Skip to content
Noviqent.
Home
Solutions Integrations Services Software Insights About Log in Contact us

Business Platform

Why a flat admin/member split stops working around your first ten users

08 August 2026

Most business software ships with two roles: admin, and everyone else. For a five-person team, that's not a limitation — it's barely a decision. Someone runs the business, everyone else uses the parts they need. But the moment an organisation has real departments — Finance, IT, Operations, Sales — that same two-role model turns into a genuine problem.

The failure mode is always the same shape. Finance needs to manage billing and see every invoice. IT needs to manage API keys and integrations. Neither should be able to do the other's job, and neither should need full admin rights just to do their own. With a flat admin/member split, there are exactly two ways to resolve this: promote everyone who needs any elevated access to full admin (and accept that Finance can now also revoke IT's integrations, and IT can now also see payroll data flowing through billing), or keep everyone as a plain member and have one overloaded admin account doing everything, becoming both a bottleneck and a single point of failure.

Neither is actually acceptable once you think about it for more than a minute, which is exactly why it keeps getting deferred — "we'll sort out proper permissions later" — until an audit, an offboarding, or an incident forces the question.

What actually fixes it is a permission model built around groups an organisation defines for itself, not a fixed list a vendor decided in advance. A Finance group gets exactly the billing and invoicing permissions Finance needs. An IT group gets integration and storage management, and nothing else. A member can belong to more than one group, and their effective access is simply the union of what those groups grant — no promotion to admin required, no shared login, no manually maintained spreadsheet of "who's allowed to do what."

This is exactly how permissions work in our Business Operations Platform: fixed roles set a baseline, and org-defined groups layer specific permissions on top, department by department. It's available as a hosted SaaS or run entirely on your own infrastructure, and if your organisation's access model needs something the built-in groups don't cover, we'll build it.

Frequently asked questions

Do permission groups replace user roles entirely?

No — fixed roles (like org admin or member) still set a sensible baseline. Groups add specific extra permissions on top for people who need more than their role gives them, without a full admin promotion.

Can one person belong to more than one group?

Yes. Effective permissions are the union of everything a person's role and every group they belong to grant, so someone can sit across Finance and Operations if that reflects their actual job.

Want to talk this through?

Happy to go into more detail, or look at how it applies to your own setup.

Speak with us

Related insights