A&A DealFlow

Team and Permissions

Give each teammate access to the work their role requires.

Invite employees, use fixed roles mapped to permission keys, assign records and tasks, manage member status, and review authorized activity without relying on interface-only checks.

Capabilities

Verified invitations

Invite a teammate through a time-limited, one-time flow with masked account information.

Fixed roles and permission keys

Roles map to server-enforced permission keys so access does not depend on a hidden button.

Assignments

Make lead and task ownership visible in the workflow.

Member lifecycle

Authorized admins can manage invitations and supported member status changes.

Audit and activity visibility

Review protected administrative events and record history according to permission.

Current boundary

Custom roles are Planned. The current product provides one workspace per company; arbitrary workspace structures are not available.

Illustrative product view

FAQ

Can we create custom roles?

Not today. The MVP uses fixed roles mapped to permission keys; custom roles are Planned.

Are permissions enforced only in the interface?

No. The architecture requires server-side permission checks, with database tenant controls as defense in depth.

Can one company see another company’s data?

The product is designed with company-level tenant isolation, app-layer scoping, and database row-level security. The Security page states verified controls and test status without making a certification claim.

Can an admin remove access?

Authorized admins can suspend, reactivate, or remove member access. Removal revokes the affected user’s company sessions.

Review roles, assignments, and access with your operating model in mind.