A shared password feels quick when the office is small. It becomes hard to answer basic questions: who changed a price, who approved a claim, and whose access should be removed when someone leaves? Separate accounts and job-based roles make those questions answerable.

Describe the work before naming the role. A person who prepares quotations may need to read customers and items but may not need to change the catalogue’s master price. Someone who reviews payroll needs different records from someone who marks attendance. Give each job the actions it needs, then test the role by walking through an ordinary day.

Branches add another boundary. A manager may need a view across locations, while a person handling one branch may need only that branch’s work. A role and a branch scope answer two different questions: what may this person do, and where may they do it?

Keep a way to review changes. An activity record is most useful when it names the person, the action and the affected record. It does not replace a conversation about a mistake, but it gives that conversation a starting point.

Review access when the work changes, not only when someone leaves. A temporary cover arrangement should have an end; a promotion may need broader permissions; a role nobody uses can be retired. The goal is a team that can keep moving without everyone carrying the key to every room.