Access control & privacy: who sees what, and why it matters
06 Oct 2025, 09:21 am ยท 3 min read
A shared login and a spreadsheet on a drive is fine, right up until a casual can see payroll, a contractor can see everyone's customers, or an ex-employee still has the keys. Access control isn't corporate box-ticking; it's how you avoid a very bad Tuesday.
The three questions
- Who are you? Real logins per person, ideally with MFA or a passkey, not a shared password on a sticky note.
- What can you see? Roles and per-page permissions, a barista doesn't need the P&L.
- What did you do? A quiet log of who accessed what, so problems are findable.
Privacy is a feature, not a policy PDF
Customers increasingly ask where their data lives and who can touch it. "In our system, encrypted, access-logged, deletable on request" is a better answer than "somewhere in a spreadsheet, honestly not sure." It's also, increasingly, the law.
The law is catching up, even for small business
Australia's privacy rules are tightening. Recent reforms added tougher penalties and gave people a clearer path to act over serious breaches, and the long-standing carve-out that exempts most small businesses (under $3 million turnover) is under review and widely expected to narrow. "We're too small to matter" is getting riskier to lean on. Knowing who can see what, and being able to prove it, is quietly becoming table stakes rather than a nice-to-have.
Roles in plain English
Access control sounds like enterprise jargon. In practice it's just deciding, once, what each kind of person should be able to touch.
Owner / admin
Sees everything, changes anything, and decides who else gets in. Usually one or two people, no more.
Staff
The day-to-day view: their jobs, their customers, their tasks. Not the payroll, not the whole database.
Contractor / casual
A narrow slice, for a set time. Easy to grant, easier to revoke the day the work ends.
Customer
Their own records and nobody else's. The line that keeps one client from ever seeing another.
The one-click off-boarding test
Here's a question worth sitting with: when someone leaves, how long until they truly can't get back in? If the honest answer involves changing a shared password everyone has to relearn, or hunting through five tools, you don't have access control, you have a hope. Good systems make it one switch, logged, done.
You don't need an identity department. You need individual logins, a few sensible roles, and an off switch.
The small-business version
You don't need an identity department. You need: individual logins, a few sensible roles, the ability to turn someone off in one click, and a record of access. That's a weekend of thought that saves you a lawsuit.
