Access narrows by design
Not because frontline staff are less trusted, but because their duties don't require it.
Volume 04, Chapter 8
Ask "what does this role need to do its job?", never "would this person like to see it?" Curiosity is not a reason for access; duty is.
Full access for everyone isn't generous, it's a control failure waiting to happen. Restricting access protects privacy, confidentiality, and the integrity of every record this volume built.
Not because frontline staff are less trusted, but because their duties don't require it.
Restricting access is the whole premise of internal controls, starting at record creation.
Old access quietly outlives the role that justified it.
Informal access is easiest to grant early and hardest to walk back later.
Imagine a shared spreadsheet holding customer orders on one tab and staff salaries on another, open to anyone with the folder link. A cutter checking his own hours notices the salary tab is just one click away. Nothing gets stolen. But the moment two employees compare pay and can't get an answer, trust breaks, and it breaks because nobody ever asked who actually needed to see that tab.
to a record should be based on responsibility, not rank, curiosity, or convenience. The rule that decides it is the principle of least privilege: people should have access only to the information necessary to perform their duties, nothing more.
Not everyone should have unrestricted access to every drawer in this volume's cabinet. Full access for everyone isn't generous, it's a control failure waiting to happen (Volume 11's whole subject). Restricting access protects privacy, confidentiality, and the integrity of every record this volume has just spent seven chapters building.
Full access to all drawers.
EverythingFinancial records, payroll, tax, invoices.
MoneyProduction schedules, inventory, maintenance.
OperationsEmployee records, payroll information.
PeopleCustomer records relevant to their own work.
Their customersWork orders and production instructions only.
Their tasks| Role | Typical Access |
|---|---|
| Owner / Managing Director | Full access to all drawers |
| Accountant / Bookkeeper | Financial records, payroll, tax, invoices |
| Operations Manager | Production schedules, inventory, maintenance records |
| HR Officer | Employee records, payroll information |
| Sales Staff | Customer records relevant to their own work |
| Production Staff | Work orders and production instructions only |
Read down that table and notice the shape: access narrows as you move from owner to frontline staff, not because frontline staff are less trusted, but because their duties don't require drawer one's shareholder register or drawer four's salary details.
Ask "what does this role need to do its job?", never "would this person like to see it?" Curiosity is not a reason for access; duty is.
| Who It Protects | How |
|---|---|
| Employees | Salary and disciplinary details stay private, per Chapter 5's warning |
| Customers | Their contact and payment details aren't visible to staff with no reason to see them |
| Investors | Confidential valuation and ownership details (Volume 03) stay contained |
| The business itself | Fewer people who could misuse a record means fewer opportunities for fraud, the whole premise of Volume 11: Internal Controls |
This chapter is really Volume 11's first appearance, arriving early because access decisions start the moment a record is created, not later, once a control policy gets written.
Early on, MANIAC MINDZ kept one shared spreadsheet: customer orders, supplier costs, and staff salaries, all on different tabs of the same file, open to anyone with the shared folder link. A well-meaning cutter, checking his own hours on the attendance tab, could see every colleague's pay with one more click.
Nothing was stolen. But trust broke the moment two employees compared salaries and found pay differences the owner could not explain on the spot. The fix was simple and overdue: separate files, separate access, by role, exactly the table in Section 2.
Convenience today, a trust problem tomorrow. Separate access by drawer, not just by goodwill.
An employee who changes roles (or leaves) often keeps old access long after it's needed. Access should be reviewed whenever a role changes, see Volume 20: Technology & Cybersecurity for the password/account side of this.
Small size is exactly when informal access is easiest to grant and hardest to walk back later. Build the habit small; it scales far better than retrofitting it onto a 20-person team.