Dispute sentences are usually “I thought I could see that” and “they used to be able to approve.” Leak sentences are usually “everyone can enter the drive” and “leave the account for now.” The matrix is not philosophy. It is each cell: view / approve / export—yes or no for this role.
| Role | See dept. expenses | See payroll | Approve contracts | Use seal | Export clients |
|---|---|---|---|---|---|
| Sales | Own only | No | No | No | Own only |
| Sales manager | Yes | No | Within limit | No | Team |
| Finance | Yes | Yes | No | No | No |
| Admin / seal control | Related to-dos | No | No | Yes | No |
| Exit, not reclaimed | Must close | Must close | Must close | Must close | Must close |
Fewer disputes because there is a cell first, not a hearing later
Once cells are written, the fight moves from “who are you to look” to “change the role or change the limit.” Exceptions still happen. They go through a grant and expire. Verbal rules have no cells, so they break—see Why verbal permission rules eventually fail. Groups and subsidiaries also need isolation and roll-up on those cells—see Group and subsidiaries: isolate permissions, still report up.
Fewer leaks because export and exit are permission events
Client lists, payroll and contract scans are dangerous not because “someone saw them,” but because they can be bulk-exported with no audit. Make export its own column. Log sensitive actions. When a manager leaves, accounts and to-dos transfer together—see How to-dos and permissions survive when a manager leaves. Attendance-only, without rules for approvals and data scope, leaves the leak path open—see What happens if you only ship HR and attendance, and skip approvals.
Feishu and DingTalk document permissions are flexible—and often wider than the role. A custom back office is the place to make the few columns the company actually cares about into hard rules. Directories can still sync from the platform. How to split the work: Feishu, DingTalk, and a custom back office: what actually differs. DaXi fills this matrix with you before code, so launch is not a verbal whitelist from the admin. Bring the data you most fear leaking to the Management systems service page.
Cells have to change with the org, not get filled once
A matrix is not a poster. Rotations, side jobs and vendor onboarding all change cells. If the admin only knows “open it for this person,” the matrix is hallway talk again in three months. Treat transfers and join/leave as permission events: HR status changes, the role follows. Then an audit can answer “could they see it then” on a timeline—see What role OA plays in audit and compliance. When sales, delivery and finance share a contract, view fields and approve fields still have to split—see Sales, delivery, and finance share contracts: how to split the back office. Clear cells are why departments dare put daily work in the back office without fearing a wrong click. Exporting clients and downloading contract scans should be their own approval—not the same cell as “can log in.” If cells are not reviewed for six months, hallway talk grows back through the whitelist.
The other side of fewer disputes is an exit for exceptions: temporary grants have an expiry, not a permanent green light. The other side of fewer leaks is an export log that can answer “who took the list on which day.” Both have to be true, or the matrix is decoration.