Skip to content
UnionStack logo UnionStack

Learning centre · Foundations & administration

Plan roles, users and access

Plan UnionStack access around real responsibilities, review points and the principle of least privilege.

Workflow context

What this guide helps you accomplish

Plan UnionStack access around real responsibilities, review points and the principle of least privilege.

Access design should begin with work responsibilities and sensitive records. Test the result as ordinary users, because an administrator account cannot prove least-privilege behaviour.

Working principle
Access should be understandable, intentional and reviewed whenever a person’s responsibilities change.

Before you begin

Prepare the following before changing shared configuration or records:

  • Administrator access to a UnionStack test organization and a written description of the procedure you are configuring.
  • A small set of fake records that covers an ordinary example and at least one exception.
  • A named configuration owner who can approve terminology, access and any change to shared settings.
  • A responsibility-to-access matrix approved by the operational and privacy owners.

Procedure

Complete the steps in order with fake or approved test information first. Record configuration decisions that will affect other teams.

01

List operational responsibilities

Identify who configures the platform, manages people, handles cases, publishes sites, reviews reports and supports integrations. Start with responsibilities rather than job titles alone.

02

Separate configuration from everyday work

Limit settings and type configuration to the people accountable for maintaining the shared model. Everyday users should receive the tools needed for their assigned work.

03

Create an initial access matrix

Map user groups to the records and procedures they need. Note where sensitive case, personal or document information requires a narrower audience.

04

Invite a controlled pilot group

Begin with representatives from each major workflow. Ask them to complete realistic tasks and report both missing access and access they did not expect.

05

Review access after organizational changes

Update access when responsibilities, employment or representation terms change. Schedule periodic reviews rather than relying only on ad hoc removal.

Product view

UnionStack access configuration for users and roles
UnionStack 2.0 test environment using fake data. Interface details may vary with your organization’s types, fields, permissions and terminology.

Video demonstration

Troubleshooting

Use the symptoms below to diagnose the workflow before widening access, adding duplicate configuration or bypassing an intended control.

An administrator test appears successful but ordinary users fail

Repeat the procedure with non-administrator accounts representing each role. Record both missing access and unexpected visibility.

Users describe the same concept with different names

Pause configuration and reconcile the labels used in policies, forms and everyday work. Choose one preferred term and document any legacy synonyms for onboarding.

A pilot user can see too much or too little

Compare the user’s actual responsibility with the planned access matrix. Correct the role or group assignment, then repeat the test with a second representative account.

The configuration works only for the sample record

Add an unusual but valid scenario and trace it through the same procedure. Adjust the model only when the difference affects a real decision, relationship or report.

Validation checklist

Do not treat the procedure as complete until an authorized second person can reproduce the intended result.

  • Each pilot account can complete its assigned work and cannot open the deliberately restricted test record.
  • A second administrator can explain the configuration and its owner without relying on undocumented knowledge.
  • A pilot user can complete the intended task without a spreadsheet, private note or duplicate record.
  • Names, statuses and structured choices match the approved terminology list.
  • Access was tested with representative non-administrator accounts.

Version applicability

UnionStack 2.0

This guide was verified for UnionStack 2.0 on August 16, 2026. Available fields, types, relationships, navigation and access can vary with tenant configuration and user permissions.

Continue learning

Return to the UnionStack Learning Centre, or take the UnionStack product tour to see how these parts connect.