1Tool

Blog · 05 June 2026

Who Can See What? The Permission System Behind 1Tool

Who Can See What? The Permission System Behind 1Tool

In many companies, the volume of digitally managed data grows faster than the understanding of who is actually allowed to access what. As long as there are only a handful of employees, a simple distinction between "administrator" and "standard user" is often enough. But as soon as several departments, external partners and sensitive projects come into play, this coarse model becomes a problem: either too many people see too much, or exceptions constantly have to be maintained by hand. 1Tool meets this challenge with a permission system that combines classic roles with granular, record-level access rights.

Three levels instead of one rigid template

The key difference from a simple role model is that access in 1Tool can be granted on three different levels. First, to individual users, when a permission really should apply to one specific person only. Second, to entire roles, when a permission makes sense for a function within the company, regardless of which person currently holds it. And third, something many systems lack: to individual contacts, meaning external people who do not even have a regular user account. This combination lets you fine-tune access rights as precisely as your actual organisational structure requires, instead of bending the organisation to fit the limits of the software.

Why pure role models reach their limits

A classic role model works well as long as responsibilities can be mapped neatly along functions. In practice, however, situations keep arising that do not fit so tidily: a single confidential project, a temporary collaboration with an external consultant, or a special case in which one particular person needs insight without the whole department reading along. Record-level permissions are designed precisely for such cases. They complement the role logic without replacing it, and they prevent companies from granting permissions more generously than necessary simply for convenience.

Security that fits your organisation

The result is a system that adapts to the actual structure of a company, not the other way round. Whether you hire new employees, share projects with customers or reassign responsibilities, you no longer have to choose between "easy to manage" and "secure enough". 1Tool lets you pursue both goals at the same time, because granularity applies exactly where it is needed and can deliberately stay coarse everywhere else.

Frequently asked questions

What is the difference between role-based and individual permissions in 1Tool?
Role-based permissions apply to all users with a particular role and are suited to recurring, function-related access. Individual permissions apply to a single person and are suited to exceptions or particularly sensitive records. Both approaches can be used side by side. Can external people also be given access rights in 1Tool?
Yes. In addition to users and roles, 1Tool also supports granting access to individual contacts, meaning external people who do not have their own user account in the system. Do I have to give up my existing role concept to benefit from granular permissions?
No. Record-level permissions complement existing roles; they do not replace them. You can keep your role concept as it is and refine it selectively wherever needed. How granular does your permission system need to be today, and where do you still see open questions?

Book a demo

Read more