Home/ Volume 04/ Chapter 8
Show menu button
The Golden Rule

Access should be based on responsibility, not rank, curiosity, or convenience: the principle of least privilege.

Full access for everyone isn't generous, it's a control failure waiting to happen. Restricting access protects privacy, confidentiality, and the integrity of every record this volume built.

OwnerFull access to all drawers.
Specialist rolesOnly the drawer their duties actually touch.
Frontline staffTheir own work orders and instructions only.

Access narrows by design

Not because frontline staff are less trusted, but because their duties don't require it.

Fewer people, fewer opportunities

Restricting access is the whole premise of internal controls, starting at record creation.

Review access on every role change

Old access quietly outlives the role that justified it.

"We're small" is the trap

Informal access is easiest to grant early and hardest to walk back later.

1

Definition

Imagine a shared spreadsheet holding customer orders on one tab and staff salaries on another, open to anyone with the folder link. A cutter checking his own hours notices the salary tab is just one click away. Nothing gets stolen. But the moment two employees compare pay and can't get an answer, trust breaks, and it breaks because nobody ever asked who actually needed to see that tab.

Access

to a record should be based on responsibility, not rank, curiosity, or convenience. The rule that decides it is the principle of least privilege: people should have access only to the information necessary to perform their duties, nothing more.

In One Sentence

Not everyone should have unrestricted access to every drawer in this volume's cabinet. Full access for everyone isn't generous, it's a control failure waiting to happen (Volume 11's whole subject). Restricting access protects privacy, confidentiality, and the integrity of every record this volume has just spent seven chapters building.

2

The Access Table

Owner / Managing Director

Full access to all drawers.

Everything

Accountant

Financial records, payroll, tax, invoices.

Money

Operations Manager

Production schedules, inventory, maintenance.

Operations

HR Officer

Employee records, payroll information.

People

Sales Staff

Customer records relevant to their own work.

Their customers

Production Staff

Work orders and production instructions only.

Their tasks
RoleTypical Access
Owner / Managing DirectorFull access to all drawers
Accountant / BookkeeperFinancial records, payroll, tax, invoices
Operations ManagerProduction schedules, inventory, maintenance records
HR OfficerEmployee records, payroll information
Sales StaffCustomer records relevant to their own work
Production StaffWork orders and production instructions only

Read down that table and notice the shape: access narrows as you move from owner to frontline staff, not because frontline staff are less trusted, but because their duties don't require drawer one's shareholder register or drawer four's salary details.

Memory Trick

Ask "what does this role need to do its job?", never "would this person like to see it?" Curiosity is not a reason for access; duty is.

3

Why This Rule Protects Everyone, Not Just the Business

Who It ProtectsHow
EmployeesSalary and disciplinary details stay private, per Chapter 5's warning
CustomersTheir contact and payment details aren't visible to staff with no reason to see them
InvestorsConfidential valuation and ownership details (Volume 03) stay contained
The business itselfFewer people who could misuse a record means fewer opportunities for fraud, the whole premise of Volume 11: Internal Controls

This chapter is really Volume 11's first appearance, arriving early because access decisions start the moment a record is created, not later, once a control policy gets written.

4

Example Story: The Spreadsheet Everyone Could Open

Early on, MANIAC MINDZ kept one shared spreadsheet: customer orders, supplier costs, and staff salaries, all on different tabs of the same file, open to anyone with the shared folder link. A well-meaning cutter, checking his own hours on the attendance tab, could see every colleague's pay with one more click.

Nothing was stolen. But trust broke the moment two employees compared salaries and found pay differences the owner could not explain on the spot. The fix was simple and overdue: separate files, separate access, by role, exactly the table in Section 2.

5

Common Mistakes

Common Mistake #1: One Shared Folder, No Separation

Convenience today, a trust problem tomorrow. Separate access by drawer, not just by goodwill.

Common Mistake #2: Access Granted and Never Revisited

An employee who changes roles (or leaves) often keeps old access long after it's needed. Access should be reviewed whenever a role changes, see Volume 20: Technology & Cybersecurity for the password/account side of this.

Common Mistake #3: "We're Small, Everyone Needs to See Everything"

Small size is exactly when informal access is easiest to grant and hardest to walk back later. Build the habit small; it scales far better than retrofitting it onto a 20-person team.

6

Quiz Yourself

Quiz 1
What is the principle of least privilege?
People should have access only to the information necessary to perform their duties, no more, regardless of rank or curiosity.
Quiz 2
In the spreadsheet story, what was the actual failure, theft, or something else?
Something else: a trust and privacy failure. No money was stolen, but salary confidentiality was broken simply because access wasn't separated by role.
Quiz 3
Why does access control matter more, not less, in a small business?
Informal, blanket access is easiest to grant when everyone still knows each other, and hardest to unwind once the business and team have grown past that comfort.
7

Practice Exercise

  1. List every record drawer from this volume (Chapters 2–7) down the side of a page, and every role in your business across the top.
  2. Mark which roles genuinely need access to each drawer, using the table in Section 2 as a starting template.
  3. Compare that to who actually has access today. Close every gap you find this week.
8

Quick Summary

Quick Summary

  • Access should follow the principle of least privilege: only what a role needs to do its job.
  • The typical shape: owner (everything) → specialist roles (their drawer) → frontline staff (their own instructions only).
  • Restricting access protects employees, customers, investors, and the business, not just against theft, but against broken trust.
  • Review access whenever a role changes, and never let "we're small" be the reason it's skipped.
  • Volume 04 complete. The cabinet is built; next, Volume 05: Production & Patterns covers the records specific to what the business actually makes.