Reading a journal and deleting one are not the same thing.
Your team does not divide neatly into three job titles. So Papercare gives every page its own View, Add, Edit and Delete, set person by person. Twenty-three pages, four verbs, ninety-two decisions, and a leaver who is deactivated rather than deleted.
23 pages · 4 verbs · 92 switches per person
Everyone in the firm. One list.
Your team members sit in one place, each with a status and a set of rights. No spreadsheet of who was given access to what in 2023 and never taken off it.
- ✓Active or Inactive. An inactive member cannot sign in, and everything they ever signed keeps their name on it.
- ✓Edit any member's rights from here. One click, straight into the matrix.
- ✓Nobody gets a default. Every permission is a decision somebody made.
press edit.
| Sr. No. | Member Name | Status | Actions |
|---|
Running the firm is not doing the work.
Papercare splits rights into two scopes, because they are genuinely different jobs. One is about the practice. The other is about the client file in front of you.
- ✓Admin rights. The team, the clients, the chart of accounts, settings, deadlines, the firm's checklists.
- ✓Operational rights. Import, journals, queries, review points, the final pack, AI Review.
- ✓Which means a manager can run every job in the practice without being able to reconfigure the practice.
click one. see what it covers.
Every page. Four verbs. Ninety-two switches.
This is the whole argument. Not a dropdown with Partner, Manager and Junior in it. A grid, with every page in Papercare down one side and View, Add, Edit and Delete across the top, for one named human.
- ✓Search by page name, because twenty-three rows is a lot to scroll when you want one.
- ✓Tick a whole column to grant one verb everywhere, then take back the two you did not mean.
- ✓Delete is its own switch. Somebody can prepare work they are not able to destroy.
tick the Delete column. then think about it.
| Sr. | Page Name |
|---|
Four ticks. Four different people.
A permission matrix is abstract until you say it out loud. So here is one page, four switches, and what the person can actually do written underneath in English.
- ✓View only. A trainee can read the ledger and learn from it. They cannot touch it.
- ✓View and Add. They can post a journal but not go back and change it. Everything they do is on the record.
- ✓Everything but Delete. The shape a great many firms actually want, and the one an access level cannot express.
toggle them. read the sentence.
People leave. The evidence stays.
When somebody leaves, the instinct is to delete the account. Do that and every journal, review point and checklist they signed loses its author. You have just torn a hole in the exact record a monitoring visit will ask to see.
- ✓Mark them Inactive. Sign-in is blocked immediately.
- ✓Their name stays on everything they ever signed. The history is intact.
- ✓Sabbatical, maternity leave, a leaver who might come back: same switch, and nothing is lost.
deactivate her. watch the trail.
Still signed by her, and still hers
Permissions are only worth what they guard.
A matrix is not the point. The point is that the ledger, the journals, the review points and the AI itself are all pages, so they all carry the same four switches. Including who is allowed to talk to the AI at all.
AI Review is a page. so it has permissions too.
Job titles are a lie.
No two firms mean the same thing by "manager". Shipping you three preset roles would force your practice into our idea of a hierarchy. So we ship a grid instead, and let you describe the person you actually employ.
Access levels force your hand.
When View and Delete are welded together, you either lock somebody out of work they need to do, or you hand them a delete button nobody wanted them to have. Almost every firm picks the second one and hopes.
A deleted person is a hole.
If you delete a leaver, every signature they left behind becomes anonymous. Deactivation keeps the person out and the evidence in, which is the only version of this that survives a monitoring visit.
Straight answers.
Describe one of your people. Properly.
Not "manager". The actual person, with the actual things they should and should not be able to do. Build their permission shape in the demo and see whether your current system could even express it.