team lead visibility, deal approvals, and commission oversight.
Accountant Posting journal vouchers, managing ledgers, bank reconciliations.
HR Officer Biometric attendance, leave approvals, and payroll processing.
AUDIT COMPLIANCE

Segregation of Duties (SoD) Safeguards

Prevent financial fraud and internal risk by enforcing strict role separation across high-risk pairs.

Accounts.Voucher.Create + Accounts.Voucher.Post

Separates entry preparation from final commitment to the double-entry financial ledger.

SalesManagement.Receipt.Create + SalesManagement.Receipt.Approve

Separates cash/payment collection entry from managerial authorization.

SalesManagement.Refund.Create + SalesManagement.Refund.Approve

Separates customer refund initiation from financial disbursement release.

HRM.Salary.Create + HRM.Salary.RunPayroll

Separates payroll salary calculations from actual fund release and disbursement.

Inventory.Procurement.Create + Inventory.Procurement.Approve

Separates purchase requisitions from vendor procurement approvals.

System.UserManagement.Create + System.Permissions.Update

Separates user account creation from privilege escalation grants.

MULTI-TENANT ARCHITECTURE

Multi-Company Setup & Data Layer Isolation

Manage multiple independent companies or subsidiaries within a single Smart Business 360 platform.

Two Administrator Levels
Level Role Scope Responsibility
Platform Super Admin PlatformSuperAdmin Creating companies, module entitlements, subscription plans.
Company Administrator TenantAdmin Company-specific configuration: users, roles, departments, ledgers.
Ongoing Administration Audit Cadence
Weekly Audit approval queues & check webhook integration health.
Monthly Review automation execution logs & audit new/deactivated accounts.
Quarterly Audit active roles against Segregation of Duties (SoD).
Annually Perform financial year closing and open the new fiscal accounting period.
FAQ

Enterprise RBAC & Security FAQ

Permissions are additive. If a user holds CRM.*.Read and CRM.Lead.Update, they can read all CRM resources and update lead records.
Role scopes (e.g. TeamManager or TenantAdmin) determine whose records a user can see, whereas RBAC keys determine which actions they can perform on those records.
Deactivating blocks account sign-in while preserving historical journal vouchers, lead activities, and audit logs. Deleting a user breaks historical attribution.

Secure your business operations with Enterprise RBAC

Schedule a call with our technical team to explore custom roles and security controls.